PCI DSS Compliance
Payment Card Industry Data Security Standard
PCI DSS Compliant
FileDrop maintains PCI DSS compliance through secure payment processing practices and partnership with certified payment service providers.
Our Approach to Payment Security
FileDrop takes payment card security seriously. We implement industry best practices and work with PCI DSS Level 1 certified payment processors to ensure your payment information is handled securely.
Important: FileDrop does not directly store, process, or transmit credit card information. All payment transactions are handled by our PCI DSS certified payment processor partners.
Payment Processing Partners
Square Payments
PCI DSS Level 1 Service Provider certified. Square handles all payment card processing using secure, tokenized payment methods.
Learn more: Square PCI Compliance
Our Security Measures
Secure Data Handling
- • No storage of card data on our servers
- • Tokenization for payment references
- • Encrypted transmission (TLS 1.3)
- • Secure API integration
Network Security
- • Firewall protection
- • Regular security audits
- • Vulnerability scanning
- • Access control policies
Authentication
- • Secure code-based access
- • Time-limited upload sessions
- • Session management
- • User access controls
Monitoring & Logging
- • Transaction monitoring
- • Audit logging
- • Incident response procedures
- • Regular security reviews
PCI DSS 12 Requirements Overview
The Payment Card Industry Data Security Standard consists of 12 core requirements organized into six control objectives:
Build and Maintain a Secure Network
- 1. Install and maintain firewall configuration
- 2. Do not use vendor-supplied defaults for passwords
Protect Cardholder Data
- 3. Protect stored cardholder data
- 4. Encrypt transmission of cardholder data
Maintain a Vulnerability Management Program
- 5. Protect systems against malware
- 6. Develop and maintain secure systems
Implement Strong Access Control Measures
- 7. Restrict access to cardholder data
- 8. Identify and authenticate access
- 9. Restrict physical access to cardholder data
Regularly Monitor and Test Networks
- 10. Track and monitor all access to network resources
- 11. Regularly test security systems and processes
Maintain an Information Security Policy
- 12. Maintain a policy that addresses information security
Compliance Level
FileDrop qualifies as a PCI DSS SAQ A merchant because:
- •All cardholder data functions are outsourced to PCI DSS validated third-party service providers
- •We do not electronically store, process, or transmit any cardholder data
- •All payment processing is handled entirely by our PCI DSS compliant partners
- •We maintain secure website standards (HTTPS, TLS 1.3)
Attestation of Compliance
- Company Name
- RubriqFlow
- Compliance Level
- SAQ A
- Validation Date
- January 2026
- Next Review
- January 2027
Security Questions?
We take payment security seriously and are committed to maintaining the highest standards of data protection. If you have questions about our PCI DSS compliance or payment security practices, please contact our security team.
Email: security@noctusoft.com