How do I obtain an SAS-70 letter? I need one for an audit.
Hi there.
A SSAE-16 report is typically required of third-parties that operate in an unregulated environment. This is the case for companies such as data center providers, paper shredding companies, cloud computing providers, and other unregulated service providers.
Square operates directly in the payment card industry (PCI) which is regulated under the PCI Security Standards Council (PCI SSC). As such, we adhere to our industry regulations without the need to have a separate SSAE-16 review.
You can validate our compliance by seeing our listing on the Visa Service Provider website http://www.visa.com/splisting.
You will see that we comply with the Payment Card Industry Data Security Standard (PCI DSS). This standard includes the following areas of review:
Let me know if you have any further questions!
Square Community