If your website takes card payments, you may be asked whether your host is PCI compliant. The short answer is yes: the FimuroHost Cloud Hosting platform is PCI (Payment Card Industry) compliant, runs in ISO 27001-certified data centres and is designed to pass PCI compliance scans.
What this means
- PCI DSS is the security standard that applies to anyone who stores, processes or transmits card data.
- ISO 27001 is an international standard for information security management. Our data centres are certified against it.
What is still your responsibility
Hosting is only one part of PCI compliance. Your own website and processes count too:
- Use a hosted payment gateway (for example a redirect or embedded payment page from your payment provider) so card numbers never touch your server. This greatly reduces what you have to prove.
- Always use HTTPS. Free SSL (Let's Encrypt) is included with your plan. Make sure it is active and that all pages redirect to
https://. - Keep software updated: your CMS, plugins, themes and PHP version.
- Protect logins with strong, unique passwords and two-factor authentication wherever it is offered.
- Never store card numbers in your database, emails or log files.
If your payment provider or bank asks for a scan report or specific details about the hosting environment, send us the request and we will help.
Need help?
If anything here does not work as described, our team is happy to take a look. Open a support ticket from your client area or message us on WhatsApp at 01818160926.
Categories
Written by
FimuroHost Team
Technical Writer