PaymentCompanies.com — an index of the payments industry
Infrastructure & EnablementOrchestration

Spreedly

A payments orchestration platform and PCI DSS Level 1 card vault that stores payment credentials for the merchant and routes transactions across more than a hundred third-party payment services.

Last reviewed July 2026 · independently researched · not sponsored

What Spreedly actually is

Spreedly is infrastructure that sits in front of a merchant's payment providers rather than replacing any of them. Credentials are captured into Spreedly's vault, converted into Spreedly tokens, and presented to whichever gateway, acquirer or payment service the merchant chooses. The same stored credential works with more than one provider, and with a new one, without being collected again.

The company is unusually direct about its own boundary. Its FAQ states: "We never touch your money. Instead, money flows from your customer to your gateway/merchant account." That answers most of the questions buyers ask. The merchant keeps the acquiring relationship, the underwriting, the settlement account and the chargeback liability; Spreedly's role is credential custody plus decisions about where each authorization goes.

Payments orchestration. A software layer between a merchant's checkout and its payment providers that decides, per transaction, which provider gets the authorization — and what to do when that provider declines or is unavailable. It exists because large merchants rarely use one processor: they use several, for redundancy, for local acquiring, and for leverage in negotiations.

Two mistaken identities are worth ruling out. Spreedly is not a payment gateway, because it does not connect to an acquirer on its own behalf, and not a processor, holding no acquiring registration and doing no underwriting or settlement. It is also distinct from the payments-intelligence vendors it gets listed beside: Spreedly is in the authorization path and executes the routing decision, where an analytics vendor reads the outcome afterwards.

How Spreedly works, and what it changes about lock-in

Credentials are captured through methods that keep card data off the merchant's own servers — a transparent redirect posting the card form directly to Spreedly, or an iframe rendering Spreedly-controlled fields inside the merchant's checkout. The card never lands on merchant infrastructure, which is how the merchant reduces its PCI DSS scope: the systems that touch cardholder data and therefore fall under the standard's audit requirements. That is the difference between a short self-assessment questionnaire and an expensive annual assessment.

The vault is the lock-in, and moving it is the cost. When a merchant's stored cards live inside its processor, changing processors means migrating a card vault — slow, negotiated, sometimes obstructed, and it leaves the renewal conversation weaker than it looks on paper. Holding the vault at a neutral third party removes that friction. Spreedly's FAQ takes the position that "We believe it's your data, not ours" and says customers can export credit card tokens to other PCI-certified organizations provided the transfer is done securely. That is why many large merchants buy this product, and it should be tested in the contract rather than taken from a FAQ page.

On top of vaulting sits the orchestration: routing rules, failover when a provider declines or is down, smart retries, and a workflow engine across the connected payment services. Alongside it Spreedly sells the optimization tooling that only makes sense when you hold the credentials — network tokenization, account updater, 3-D Secure and, since the 2025 Dodgeball acquisition, fraud orchestration.

Network tokenization and account updater. Two fixes for one problem: stored cards go stale. A network token is issued by Visa or Mastercard in place of the card number and survives reissue, so a renewal keeps working after the customer's card is replaced. Account updater pushes refreshed card details from the issuer to the merchant. Both matter enormously to subscription businesses and barely at all to one-off retailers.

How Spreedly prices

Pricing is partly published and mostly not. As of July 2026 Spreedly shows a starting price for its entry Independent Vault tier — the standalone credential-custody product unbundled on 15 July 2026, which lets a merchant buy credential independence without the routing layer and add orchestration later — and quotes everything else through sales. The upper tier, Performance Optimization, covers routing, network tokenization, account updater, smart retries, 3-D Secure and fraud prevention.

That split has a consequence: every capability that makes Spreedly an orchestration platform rather than a vault sits behind the sales conversation, so a buyer cannot compare it against a competing orchestrator on cost from public information. Monthly minimums, contract length, termination terms and service levels are all unpublished, and there is no standard customer agreement.

