# Stripe security audit — Radar, 3D Secure, card testing protection | RootCore LLC

> Free Stripe security review — Radar rules, CVC and AVS checks, 3D Secure, block lists, dispute rate. Written report within 24 hours.

Page: https://cyber-security.rootcr.com/en/stripe-audit/
Updated: 2026-08-20

---

# Stripe security audit

> **In short:** On default Stripe settings most accounts have no CVC or AVS check enabled, no 3D Secure, and empty block lists. A card testing attack runs straight through. During the free audit we review the account settings and send a written report within 24 hours on what is missing and in which order it is worth fixing.

## Why is it worth a look?

A large share of Stripe accounts runs on the default Radar settings. Attackers know this: an automated script runs stolen card numbers through your payment form, because nothing at your end stops it.

The damage does not come from the attempts themselves but from what follows. Every failed transaction worsens the account's risk profile. Above a 0.75% dispute rate Stripe can suspend the account — funds are frozen, customers cannot pay, and recovery can take weeks or months.

<div class="stats-grid"><div class="stat-card"><div class="stat-val">80%</div><div class="stat-label">of Stripe accounts run on default Radar</div></div><div class="stat-card"><div class="stat-val">$25B</div><div class="stat-label">annual global card fraud loss</div></div><div class="stat-card"><div class="stat-val">0.75%</div><div class="stat-label">dispute rate above which Stripe can suspend an account</div></div></div>

## What do we review?

| Area | What we check |
|---|---|
| Radar rules | Whether CVC, AVS and 3D Secure rules are enabled or left at their default off state |
| Card testing protection | Whether velocity limits exist and whether probing patterns are recognised |
| 3D Secure / SCA | Whether strong customer authentication works on supported cards |
| Block lists | Whether e-mail, IP, BIN and country lists are populated or empty |
| Transaction patterns | Decline rate on recent charges, country mismatches, suspicious clustering |
| Dispute rate | The current rate and the distance from the suspension threshold |
| Webhook and descriptor | Webhook signature verification and the statement descriptor shown on card statements |

## What the report looks like

<div class="terminal terminal--narrow"><div class="terminal-bar" aria-hidden="true"><i></i><i></i><i></i><em>rootcore-stripe-audit</em></div><div class="terminal-body"><span class="t-accent">RootCore Stripe Security Audit</span><br><span class="t-dim">------------------------------</span><br><br><span class="t-red">&#x2717;</span> Radar: CVC check <span class="t-red">DISABLED</span><br><span class="t-red">&#x2717;</span> Radar: Postal code check <span class="t-red">DISABLED</span><br><span class="t-red">&#x2717;</span> Radar: 3D Secure <span class="t-red">DISABLED</span><br><span class="t-red">&#x2717;</span> Block lists: <span class="t-red">ALL EMPTY</span> (0 items)<br><span class="t-green">&#x2713;</span> Webhook signature verification <span class="t-green">OK</span><br><span class="t-green">&#x2713;</span> Statement descriptor <span class="t-green">SET</span><br><span class="t-yellow">&#x26A0;</span> Dispute rate: <span class="t-yellow">0.00%</span> (no data)<br><br><span class="t-dim">Score:</span> <span class="t-red" style="font-size:1.1em;font-weight:700">3/10</span> <span class="t-red">HIGH RISK</span><br><br><span class="t-dim">4 critical gaps. This is a sample report, not live data.</span></div></div>

## How does it work?

1. **Request.** Fill in the [form](/en/#kapcsolat) or send an e-mail. You do not need to hand over API keys or passwords.
2. **Review.** We go through the list above. Where a setting is not visible from the outside, we write down exactly which screen to look at — or, if that is easier, we go through it together on a call.
3. **Report.** Within 24 hours you get a written summary: what is in order, what is missing, and in which order to fix it. It comes with no obligation.
4. **Configuration, if you want it.** We can implement the fixes, or your own developer can work from the report.

## What not to expect from us

- **We do not ask for live API keys** for the audit, and we change nothing in your account without permission.
- **We do not see card data** — Stripe does not hand it out, and we do not need it.
- **We do not promise zero.** Fraud attempts cannot be eliminated; protection is about making the attempt not worth it and keeping it from doing damage.

## Continuous protection

A one-off audit is a snapshot. If you also need continuous monitoring of payment traffic — maintaining velocity limits, refreshing block lists, alerting on attack patterns, watching the dispute rate — we have a monthly plan for that, cancellable and with no minimum term.

