- Docs
- Compliance
- Compliance Frameworks
- Payment Card Industry (PCI)
Payment Card Industry (PCI)
The Payment Card Industry Data Security Standard (PCI DSS) is a global framework designed to protect credit card data. It applies to all entities that store, process, or transmit cardholder information.
Files.com PCI Compliance Status
Files.com is a Level 2 PCI DSS Certified Service Provider. This certification supports two primary scenarios:
- Processing our own billing transactions: Files.com is certified to securely handle cardholder data for its own billing and account management functions. All credit card transactions are processed through PCI-compliant third-party providers. Specifically, we use Stripe, Braintree, and PayPal, all of whom are also PCI–certified.
- Storing cardholder data on behalf of customers: Files.com is also certified to store PCI-regulated cardholder data for customers that are subject to PCI DSS, provided those customers maintain their own overall PCI compliance.
Files.com is open to pursuing Level 1 PCI certification specifically for this customer storage scenario, if required as part of a customer engagement. While the audit scope would expand, there is no material difference in the actual work we’ve already done to meet PCI standards.
Our most recent Attestation of Compliance (AOC) is available upon request. Please contact your Account Executive or Account Manager to obtain a copy.
About PCI DSS
PCI DSS is managed by the PCI Security Standards Council, a global body founded by major payment brands including Visa, MasterCard, American Express, Discover, JCB, and UnionPay.
The standard includes 12 key requirements designed to protect cardholder data and maintain a secure environment. These requirements fall under broader goals such as securing networks, managing vulnerabilities, and enforcing access control.
Organizations are expected to:
- Install and maintain secure firewalls
- Encrypt cardholder data
- Use antivirus and anti-malware tools
- Restrict access to cardholder data on a need-to-know basis
- Monitor and test networks regularly
- Maintain a company-wide security policy
Compliance is validated annually through assessments and security scans, based on the organization’s role and transaction volume.