Stenocall PCI Compliance Certification
Announcing PCI Compliance Certification!
We are pleased and proud to announce Stenocall has been independently certified as PCI DSS Compliant for credit card security. Here is our certificate (click it for a larger image):
Why is Outside Certification Important?
Even better than a PCI compliant call center is a PCI certified compliant call center. Except for the external network penetration tests, we could have filled out a self-assessment questionnaire to meet the PCI requirements. Many smaller firms do, but then you don't know if they fully understood the requirements, or "fudged" on them.
We've seen someone say, for instance, that they just installed a new firewall, and that made them compliant. Far from it! (See Common PCI Myths.) There are nearly 300 separate requirements, many of which are ongoing procedures and network tests for "hacker resistance." We felt it was important to our clients to take the extra step (and cost) to have our network, software, and procedures audited by an independent Qualified Security Assessor (QSA). This leaves no question that the requirements are met.
So Stenocall is not merely PCI Compliant; we are certified PCI Compliant.
What PCI Compliance means to you
You hear it on the news almost every week it seems -- some company has been hacked and thousands of credit card numbers stolen. In response to this problem, the Payment Card Industry (PCI) has established Data Security Standards (DSS) which vendors and outsourcers must meet in order to process credit and debit cards, or face stiff penalties -- monetary fines, or even a cutoff of credit card processing.
So if you take orders with credit cards, you need a PCI compliant call center. Their rules say this applies even if the credit cards are only stored on your own computers. Because the card numbers go through the call center's network and computers, the call center needs to be PCI compliant also.
This certificate is your assurance that Stenocall is compliant with these stringent standards, so we can handle your credit card orders without subjecting you to any of those penalties -- or your auditor's frowns.
Responsibility on Both Ends
Be aware that if you store, process, or transmit credit card data in your own system, then you need to be PCI compliant also. For instance, for those clients where we capture the data on our systems, we transmit all credit card data to you encrypted. (Not only encrypted in transit, but the file is still encrypted after you receive it.) At the point where you decrypt this file, the computer(s) on which this is done and stored need to be compliant.