4 ms·
FYI we are complying with PCI DSS when you use this site - you can read details in the FAQ
by zbruhnke 7y ago
FYI we are complying with PCI DSS when you use this site - you can read details in the FAQ
- snazz 7y agoDo we have proof of that? I think the fact that we're taking your word for everything so far is the source of the discomfort here.
- toomuchtodo 7y agoSort of humorous comment, as PCI DSS is self assessment and attestation of compliance. If OP states they’ve met their burden, that’s all that’s required at their scale.
- snazz 7y agoReally? I evidently know nothing of the matter, but you're saying that the auditors only get involved when they become a larger operation?
- toomuchtodo 7y agoYep. Card networks can also unilaterally decide your level. https://www.pcicomplianceguide.org/faq/#4 https://www.pcicomplianceguide.org/faq/#4 Disclaimer: I work in governance/risk/compliance, but have not performed PCI compliance work in the last several years.
- gowld 7y agoPCI DSS assessments are signed by natural persons, not arbitrary HTML content.
- deleted 7y ago[deleted]
- toomuchtodo 7y agoNatural persons who are rarely, if ever, pursued when breaches occur.
- craftyguy 7y agoAnyone can make a FAQ on the web. Not everyone can prove compliance with PCI DSS.
- chipperyman573 7y agoThe same could be said about any other online merchant...
- igetspam 7y agoIt could but they should be able to provide an Attestation of Compliance. If they can't, then you can trust that they're PCI compliant.