Search  
Home Solutions Customer Service News & Events About Us Contact Us Systems Link
User Name:

Password:

Compliance

Pemco Technologies complies with strict standards of information security as required by agencies and associations that govern our industry. Below you'll find some details and documentation of our commitment to security standards.

CISP/PCI: What it means and why it matters

Pemco Technologies is CISP/PCI compliant. This compliance means everything to us and to our customers. It guarantees that strong and sophisticated data security measures are in place.

Our company's most recent letter of acceptance from Visa was written on August 3, 2007. The letter states, "Thank you for continuing your participation in the Visa CISP, and for your diligence in operating within the compliance standards of the Payment Card Industry Data Security Standard."

In 2001, Visa introduced its Cardholder Information Security Program (CISP) to strengthen protection of cardholder information. This program was later incorporated into an industry-wide set of safeguards; the Payment Card Industry (PCI) standards for protecting cardholder information. Cardholders have a right to expect their institutions to uphold these standards, and auditors insist upon it.

When Pemco is audited, observance of these standards is checked on all systems where cardholder data is processed, stored, or transmitted. This includes network connections to payment card companies, financial institutions, processing companies, and remote access employees. It also includes Point of Sale (POS) environments that involve IP-based communications (Internet, VPN, dial-in, etc.).

To maintain compliance with CISP/PCI, our company is audited annually, and must meet very stringent requirements. Below are some of the areas that PCI standards examine:

When a vendor or auditor contacts your financial institution and inquires as to whether Pemco programs are CISP/PCI compliant, you can be assured that the answer is yes. You can find proof of our CISP compliance on the following page:
Compliance Documents
(Log-in is required to view this page.)

The PCI requirements are also publicly available at pcisecuritystandards.org.

Back to Top

SAS 70 (Statement on Auditing Standards #70)

SAS 70 is an internationally recognized auditing standard developed by the American Institute of Certified Public Accountants. Pemco Technologies is annually subject to an in-depth SAS 70 audit of its control activities (controls over information technology and related processes). You can find our most recent SAS audit here:
Customer Service Forms
(Log-in is required to view this page.)

Back to Top

Disaster Recovery

Pemco Technologies recognizes the necessity of maintaining business continuity in the event of a disaster. Solid recovery procedures are in place and regularly tested. You can read our document, "Pemco Technologies' Disaster Recovery Support for Financial Institutions," on this page:
Customer Service Forms
(Log-in is required to view this page.)

Back to Top