The structural point that survives the absence of rates: because Spreedly does not settle funds, its fees are additive rather than substitutive. The business case must be made out of recovered revenue — authorizations saved by failover, renewals saved by network tokens and account updater, chargebacks avoided by fraud tooling — or out of avoided cost, mainly PCI scope reduction and removal of future re-vaulting expense. A merchant who cannot quantify one of those is buying architecture, not economics.

Where Spreedly is genuinely strong

Orchestration across a large provider set. Provider-agnostic routing, failover, smart retries and a workflow engine across more than a hundred connected payment services — gateways, acquirers, digital wallets, alternative payment methods and fraud vendors. For a merchant already running two or three acquirers, this replaces parallel integrations with one.

The vault, and the compliance posture behind it. Spreedly is a PCI DSS Level 1 service provider listed on the Visa Global Registry of Service Providers and the Mastercard SDP list, SOC 2 Type 2 audited with no exceptions, a certified vendor-neutral network tokenization provider with Visa and Mastercard, and holder of EMVCo-certified 3-D Secure 2 SDKs. It is GDPR compliant, certified under the EU-US, UK Extension and Swiss-US Data Privacy Frameworks, and a Cloud Security Alliance STAR Level 1 member — close to a complete answer for an enterprise security review.

Stored-credential commerce. Spreedly says stored-credential transactions were roughly 40% of platform volume in 2026, up from 34% in 2022. Subscription merchants are the natural buyer: tokenization, account updater and retry logic attach to renewals that would otherwise fail.

Fraud orchestration. The September 2025 Dodgeball acquisition added fraud prevention and chargeback reduction alongside 3-D Secure; Dodgeball's CEO joined Spreedly and was later listed as EVP of Product Strategy, suggesting it was absorbed rather than parked.

Cross-border reach without cross-border plumbing. Merchants can route to local acquirers and local methods — Pix Automático and NuPay among the named ones — across more than a hundred countries, though the FX and settlement are done downstream. Spreedly gives access to local acquiring; it does not perform it.

Where Spreedly falls short

It cannot get you accepted. Spreedly performs no underwriting, so a merchant in a high-risk category gains nothing here: it can only route to providers that already approved that merchant. Orchestration multiplies the value of acceptance you have; it does not create acceptance. Its agentic-commerce messaging is similarly forward-looking: Spreedly markets the vault as groundwork for AI-initiated purchases but publishes no agentic payment protocol.

You cannot compare it on price before engaging sales. Only the entry vault tier carries a published starting price; everything in the orchestration tier is quoted, so the first round of any competitive comparison is qualitative by force.

It adds a dependency to every authorization. A layer between checkout and the gateway is a component whose availability affects every transaction the merchant takes. That is the central architectural trade of the category, and why uptime history, incident communications and contractual service levels deserve harder diligence than the feature list.

Single-gateway merchants are paying to solve a problem they do not have. With one provider and no near-term plan for a second, the routing engine has nothing to route between and the fee sits on top of processing costs with no offsetting recovery. The vault-only tier is the defensible purchase for that merchant.

Large parts of a payments stack are simply absent. No card acquiring, no in-person point of sale, no payouts, no instant transfers, no payment links, no invoicing. ACH and eCheck exist only through whichever connected gateways support them, since Spreedly holds no bank rails of its own. These are the boundaries of the category rather than failures against Spreedly's claims, but a buyer expecting a full stack should know where they sit.

Ownership, history and scale

Spreedly was founded in Durham, North Carolina in 2007 as a different business, pivoting to payments infrastructure around 2012 and 2013 and raising an additional $500,000 in 2013. It scaled quietly and took a $75M growth investment from Spectrum Equity in 2019. Spectrum Equity remains the named institutional backer as of July 2026, though whether that position is majority or minority, and whether any subsequent round has occurred, is not disclosed. Founders are not named on Spreedly's own About page and the public record is inconsistent enough that guessing would be irresponsible; employee count is unpublished.

Two events define the current product. In September 2025 Spreedly acquired fraud orchestration company Dodgeball, adding fraud prevention and chargeback reduction to a platform that had stopped at 3-D Secure. In July 2026 it unbundled the Payment Vault as a standalone product — a direct answer to the objection that the platform was all-or-nothing.

