PCI DSS Compliance
How DK Wholesale ensures secure payment processing for all transactions
What is PCI DSS?
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. DK Wholesale is committed to meeting these standards to protect our business partners.
Our Compliance Level
PCI DSS Level 4 Merchant
For merchants processing fewer than 20,000 e-commerce transactions annually
As a B2B wholesale distributor, most of our transactions are processed through secure third-party payment processors. We complete an annual Self-Assessment Questionnaire (SAQ) to validate our compliance.
PCI DSS Requirements We Follow
Build & Maintain Secure Network
- Firewall configuration to protect cardholder data
- No vendor-supplied default passwords on systems
Protect Cardholder Data
- Encryption of cardholder data in transit (TLS 1.2+)
- No storage of sensitive card data on our servers
Vulnerability Management
- Regular system and software updates
- Anti-malware protection on all systems
Access Control Measures
- Restrict access to cardholder data on a need-to-know basis
- Unique IDs for each person with computer access
Monitoring & Testing
- Track and monitor all access to network resources
- Regular testing of security systems and processes
Information Security Policy
- Maintain a policy addressing information security for all personnel
- Regular staff training on data security best practices
Our Payment Security Approach
Third-Party Payment Processing
We use PCI-compliant payment processors (e.g., Stripe) so that sensitive card data never touches our servers.
Tokenization
Payment information is tokenized — we only store non-sensitive tokens, never actual card numbers.
SSL/TLS Encryption
All data transmitted between your browser and our website is encrypted using TLS 1.2 or higher.
Annual Compliance Review
We complete an annual PCI DSS Self-Assessment Questionnaire and engage qualified security assessors when needed.
Payment Security Questions?
If you have questions about our payment security practices or PCI DSS compliance, please contact us.