PCI DSS compliant cloud providers

21 of the 112 cloud providers we track say they hold a PCI DSS attestation.

Providers

PCI DSS is the payment card industry's standard for handling card data. Level 1 is the strictest tier, audited on site every year.

Headquarters
Provider Level Source Checked
Akamai Cloud logo Akamai Cloud United States of America flag trust.akamai.com
Alibaba Cloud logo Alibaba Cloud China flag Level 1 alibabacloud.com
Amazon Web Services logo Amazon Web Services United States of America flag Level 1 aws.amazon.com
Cloudflare logo Cloudflare United States of America flag Level 1, some products cloudflare.com
DigitalOcean logo DigitalOcean United States of America flag SAQ-A digitalocean.com
Firebase logo Firebase United States of America flag Some Firebase services only cloud.google.com
Gcore logo Gcore Luxembourg flag trustcentre.gcore.com
Google Cloud logo Google Cloud United States of America flag cloud.google.com
Heroku logo Heroku United States of America flag Level 1, Heroku Shield only devcenter.heroku.com
Hetzner logo Hetzner Germany flag Card payments only docs.hetzner.com
Hostinger logo Hostinger Lithuania flag SAQ-A trust.hostinger.com
Impossible Cloud logo Impossible Cloud Germany flag Data centers only impossiblecloud.com
Leaseweb logo Leaseweb Netherlands flag Physical security only kb.leaseweb.com
Microsoft Azure logo Microsoft Azure United States of America flag Level 1 learn.microsoft.com
Netlify logo Netlify United States of America flag SAQ-A netlify.com
Oracle Cloud logo Oracle Cloud United States of America flag oracle.com
OVHcloud logo OVHcloud France flag Level 1, Hosted Private Cloud only ovhcloud.com
Paperspace logo Paperspace United States of America flag Level 1, data centers only paperspace.com
Vercel logo Vercel United States of America flag vercel.com
Vultr logo Vultr United States of America flag Merchant vultr.com
Wasabi logo Wasabi United States of America flag Data centers only docs.wasabi.com

No providers matching your filters.

Showing 21 of 21 providers

Heads up: Each row links to the provider's own statement, checked on the date shown. An attestation can cover one tier, one region or the platform alone rather than every service. Verify the scope before you rely on it.