Security and PCI compliance when using Persolvent
What PCI DSS is
The Payment Card Industry Data Security Standard (PCI DSS) sets security requirements for anyone who stores, processes or transmits card data. Every merchant accepting cards must validate compliance, usually through an annual self-assessment questionnaire.
Shared responsibility
Your provider secures its platform, but you remain responsible for your own environment: your website, devices, staff access and passwords. Ask Persolvent which self-assessment questionnaire applies to your setup and what help it provides.
Reducing your scope
- Use hosted payment pages or tokenised fields so card numbers never touch your servers.
- Never store card numbers in email, spreadsheets or notes.
- Keep software and plugins updated.
- Use unique logins and multi-factor authentication for payment portals.
Protect yourself from phishing
Only log in to payment accounts through the official website you signed up with. Persolvent will never ask for login details, card numbers or payments. If you receive a message claiming to be from any payment provider, verify it by contacting the provider through its official website.