<div class="price-grid"><div class="price-card"><div class="price-name">Audit</div><div class="price-amount">Free</div><div class="price-period">one-off</div><ul class="price-features"><li>Full Radar review</li><li>Block list audit</li><li>Transaction pattern review</li><li>Written report within 24 hours</li></ul><a class="price-btn outline" href="/en/#kapcsolat">Request audit</a></div><div class="price-card featured"><div class="price-name">Continuous protection</div><div class="price-amount">$29</div><div class="price-period">per month, cancellable</div><ul class="price-features"><li>Full Radar configuration and setup</li><li>Transaction monitoring</li><li>Card testing alerts</li><li>Block lists kept up to date</li><li>3D Secure + CVC/AVS enforcement</li><li>Dispute rate monitoring</li><li>Daily, weekly or monthly reporting</li></ul><a class="price-btn" href="https://buy.stripe.com/3cI00bcMgcgz6NgepR1wY05">Subscribe</a></div></div>

<div class="stripe-mark"><svg viewBox="0 0 468 222.5" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"><path d="M414 113.4c0-25.6-12.4-45.8-36.1-45.8-23.8 0-38.2 20.2-38.2 45.6 0 30.1 17 45.3 41.4 45.3 11.9 0 20.9-2.7 27.7-6.5v-20c-6.8 3.4-14.6 5.5-24.5 5.5-9.7 0-18.3-3.4-19.4-15.2h48.9c0-1.3.2-6.5.2-8.9zm-49.4-9.5c0-11.3 6.9-16 13.2-16 6.1 0 12.6 4.7 12.6 16h-25.8zm-63.5-36.3c-9.8 0-16.1 4.6-19.6 7.8l-1.3-6.2h-22v116.6l25-5.3.1-28.3c3.6 2.6 8.9 6.3 17.7 6.3 17.9 0 34.2-14.4 34.2-46.1-.1-29-16.6-44.8-34.1-44.8zm-6 68.9c-5.9 0-9.4-2.1-11.8-4.7l-.1-37.1c2.6-2.9 6.2-4.9 11.9-4.9 9.1 0 15.4 10.2 15.4 23.3 0 13.4-6.2 23.4-15.4 23.4zM209.7 65.9l25.1-5.4V40l-25.1 5.3v20.6zm0 7.3h25.1v86.4h-25.1V73.2zm-30.8 7.3l-1.6-7.3h-21.6v86.4h25V97.9c5.9-7.7 15.9-6.3 19-5.2v-23c-3.2-1.2-14.9-3.4-20.8 5.8zM132.1 50.9l-24.4 5.2-.1 79.1c0 14.6 11 25.4 25.6 25.4 8.1 0 14-1.5 17.3-3.3V138c-3.2 1.3-18.9 5.8-18.9-8.7V93.3h18.9V73.2h-18.9l.5-22.3zM50.4 94.5c0-3.7 3.1-5.2 8.1-5.2 7.3 0 16.5 2.2 23.8 6.1V72.8c-8-3.2-15.9-4.4-23.8-4.4C37.4 68.4 22 80.6 22 99.4c0 29.1 40.1 24.4 40.1 37 0 4.4-3.8 5.8-9.2 5.8-7.9 0-18.1-3.3-26.1-7.6v23c8.9 3.8 17.9 5.5 26.1 5.5 21.5 0 36.3-10.6 36.3-29.7-.1-31.4-40.8-25.8-40.8-37.9z"/></svg><span class="stripe-mark-text">Stripe Technology Partner</span></div>

## Frequently asked questions

### Is the audit really free?

Yes. You get the report and you decide whether you want help with the fixes. There is no hidden cost and no automatic subscription.

### Do I have to give you an API key?

No. The audit is based on account settings that we either review together or that you copy from the screens we name. Never send a live secret key to anyone — including us.

### How long does it take?

The review itself is short; the report goes out within 24 hours. If you ask for a joint walkthrough, half an hour is usually enough.

### Is this not Stripe's job?

Stripe provides the tools — Radar rules, 3D Secure, block lists — but configuring them is the merchant's job. The default state is deliberately permissive so that nobody's payments break; tightening it is your decision.

### What if my account has already been suspended?

Then the audit is about what led there and what you need to be able to show Stripe. Lifting a suspension is Stripe's decision — we do not promise that; a documented clean-up is the best thing you can do.
