PCI DSS Compliance

How DK Wholesale ensures secure payment processing for all transactions

What is PCI DSS?

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. DK Wholesale is committed to meeting these standards to protect our business partners.

Our Compliance Level

4

PCI DSS Level 4 Merchant

For merchants processing fewer than 20,000 e-commerce transactions annually

As a B2B wholesale distributor, most of our transactions are processed through secure third-party payment processors. We complete an annual Self-Assessment Questionnaire (SAQ) to validate our compliance.

PCI DSS Requirements We Follow

Build & Maintain Secure Network

  • Firewall configuration to protect cardholder data
  • No vendor-supplied default passwords on systems

Protect Cardholder Data

  • Encryption of cardholder data in transit (TLS 1.2+)
  • No storage of sensitive card data on our servers

Vulnerability Management

  • Regular system and software updates
  • Anti-malware protection on all systems

Access Control Measures

  • Restrict access to cardholder data on a need-to-know basis
  • Unique IDs for each person with computer access

Monitoring & Testing

  • Track and monitor all access to network resources
  • Regular testing of security systems and processes

Information Security Policy

  • Maintain a policy addressing information security for all personnel
  • Regular staff training on data security best practices

Our Payment Security Approach

1

Third-Party Payment Processing

We use PCI-compliant payment processors (e.g., Stripe) so that sensitive card data never touches our servers.

2

Tokenization

Payment information is tokenized — we only store non-sensitive tokens, never actual card numbers.

3

SSL/TLS Encryption

All data transmitted between your browser and our website is encrypted using TLS 1.2 or higher.

4

Annual Compliance Review

We complete an annual PCI DSS Self-Assessment Questionnaire and engage qualified security assessors when needed.

Payment Security Questions?

If you have questions about our payment security practices or PCI DSS compliance, please contact us.