What does it mean?
The Payment Card Industry Data Security Standard (PCI DSS) is a written standard, created by the major credit card companies, and maintained by the Payment Card Industry Security Standards Council (PCI SSC). The PCI DSS contains technical requirements that protect and secure payment card data during processing, handling, storage, and transmission. All businesses that handle payment card data, no matter their size or processing methods, must follow these requirements and be PCI compliant. The type of compliance is dependent on the method of data processing. A merchant who handles actual credit cards will be subject to different regulations than a merchant who only processes them online.
PCI defines that service providers like Piano, who do not manage card data on behalf of a merchant, still need to be PCI compliant, because there is the possibility that an incident or an intrusion into Piano's platform may allow for the malicious collection of credit card information. Piano therefore is required to be assessed using the Service Provider assessment as defined by the PCI council.
Piano being PCI compliant does not imply that other merchants are PCI compliant. Every merchant is required to handle PCI compliance by themselves.
What Piano product is covered?
-
Piano Subscriptions (Management + Billing)
How do we comply?
As a requirement for PCI Compliance, an external firm runs quarterly vulnerability scans on our system to ensure that we have not introduced any issues through the software development process. The links to view our current PCI status for our various sites are provided below:
dashboard.piano.io dashboard.tinypass.com
Certification
Piano has passed the PCI DSS onsite audit and was issued with Attestation of Compliance for onsite assessments of service providers, which is valid from 9th March 2021.
Piano will provide the Attestation of Compliance (AOC) on request. Please send all request to security@piano.io.