Skip to content

Security

The PCI DSS certificate | MULENPAY

Compliance with the payment card data security standard is backed by a certificate. Below are its details, the document itself and what follows from it for a store taking payments.

Document

Certificate details

Everything written on the document is here as text: neither a search engine nor someone on a phone can read figures off an image

Holder
RBY Commerce Ltd
Standard
PCI DSS 4.0.1
Certificate ID
873-JJD939333
Date of issue
22 June 2026
Valid until
22 June 2027
Validated by
Annual QSA audit, Audit Aliance Ltd

What it is

What PCI DSS is

The standard was written by the card schemes themselves — not by a government or a trade body

Who created it

The PCI Security Standards Council, founded by Visa, Mastercard, American Express, Discover and JCB. Its requirements bind anyone who processes or transmits card data.

What it requires

Encryption of card data, restricted access to it, logging, regular network scanning and review of processes — not only of technology.

How it is proven

By an audit from a Qualified Security Assessor (QSA), once a year and on site. The certificate is issued for a year and needs a fresh audit after that.

For merchants

What it changes for you

Card numbers never reach you

The buyer enters card details on the payment service's side. The number, expiry and security code never touch your server — so there is nothing for you to store.

Fewer requirements on you

How much of the standard applies to the store itself depends on the integration: the less card data passes through your code, the shorter your own questionnaire.

A document you can check

A certificate is not a badge on a page: it has a number, a validity period and an auditor, and all of that can be verified.

Plainly

What the certificate does not do

This part usually goes unsaid, and it is worth knowing before you sign up

It does not cancel chargebacks

The standard is about protecting card data, not about disputes over transactions. The dispute procedure is set out separately, in the refunds and chargebacks policy.

It does not replace fraud screening

PCI DSS does not decide whether to approve or decline a payment. 3-D Secure and anti-fraud do that — they are different mechanisms.

It does not cover your site

The certificate is issued to the service and covers its perimeter. The security of your own site, credentials and admin panel stays with you.

Questions and answers

Frequently asked

The document carries a number — 873-JJD939333 — and names the auditor who carried out the review. The file itself is open from a link on this page rather than hidden behind a form. Its status can be confirmed with the auditor: they issued the document and stand behind it.

Ready to take payments?

Send a request — a manager will pick a plan and help with the integration.

Phone

+1 (767) 555-0147

International number

Telegram bot

@mulen_support_bot

Quick answers 24/7

Legal address

RBY Commerce Ltd.

8 Copthall, Roseau Valley, 00152, Commonwealth of Dominica

Leave a request

Fill out the form — a manager will get in touch, tailor the terms and help with the integration.

By clicking the button you agree to the processing of personal data.

TelegramTelegram