nonkyc.io

A
Trust rating
Excellent · 95/100
Procurement snapshot
No critical findings. The 2 remaining items are configuration gaps, not architectural problems.
Strengths
DNS Configuration
TLS Protocol Support
TLS Configuration
security.txt (RFC 9116)
Estimated remediation effort: 1–2 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned April 09, 2026
Your rating Industry average
Score
100 75 50 25 0
A
nonkyc.io
95/100
Compliance & Certifications
Not yet verified
PCI DSS
PCI-DSS
AOC not on file
3rd party · QSA
Pro subscribers only
SOC 2 TYPE II
SOC 2 Type II
Audit report not on file
3rd party · AICPA
Pro subscribers only
DORA
DORA
Not on file
EU regulatory
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
Security Posture
2 items need attention
13 passed
Add a CAA record (limits who can issue certificates for you)
DNS CAA Records
15 minutes

This is a low-risk, near-zero-cost control most security checklists expect to see. nonkyc.io has no CAA record, which means any certificate provider in the world is technically allowed to issue an SSL certificate for your domain — usually not exploited, but it's an easy, low-effort lock to add. A CAA record just says "only these specific providers are allowed to issue certificates for me."

How to fix this
1Figure out which certificate provider you actually use — if you're not sure, "letsencrypt.org" is the most common default for most hosts.
0 issue "letsencrypt.org"
2Add a CAA record in your DNS provider's dashboard (whichever company manages this domain's DNS — often your registrar, e.g. GoDaddy, Namecheap, or Cloudflare) on the root domain (leave the name/host field blank or "@"), with this value:
3Confirm it worked: search "caa record checker" and enter nonkyc.io.
Report unlocked.
View all 13 passed checks
DNS Configuration
TLS Protocol Support
TLS Configuration
security.txt (RFC 9116)
DMARC / Email Security
MX Records & Mail Provider
Known Breaches
MTA-STS & TLS Reporting
HSTS Header
Security Headers
Cookie Security
CVE Exposure
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Trust Center
trust.nonkyc.io ↗
Security page
nonkyc.io/security ↗
Privacy Policy
nonkyc.io/privacy ↗
DPA (Data Processing Agreement)
nonkyc.io/dpa ↗
Updated recently
Subprocessors List
nonkyc.io/policies/subprocessors ↗
Tech Stack Detected
Subprocessors
Cloudflare
Similar companies in Fintech / Payments
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
Track
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Track
Top AI vendors by trust score
94 companies · LynxRadar ranking
Track
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking
Track