PCI Compliance
SwissPay.ai handles cardholder data within a PCI DSS Level 1 compliant environment, the highest level of the Payment Card Industry Data Security Standard.
Our PCI DSS status
SwissPay operates as a PCI DSS Level 1 authorized platform partner. PCI DSS is the security standard set by the major card networks to protect cardholder data, and Level 1 is the most rigorous tier, covering the highest processing volumes.
How we protect card data
Card data is tokenised so that sensitive numbers are replaced with non-sensitive tokens, encrypted in transit and at rest, and stored in an access-controlled, monitored environment. We support 3-D Secure 2 for strong customer authentication and apply real-time fraud scoring to reduce risk.
Scope and shared responsibility
We maintain the security of the systems within our control and work with acquiring partners and providers that maintain their own PCI compliance. Security of cardholder data is a shared responsibility across the payment chain.
Merchant responsibilities
Merchants using our services are responsible for maintaining their own PCI compliance appropriate to how they accept payments, for keeping their integration secure, and for following the guidance we provide. Using a tokenised, hosted integration reduces the merchant's PCI scope.
Contact
For questions about our PCI compliance or to request documentation, reach us through support.swisspay.ai.
Last reviewed: 13 August 2026