On scale, Spreedly said in January 2026 that annual gross merchant volume was expected to exceed $60 billion for 2025, up from $50 billion in 2024, with more than 400 customers across more than 100 countries and enterprise growth of 54% year over year in the third quarter of 2025. Those are company figures, not audited, and the 2025 volume was an expectation rather than a confirmed result. No enforcement actions or litigation were found.

How to evaluate Spreedly before you sign

The diligence that matters is not about features. It is about three things a vault-and-routing vendor can do that ordinary software cannot: sit in your authorization path, hold your customers' cards, and become expensive to leave.

  • Get the token export commitment into the contract. The FAQ says customers can export tokens to other PCI-certified organizations, but a FAQ is not a contractual right. Ask for the process, format, timescale, any professional-services fees, and what happens if the relationship ends badly.
  • Diligence availability like the dependency it is. Request historical uptime, incident post-mortems, the contractual service level and the remedy when it is missed, and ask what your checkout does when Spreedly is unreachable — whether a bypass path to a gateway exists, and who owns it.
  • Count your providers honestly, then build the business case out of recovered revenue. One acquirer and no funded plan for a second means pricing the vault-only tier. Where a second provider is real, measure authorization uplift from failover, renewal recovery from network tokenization and account updater, and chargeback reduction against the software fee.
  • Confirm which downstream providers support what you need. ACH, bank debit, local methods and wallets come from connected gateways, so verify method by method and country by country. Ask for compliance evidence rather than the badge list: the current PCI DSS Attestation of Compliance and the SOC 2 Type 2 report.
  • Pin down commercial terms early, since none are public — minimum commitment, contract length, price-change rights, renewal mechanics and termination notice. Negotiate them before you have migrated your vault.

Capability assessment

Every company profiled on this site is assessed against the same eighteen dimensions, so the profiles can be read against one another. Each rating carries one sentence of evidence. There is no score out of ten, because a score is not defensible and a sentence is.

Core strength means a primary, differentiating capability. Supported means genuinely offered and documented, but not a differentiator. Limited means partial, geographically restricted, gated behind an enterprise tier, or delivered through a third party. Not offered means what it says. Unclear means the company markets the capability but does not document it well enough to judge — which is itself a finding.

Card processing
Not offered
Spreedly does not acquire or process card transactions itself and states in its own FAQ that it never touches the merchant's money, which flows from the customer to the merchant's own gateway or merchant account.
Online & e-commerce
Core strength
Spreedly's entire product is built for card-not-present online and in-app commerce, capturing credentials through transparent redirect and iframe methods so card data never touches the merchant's servers.
In-person / POS
Not offered
Spreedly sells no terminals, card readers or in-person point-of-sale software.
Mobile & contactless
Limited
Spreedly supports Apple Pay and Google Pay as digital wallet payment methods within online and in-app checkout, but offers no contactless in-person acceptance.
Recurring & subscription billing
Supported
Spreedly is heavily used by recurring merchants for stored-credential transactions, which the company said represented about 40% of platform volume in 2026, up from 34% in 2022, but it does not sell a subscription-management or invoicing product.
ACH & bank debit
Limited
ACH and eCheck are available only through the subset of connected gateways that support them, since Spreedly routes to third-party providers rather than holding bank rails of its own.
Instant / real-time payments
Not offered
Spreedly does not offer instant payouts, RTP or FedNow transfers; it is an authorisation-path and credential layer, not a funds-movement provider.
Cross-border & FX
Supported
Spreedly enables cross-border commerce by letting merchants route to local acquirers and local payment methods in more than 100 countries, but the FX and settlement are performed by those downstream providers, not by Spreedly.
Embedded payments / PayFac
Not offered
Spreedly does not sponsor, underwrite or onboard sub-merchants and holds no payment facilitator registration.
Payment orchestration
Core strength
Payments orchestration is Spreedly's defining product: PSP-agnostic routing, failover, smart retries and a workflow engine across more than 100 connected payment services.
Payment links & invoicing
Not offered
Spreedly provides no hosted payment links, invoicing or billing product; it is an API and vault layer behind the merchant's own checkout.
High-risk acceptance
Limited
Spreedly performs no underwriting, so whether a high-risk merchant can transact depends entirely on the acquirers and PSPs that merchant has already been approved by.
Fraud & risk tooling
Core strength
Spreedly acquired fraud orchestration company Dodgeball in September 2025 and now sells fraud prevention and chargeback reduction alongside 3DS as part of its Performance Optimization tier.
Developer API & docs
Core strength
Spreedly is an API-first product with published developer documentation, transparent redirect and iframe credential-capture methods, iOS and Android SDKs and a public payment services directory.
Fee transparency
Limited
As of July 2026 Spreedly publishes a starting price only for its entry vault tier, with the orchestration and optimisation tier gated behind a sales conversation.
Vertical specialisation
Limited
Spreedly markets to recurring, travel, marketplace and enterprise retail segments but sells a single horizontal platform rather than vertical-specific products.
Crypto & stablecoin
Not offered
Spreedly documents no cryptocurrency or stablecoin acceptance or settlement product as of July 2026.
Agentic & AI-initiated payments
Limited
Spreedly markets its vault and Performance Optimization tier as groundwork for agentic commerce where AI agents initiate purchases, and has said the Dodgeball acquisition lays the foundation for an AI-powered payments assistant, but it publishes no shipped agentic payment protocol.

