[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"questions:item:en:what-is-pci-dss":3},{"id":4,"title":5,"answer":6,"body":7,"category":94,"description":95,"extension":96,"meta":97,"modifiedAt":98,"navigation":99,"pairId":100,"path":101,"publishedAt":102,"question":103,"relatedPath":79,"seo":104,"seoTitle":105,"sitemap":106,"slug":107,"stem":108,"translationSlug":109,"__hash__":110},"questions_en\u002Fen\u002Fquestions\u002Fwhat-is-pci-dss.md","What Is Pci Dss","PCI DSS is the international security standard for payment card data. It defines how card details must be stored, transmitted and processed. Level 1 is the highest certification tier, held by organisations handling the largest transaction volumes.",{"type":8,"value":9,"toc":87},"minimark",[10,13,18,34,37,41,44,52,56,59,73],[11,12,6],"p",{},[14,15,17],"h2",{"id":16},"what-the-standard-covers","What the standard covers",[19,20,21,25,28,31],"ul",{},[22,23,24],"li",{},"Encryption of data in transit and at rest.",[22,26,27],{},"Access control: who can see card data and under what conditions.",[22,29,30],{},"Infrastructure protection: network segmentation, patching, monitoring.",[22,32,33],{},"Logging and regular vulnerability testing.",[11,35,36],{},"Compliance is proven by audit, not by declaration, and has to be renewed.",[14,38,40],{"id":39},"what-it-changes-for-the-merchant","What it changes for the merchant",[11,42,43],{},"What matters most is where card details are entered. If they go into a certified provider's payment form, they never pass through the merchant's site, logs or databases. Responsibility for protecting them stays with the provider.",[11,45,46,47,51],{},"Hence a simple rule: ",[48,49,50],"strong",{},"never collect card numbers on your side",". Not in an order form, not in support correspondence, not in a CRM. The moment card data reaches you, the standard's requirements apply to you as well.",[14,53,55],{"id":54},"what-stays-with-the-merchant","What stays with the merchant",[11,57,58],{},"A provider's certification does not cover everything:",[19,60,61,64,67,70],{},[22,62,63],{},"Dashboard credentials and API keys: never stored in plain text or sent over messengers.",[22,65,66],{},"Keeping the site and payment modules updated.",[22,68,69],{},"Limiting staff permissions: not everyone needs access to transactions.",[22,71,72],{},"Responding to suspicious activity.",[11,74,75,76,81,82,86],{},"MulenPay operates under PCI DSS Level 1 v4.0, with TLS 1.2 and 3-D Secure 2.0 — details on the ",[77,78,80],"a",{"href":79},"\u002Fabout","about page",". On authentication, see the ",[77,83,85],{"href":84},"\u002Fen\u002Fquestions\u002Fwhat-is-3d-secure","3-D Secure answer",".",{"title":88,"searchDepth":89,"depth":89,"links":90},"",2,[91,92,93],{"id":16,"depth":89,"text":17},{"id":39,"depth":89,"text":40},{"id":54,"depth":89,"text":55},"security","PCI DSS is the payment card data security standard. What Level 1 means, why a provider's certification takes load off the merchant and what stays.","md",{},null,true,"question-12","\u002Fen\u002Fquestions\u002Fwhat-is-pci-dss","2026-08-11","What is PCI DSS and why does a merchant need it?",{"description":95},"What is PCI DSS and what certification gives a merchant",{"loc":101},"what-is-pci-dss","en\u002Fquestions\u002Fwhat-is-pci-dss","chto-takoe-pci-dss","gvQXPMeL1q1-4r8e29SYj_PX44jYnDVozju0DcGzTYQ"]