PCI DSS is the international security standard for payment card data. It defines how card details must be stored, transmitted and processed. Level 1 is the highest certification tier, held by organisations handling the largest transaction volumes.
What the standard covers
- Encryption of data in transit and at rest.
- Access control: who can see card data and under what conditions.
- Infrastructure protection: network segmentation, patching, monitoring.
- Logging and regular vulnerability testing.
Compliance is proven by audit, not by declaration, and has to be renewed.
What it changes for the merchant
What matters most is where card details are entered. If they go into a certified provider's payment form, they never pass through the merchant's site, logs or databases. Responsibility for protecting them stays with the provider.
Hence a simple rule: never collect card numbers on your side. Not in an order form, not in support correspondence, not in a CRM. The moment card data reaches you, the standard's requirements apply to you as well.
What stays with the merchant
A provider's certification does not cover everything:
- Dashboard credentials and API keys: never stored in plain text or sent over messengers.
- Keeping the site and payment modules updated.
- Limiting staff permissions: not everyone needs access to transactions.
- Responding to suspicious activity.
MulenPay operates under PCI DSS Level 1 v4.0, with TLS 1.2 and 3-D Secure 2.0 — details on the about page. On authentication, see the 3-D Secure answer.