Who Spreedly suits

  • Merchants who already have two or more acquirers or PSPs and want one integration, one token vault and routing between them rather than maintaining parallel integrations.
  • Recurring and subscription merchants for whom stored credentials are the business — Spreedly adds network tokenisation, account updater and smart retries on top of whichever gateways they use.
  • Merchants planning to change or renegotiate with a processor, because holding the vault outside the processor removes the re-vaulting cost that makes migration expensive.
  • Global merchants that need local acquirers and local payment methods in many countries without integrating each one directly.
  • Companies that want to stay out of PCI scope on their own servers by using Spreedly's transparent redirect or iframe capture into a Level 1 vault.

Who Spreedly is a poor fit for

  • Merchants who need someone to underwrite them, settle their funds or take risk — Spreedly's own FAQ states 'We never touch your money', so it does not replace an acquirer, does not provide a merchant account and does not carry chargeback liability.
  • Single-gateway merchants with no near-term plan to add a second provider: orchestration and vault independence are being paid for to solve a problem those merchants do not yet have, and the cost sits on top of existing processing fees.
  • Buyers who need to compare cost before engaging sales — only the entry vault tier has a published starting price as of July 2026, and everything that makes Spreedly an orchestration platform (routing, network tokenisation, account updater, 3DS, fraud) is in the sales-quoted tier.
  • Merchants in high-risk categories looking for an easier path to acceptance: Spreedly performs no underwriting and cannot approve a merchant that its downstream PSPs will not accept.
  • Teams that cannot absorb an additional dependency in the authorisation path — inserting an orchestration layer between checkout and the gateway adds a component whose availability affects every transaction.
  • Businesses needing in-person acceptance, payouts, invoicing or payment links, none of which Spreedly offers.

Competitors and alternatives

CompanyWhy a business would choose it instead
PrimerA newer orchestration-first competitor with a no-code workflow builder; a merchant would switch for the visual routing tooling.
Gr4vyCloud-infrastructure-per-tenant orchestration; chosen by merchants who want isolated deployment rather than a shared multi-tenant platform.
Basis Theory / VGS (Very Good Security)Vault-only alternatives for merchants who want token custody and PCI descoping without paying for an orchestration layer.
Payoneer / CellPoint DigitalCellPoint Digital in particular competes for airline and travel orchestration, a segment where Spreedly also sells.
Adyen or Stripe (single-provider consolidation)The realistic alternative for many merchants is to consolidate onto one full-stack provider and give up orchestration entirely, trading flexibility for a simpler stack.
PaydockAnother orchestration and vault provider competing on PSP-agnostic routing and fraud orchestration.

