Comparison Overview

FreeAgent

VS

PayPal

FreeAgent

One Edinburgh Quay, Edinburgh, Midlothian, EH3 9QG, GB
Last Update: 2026-04-04
Between 750 and 799

One product.🤳 17 years. 📆 250+ employees. 🧑‍💻Over 200,000 users. 💥There’s so much to say about it all. But here’s the version that fits the character limit. We’re FreeAgent. 👋 We make award-winning accounting software and provide superstar support for small businesses and their accountants and bookkeepers. We’re a friendly bunch with a single goal bringing us all together: making users happier and more successful by putting them in control of their finances. But how did we get here? 🤔 You might remember 2007 as the year the first iPhone, Kindle and Fitbit debuted. It was also the year FreeAgent was launched.💡 Founders Ed, Olly and Roan had all been working as freelance designers or developers for a while. They created FreeAgent out of the frustration that doing the books was just too damn difficult for most of us. So they put their heads together and decided that there must be a better way to deal with their mounting piles of invoices, spreadsheets and receipts. Since our first hire back in 2008, we’ve also worked hard to make FreeAgent a ✨great✨ place to work. We’ve grown to over 250 employees and we continue to build a diverse, high-performing, happy and collaborative team. In early 2018, the company was acquired by the NatWest Group. Our growth has been given a turbo boost, yet we remain operationally independent of the group. 🚀 Today, FreeAgent helps over 200,000 users take care of their finances - from the daily admin to big-picture planning - and do it all happily and successfully. Just like Ed, Olly and Roan set out to do all those years ago. 💙

NAICS: 5112
NAICS Definition: Software Publishers
Employees: 383
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

PayPal

2211 North First Street, San Jose, CA, US, 95131
Last Update: 2026-04-01

We're championing possibilities for all by making money fast, easy, and more enjoyable. Our hope is to unlock opportunities for people in their everyday lives and empower the millions of people and businesses around the world who trust, rely, and use PayPal every day. For support, visit the PayPal Help Center. https://payp.al/help For employment opportunities, check out our job openings in the 'Jobs' tab. We're an equal opportunity employer that welcomes diversity, and offer generous benefits to help you thrive at work and in your free time. NMLS#910457: https://nmlsconsumeraccess.org/

NAICS: 5112
NAICS Definition: Software Publishers
Employees: 36,670
Subsidiaries: 6
12-month incidents
5
Known data breaches
5
Attack type number
4

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/freeagent.jpeg
FreeAgent
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/paypal.jpeg
PayPal
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
FreeAgent
100%
Compliance Rate
0/4 Standards Verified
PayPal
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Software Development Industry Average (This Year)

No incidents recorded for FreeAgent in 2026.

Incidents vs Software Development Industry Average (This Year)

PayPal has 323.73% more incidents than the average of same-industry companies with at least one recorded incident.

Incident History — FreeAgent (X = Date, Y = Severity)

FreeAgent cyber incidents detection timeline including parent company and subsidiaries

Incident History — PayPal (X = Date, Y = Severity)

PayPal cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/freeagent.jpeg
FreeAgent
Incidents

No Incident

https://images.rankiteo.com/companyimages/paypal.jpeg
PayPal
Incidents

Date Detected: 3/2026
Type:Cyber Attack
Attack Vector: Email (Phishing Lures), Malicious LiveChat Sessions
Motivation: Financial Gain, Data Theft
Blog: Blog

Date Detected: 2/2026
Type:Breach
Attack Vector: Coding Error
Blog: Blog

Date Detected: 2/2026
Type:Cyber Attack
Attack Vector: Malicious installer (fake PDF reader/editor)
Motivation: Financial fraud, monetization through stolen ad-session access
Blog: Blog

FAQ

FreeAgent company demonstrates a stronger AI Cybersecurity Score compared to PayPal company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

PayPal company has historically faced a number of disclosed cyber incidents, whereas FreeAgent company has not reported any.

In the current year, PayPal company has reported more cyber incidents than FreeAgent company.

Neither PayPal company nor FreeAgent company has reported experiencing a ransomware attack publicly.

PayPal company has disclosed at least one data breach, while FreeAgent company has not reported such incidents publicly.

PayPal company has reported targeted cyberattacks, while FreeAgent company has not reported such incidents publicly.

PayPal company has disclosed at least one vulnerability, while FreeAgent company has not reported such incidents publicly.

Neither FreeAgent nor PayPal holds any compliance certifications.

Neither company holds any compliance certifications.

PayPal company has more subsidiaries worldwide compared to FreeAgent company.

PayPal company employs more people globally than FreeAgent company, reflecting its scale as a Software Development.

Neither FreeAgent nor PayPal holds SOC 2 Type 1 certification.

Neither FreeAgent nor PayPal holds SOC 2 Type 2 certification.

Neither FreeAgent nor PayPal holds ISO 27001 certification.

Neither FreeAgent nor PayPal holds PCI DSS certification.

Neither FreeAgent nor PayPal holds HIPAA certification.

Neither FreeAgent nor PayPal holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, two peer-facing consensus request handlers assume that the history index is always available and call blockchain.history_store.history_index().unwrap() directly. That assumption is false by construction. HistoryStoreProxy::history_index() explicitly returns None for the valid HistoryStoreProxy::WithoutIndex state. when a full node is syncing or otherwise running without the history index, a remote peer can send RequestTransactionsProof or RequestTransactionReceiptsByAddress and trigger an Option::unwrap() panic on the request path. This issue has been patched in version 1.3.0.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but performs no validation on the url parameter, passing it directly to httpx.stream() with follow_redirects=True. An attacker who controls the URL can reach any host accessible from the server including cloud metadata services and internal network services. This issue has been patched in version 1.5.95.

Risk Information
cvss3
Base: 8.6
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access to all registered tools and agent capabilities. This issue has been patched in version 4.5.97.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any network client can connect, enumerate registered agents, and send arbitrary messages to agents and their tool sets. This issue has been patched in version 4.5.97.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the re engine, blocking the Python thread for hundreds of seconds and causing a complete service outage. This issue has been patched in version 4.5.90.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H