Razorpay

India · razorpay.com · 18 vendors

Razorpay is an Indian financial technology company that provides a full-stack financial solutions platform for businesses. It offers payment gateway services, business banking solutions (RazorpayX), payroll management, and lending services (Razorpay Capital) to help businesses manage their entire money flow.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 18 sub-vendors.

Insights

Last updated 2026-07-30 · revision 10

18 direct vendors, 254 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Razorpay exhibits high migration readiness, largely due to its highly modern, cloud-native, and containerized tech stack. The extensive use of AWS, Kubernetes, Docker, microservices architecture, and event-driven patterns means the company is already operating in an environment conducive to seamless migration to new cloud platforms or environments. Their existing multi-cloud routing capabilities (Optimizer engine) and multi-jurisdictional data architecture demonstrate inherent flexibility and experience in managing diverse operational landscapes. The absence of identified mandatory data residency restrictions also offers flexibility in choosing target migration locations. However, significant challenges and uncertainties exist. The 'Vendor Lock-in Risk: Unknown' is a major concern; with 'Total Services: 32' and an unknown degree of integration, potential vendor dependencies could significantly complicate and increase the cost of migration. Furthermore, the 'Assessment Required' status for GDPR and SOC2 could introduce regulatory hurdles, potentially requiring new audits or re-certifications in a new environment. The lack of financial stability data also means the company's capacity to fund a large-scale migration cannot be fully assessed.

Compliance

7 in-scope frameworks identified; showing 3.

CCPA — Compliant

Razorpay's US privacy policy includes comprehensive CCPA compliance sections with detailed consumer rights, data categories, and opt-out mechanisms. As a company operating in the US and processing California residents' data, CCPA compliance is demonstrated through their privacy policy provisions.

Evidence: https://razorpay.com/us/privacy-policy/

ISAE 3000 (source) — Assessment Required

ISAE 3000 applies to assurance services and reporting. As a payment platform that may provide assurance reports to customers and partners, ISAE 3000 could be relevant. However, no specific evidence of ISAE 3000 compliance was found in available documentation.

ISO 27001 (source) — Partially Compliant

Razorpay's documentation references ISO certification and includes an ISO logo, suggesting they have some level of ISO 27001 compliance. However, the specific certification link was not accessible for verification. As a payment platform handling sensitive financial data, ISO 27001 is highly relevant for information security management.

Evidence: https://razorpay.com/docs/, https://seal.controlcase.com/index.php?page=showCert&cId=2922528603

Financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report