Spreedly — frequently asked questions

Is Spreedly a payment gateway or a payment processor?

Neither. Spreedly is a card vault and payments orchestration layer that sits in front of the gateways and processors a merchant already uses. Its own FAQ states: "We never touch your money. Instead, money flows from your customer to your gateway/merchant account." The merchant keeps its acquiring relationship, its settlement account and its chargeback liability, and Spreedly holds no acquiring registration and does no underwriting.

Can I get my card tokens out of Spreedly if I leave?

Spreedly's FAQ takes the position that "We believe it's your data, not ours" and states that customers can export credit card tokens to other PCI-certified organizations, provided the transfer is done securely. Spreedly also markets its tokens as portable across more than 100 payment providers without re-vaulting. Because Spreedly publishes no standard customer agreement, the export process, timescale and any associated fees should be confirmed in the contract rather than relied on from a public FAQ.

How many payment providers does Spreedly connect to?

Spreedly states support for more than 100 payment providers as of July 2026, spanning gateways, acquirers, digital wallets, alternative and local payment methods, and fraud vendors. The company publishes a public payment services directory but no audited count, so treat the figure as company-stated. Which specific methods are available to a given merchant depends on the providers that merchant is connected to, not on Spreedly.

What compliance certifications does Spreedly hold?

Spreedly is a PCI DSS Level 1 service provider listed on the Visa Global Registry of Service Providers and the Mastercard SDP compliant service provider list, and is SOC 2 Type 2 audited with no exceptions. It holds EMVCo-certified 3-D Secure 2 SDKs for iOS and Android, is a certified vendor-neutral network tokenization provider with Visa and Mastercard, is GDPR compliant and certified under the EU-US, UK Extension and Swiss-US Data Privacy Frameworks, and is a Cloud Security Alliance STAR Level 1 member.

Does Spreedly publish its pricing?

Only partly. As of July 2026 a starting price is published for the entry Independent Vault tier, which Spreedly unbundled and launched as a standalone product in July 2026. The Performance Optimization tier — covering routing, network tokenization, account updater, smart retries, 3-D Secure and fraud prevention — requires contacting sales. Monthly minimums, contract length and early-termination terms are not published.

Will Spreedly help a high-risk merchant get approved?

No. Spreedly performs no underwriting and takes no merchant risk, so it can only route transactions to acquirers and payment service providers that have already approved the merchant. A business that cannot obtain acceptance from a processor will not obtain it by adding an orchestration layer. Whether a high-risk merchant can transact through Spreedly depends entirely on its existing downstream providers.

How big is Spreedly?

Spreedly said in January 2026 that annual gross merchant volume was expected to exceed $60 billion for 2025, up from $50 billion in 2024, with more than 400 customers across more than 100 countries and enterprise-segment growth of 54% year over year in the third quarter of 2025. These are company-stated figures and the 2025 volume was framed as an expectation rather than a confirmed result. Employee count is not published.

Sources

This profile was built from the following primary and secondary sources. Where sources disagreed, the disagreement is stated in the text rather than resolved silently.

Not verified. The following could not be confirmed from a source we consider reliable, and is therefore not asserted anywhere above.
  • Founders: Spreedly's own About page names no founders. Nathaniel Talbott is widely identified as Spreedly's founder and served as CTO, while Crunchbase lists current CEO Justin Benson as a co-founder. The founder list is therefore left empty rather than guessed.
  • Ownership stake: Spectrum Equity's $75M 2019 investment is confirmed by Spectrum Equity's own portfolio page, but whether it is a majority or minority position, and whether any secondary or subsequent round has occurred since, could not be confirmed.
  • Employee count: not published by Spreedly and not found in a primary source.
  • Contract length, minimum commitment, early-termination terms and SLA: Spreedly does not publish a standard customer agreement, so none of these could be verified.
  • Exact number of connected payment services: Spreedly says 'more than 100' but publishes no audited count.
  • Dodgeball acquisition price: not disclosed.
  • Whether the 2025 GMV figure of 'expected to exceed $60 billion' was subsequently confirmed as actual: the January 2026 release stated it as an expectation.