Skip to main content

PCI DSS Compliance

Payment Card Industry Data Security Standard

PCI DSS Compliant

FileDrop maintains PCI DSS compliance through secure payment processing practices and partnership with certified payment service providers.

Our Approach to Payment Security

FileDrop takes payment card security seriously. We implement industry best practices and work with PCI DSS Level 1 certified payment processors to ensure your payment information is handled securely.

Important: FileDrop does not directly store, process, or transmit credit card information. All payment transactions are handled by our PCI DSS certified payment processor partners.

Payment Processing Partners

Square Payments

PCI DSS Level 1 Service Provider certified. Square handles all payment card processing using secure, tokenized payment methods.

Learn more: Square PCI Compliance

Our Security Measures

Secure Data Handling

  • • No storage of card data on our servers
  • • Tokenization for payment references
  • • Encrypted transmission (TLS 1.3)
  • • Secure API integration

Network Security

  • • Firewall protection
  • • Regular security audits
  • • Vulnerability scanning
  • • Access control policies

Authentication

  • • Secure code-based access
  • • Time-limited upload sessions
  • • Session management
  • • User access controls

Monitoring & Logging

  • • Transaction monitoring
  • • Audit logging
  • • Incident response procedures
  • • Regular security reviews

PCI DSS 12 Requirements Overview

The Payment Card Industry Data Security Standard consists of 12 core requirements organized into six control objectives:

Build and Maintain a Secure Network

  • 1. Install and maintain firewall configuration
  • 2. Do not use vendor-supplied defaults for passwords

Protect Cardholder Data

  • 3. Protect stored cardholder data
  • 4. Encrypt transmission of cardholder data

Maintain a Vulnerability Management Program

  • 5. Protect systems against malware
  • 6. Develop and maintain secure systems

Implement Strong Access Control Measures

  • 7. Restrict access to cardholder data
  • 8. Identify and authenticate access
  • 9. Restrict physical access to cardholder data

Regularly Monitor and Test Networks

  • 10. Track and monitor all access to network resources
  • 11. Regularly test security systems and processes

Maintain an Information Security Policy

  • 12. Maintain a policy that addresses information security

Compliance Level

FileDrop qualifies as a PCI DSS SAQ A merchant because:

  • All cardholder data functions are outsourced to PCI DSS validated third-party service providers
  • We do not electronically store, process, or transmit any cardholder data
  • All payment processing is handled entirely by our PCI DSS compliant partners
  • We maintain secure website standards (HTTPS, TLS 1.3)

Attestation of Compliance

Company Name
RubriqFlow
Compliance Level
SAQ A
Validation Date
January 2026
Next Review
January 2027

Security Questions?

We take payment security seriously and are committed to maintaining the highest standards of data protection. If you have questions about our PCI DSS compliance or payment security practices, please contact our security team.

Email: security@noctusoft.com