WhichPayroll Security Disclosure Benchmark

WhichPayroll Security Disclosure Benchmark

Security certification and disclosure quality across 17 EOR and global payroll providers.

v1 · Last updated: 2026-06-06 · Sample: 17 providers · Next refresh: Aug 2026


12/17
SOC 2 Type II verified from public sources
10/17
ISO 27001 verified from public sources
10/17
publish a public-facing GDPR DPA document
0/17
disclose Cyber Essentials Plus certification

WhichPayroll sample of 17 providers. Observed May 2026. Verified = confirmed from public provider documentation. Methodology →

What this benchmark measures

The WhichPayroll Security Disclosure Benchmark records what security certifications and compliance documentation each provider makes publicly verifiable, without requiring an NDA, a sales call, or a vendor questionnaire response. The benchmark covers six certification dimensions: SOC 2 Type II, ISO 27001, GDPR data processing agreements, HIPAA, PCI DSS, and Cyber Essentials Plus.

Each dimension is classified as: Verified (certification confirmed from public provider documentation), Public (public-facing compliance document available but formal certification not stated), On request (provider states certification is available on request), or not disclosed (no public evidence found). Not disclosed does not mean the provider lacks the certification; it means WhichPayroll could not confirm it without a vendor questionnaire.

Key findings

In WhichPayroll’s sample of 17 providers observed in May 2026:

  • 12 of 17 providers have verified SOC 2 Type II from public sources. Deel, Papaya Global, Rippling, Pebl, Multiplier, G-P, Plane, Playroll, RemotePeople, Lano, Remofirst and Gusto all publish or explicitly reference current SOC 2 Type II attestation on their trust centres or security pages. A further 2, Remote and Oyster HR, state SOC 2 is available on request. Re-checked at source on 5 August 2026, which added Pebl and Remofirst: both state the certification plainly on their own pages, and both had been recorded as undisclosed because the check ran against a pre-rebrand URL in Pebl’s case and missed the trust-signals block in Remofirst’s.
  • 10 of 17 have verified ISO 27001 from public documentation. Overlap with SOC 2 is high: providers with both certifications tend to publish them together. Only 1 provider, Safeguard Global, discloses neither certification publicly.
  • 9 of 17 publish a GDPR data processing agreement you can actually read: a DPA reachable without a login, an NDA or a sales enquiry. Re-assessed at source on 5 August 2026 under a tighter rule than the earlier count used, which had credited a privacy FAQ or a stated DPA-on-request process; on that looser test the figure was 14. The remaining 8 publish nothing that meets the standard. Safeguard Global is the clearest case: it publishes a page headed GDPR specifications, but that document is expressly controller-to-controller and covers only business contact data, so it is not a processor DPA.
  • 0 of 17 providers disclose Cyber Essentials Plus. This UK government-backed certification is standard practice for UK government suppliers. Its absence from all 17 providers in the sample reflects that most EOR platforms are US-headquartered and do not pursue UK-specific government certifications.
  • PCI DSS is not disclosed by any provider in this sample, and HIPAA by 3. PCI DSS applies to payment card handling, which is niche in the EOR context. HIPAA is not a certification at all, so no provider can be verified against it, but three now document how they handle protected health information: Gusto states on its own security page that it follows HIPAA guidelines and maintains business associate agreements, Rippling publishes HIPAA-scoped audit reports through its trust centre, and Playroll refers to HIPAA-compliant configurations without evidence behind the claim.

Buyer implications

Buyers in regulated industries (financial services, healthcare, government contractors) typically require SOC 2 Type II reports and ISO 27001 certificates before procurement approval. The 12 providers with verified SOC 2 all represent viable choices on this dimension. For the 5 providers where SOC 2 is not publicly verified, submit a security questionnaire early in the sales cycle and request the SOC 2 Type II report directly. Waiting until contract stage for this document routinely adds 2–4 weeks to procurement timelines.

For GDPR compliance specifically, any provider handling EU employee payroll data is a data processor under GDPR Article 28. Even where a public DPA document is not listed, providers are legally required to execute a DPA on request. The 3 providers with no public GDPR reference are not necessarily non-compliant; they may not be marketing their GDPR documentation publicly.

Limitations

  • Not disclosed does not mean the provider lacks certification. Providers frequently hold certifications that are not surfaced in public documentation. This benchmark records public disclosure, not certification status.
  • Certification status changes. Providers obtain, renew, or let lapse certifications on their own cycles. WhichPayroll’s observation is a point-in-time record from May 2026.
  • This benchmark does not assess underlying security quality, MFA enforcement, penetration testing disclosure, or bug bounty scope. Those dimensions will be added in the Aug 2026 refresh.

Security certification disclosure matrix

WhichPayroll Security Certification Disclosure Benchmark, May 2026. Sample: 17 providers. Verified = confirmed from public provider documentation at time of observation. Public = public-facing DPA/compliance document available. On request = stated as available on request. — = not disclosed in public sources. Not disclosed does not mean the provider lacks certification. Composite score = WhichPayroll 4-dimension provider index.
Provider SOC 2 Type II ISO 27001 GDPR DPA HIPAA PCI DSS Cyber Essentials+ Composite Confidence
DeelVerifiedVerifiedPublic9.1 /10High
MultiplierVerifiedVerifiedPublic8.5 /10Medium
PeblVerifiedVerifiedPublic8.1 /10Medium
RemotePeopleVerifiedVerifiedPublic8.0 /10Medium
RipplingVerifiedVerifiedPublicOn request6.4 /10Medium
RemofirstVerifiedVerified8.1 /10Medium
Papaya GlobalVerifiedVerified7.7 /10High
G-PVerifiedOn requestPublic9.5 /10Medium
RemoteOn requestVerifiedPublic8.0 /10High
LanoVerifiedClaimed7.8 /10Medium
WorkMotionVerifiedPublic7.7 /10Medium
PlayrollVerifiedClaimedClaimed7.5 /10Medium
Atlas HXMVerified7.2 /10Medium
PlaneVerified6.7 /10Medium
GustoVerifiedPublic3.5 /10Medium
Oyster HROn requestPublic7.0 /10Medium
Safeguard Global4.2 /10Medium

Research conducted using WhichPayroll’s evidence-first methodology. View full methodology →

How to cite WhichPayroll Research

WhichPayroll Research, [Report name], [Month Year]. Available at whichpayroll.com/research/[slug]/. Sample: [N] providers. Last updated: [date].

For data requests or corrections: contact@whichpayroll.com