PCI DSS Compliance Statement

Last updated: 10/17/2025

Payment Card Industry Data Security Standard (PCI DSS)

SecurePointAfrica is committed to maintaining the highest standards of payment security and compliance with the Payment Card Industry Data Security Standard (PCI DSS). This statement outlines our approach to protecting payment card data and ensuring secure payment processing.

Our Payment Processing Architecture

πŸ”’ Secure Payment Gateway Integration

We do not store, process, or transmit payment card data directly. All payment processing is handled by PCI DSS Level 1 certified payment providers:

  • Stripe: Level 1 PCI DSS certified service provider
  • Paystack: PCI DSS compliant payment processor
  • Flutterwave: PCI DSS compliant payment processor
  • Mercury Banking: FDIC-insured US banking partner

πŸ’° Settlement Architecture

All payments are settled securely to our US banking partner Mercury:

  • β€’ All gateways settle in USD to Mercury account
  • β€’ Secure routing and account number processing
  • β€’ FDIC insurance protection
  • β€’ Real-time settlement monitoring

PCI DSS Requirements Compliance

1. Build and Maintain Secure Networks

  • β€’ Firewall protection and network segmentation
  • β€’ Secure network architecture design
  • β€’ Regular network security assessments
  • β€’ Encrypted communication channels

2. Protect Cardholder Data

  • β€’ No storage of payment card data on our systems
  • β€’ Tokenized payment processing
  • β€’ Encryption of sensitive data in transit
  • β€’ Secure data handling procedures

3. Maintain Vulnerability Management

  • β€’ Regular security updates and patches
  • β€’ Vulnerability scanning and assessment
  • β€’ Secure coding practices
  • β€’ Third-party security evaluations

4. Implement Strong Access Control

  • β€’ Role-based access control (RBAC)
  • β€’ Multi-factor authentication (MFA)
  • β€’ Regular access reviews and audits
  • β€’ Principle of least privilege

5. Regularly Monitor Networks

  • β€’ Continuous network monitoring
  • β€’ Intrusion detection systems
  • β€’ Security event logging and analysis
  • β€’ Real-time threat detection

6. Maintain Information Security Policy

  • β€’ Comprehensive security policies and procedures
  • β€’ Regular security awareness training
  • β€’ Incident response procedures
  • β€’ Regular policy reviews and updates

Data Security Measures

Encryption

  • β€’ TLS 1.3 for data in transit
  • β€’ AES-256 for data at rest
  • β€’ End-to-end encryption
  • β€’ Key management best practices

Access Controls

  • β€’ Multi-factor authentication
  • β€’ Role-based permissions
  • β€’ Session management
  • β€’ Regular access audits

Third-Party Payment Providers

Certified Payment Processors

All payment processing is handled by PCI DSS certified third-party providers:

  • Stripe: PCI DSS Level 1 Service Provider (Certificate #2016-001)
  • Paystack: PCI DSS Compliant Service Provider
  • Flutterwave: PCI DSS Compliant Service Provider
  • Mercury: FDIC-insured banking partner

Data Flow Architecture

Payment data flows securely through our certified partners:

Customer β†’ Payment Gateway β†’ Mercury Banking

β€’ Card data never touches our servers

β€’ Tokenized payment processing

β€’ Secure settlement to Mercury account

Audit and Compliance

We maintain ongoing PCI DSS compliance through:

  • Annual PCI DSS compliance assessments
  • Quarterly vulnerability scans
  • Regular penetration testing
  • Continuous compliance monitoring
  • Third-party security audits

Incident Response

In the event of a security incident involving payment data, we have established procedures for:

  • Immediate incident containment
  • Forensic investigation
  • Regulatory notification
  • Customer communication
  • Remediation and prevention

Contact Information

For PCI DSS compliance questions or to report security concerns:

Security Team: security@securepointafrica.com

Compliance Officer: compliance@securepointafrica.com

Phone: +1 (555) 123-4567

Emergency Hotline: +1 (555) 999-SECU (7328)

βœ… PCI DSS Compliance Statement

SecurePointAfrica maintains compliance with PCI DSS requirements through our use of certified payment processors and implementation of appropriate security controls. We do not store, process, or transmit payment card data directly, ensuring maximum security for our customers' financial information.