Cheddar Gateway: Is it PCI Compliant; Exporting credit card Data
We are considering using CheddarGetter as well as the Cheddar Gateway. Since it will be holding our user's credit card numbers, I have some specific questions:
1) Is it PCI Level 1 Compliant?
2) Who did the audit? Do we have access to the audit? (Basically, is there some sort of verification that it is in fact PCI Level 1 Compliant?)
3) If we choose to leave CheddarGateway, is the credit card data exportable to another level 1 PCI Compliant handler? What is the process?
Thanks!
Michelle
Discussions are closed to public comments.
If you need help with Cheddar please
start a new discussion.
Keyboard shortcuts
Generic
? | Show this help |
---|---|
ESC | Blurs the current field |
Comment Form
r | Focus the comment reply box |
---|---|
^ + ↩ | Submit the comment |
You can use Command ⌘
instead of Control ^
on Mac
Support Staff 1 Posted by Marc Guyer on 12 Aug, 2010 02:15 PM
Yes
Attached is the certification letter. The provider is also listed here: http://usa.visa.com/download/merchants/cisp-list-of-pcidss-complian...
Quoting NMI Support: "In order to unlock the credit card data, a merchant must prove PCI Compliance. Once proof of compliance is provided, Data Decryption can be added to the merchant so that they can unlock the card numbers."
Marc Guyer closed this discussion on 12 Aug, 2010 02:15 PM.