What is PCI DSS?

PCI DSS (Payment Card Industry) — Payment Card Industry Data Security Standard for organizations that store, process, or transmit cardholder data.

Who needs PCI DSS depends on your industry, geography, and customers: buyers frequently require it from vendors during procurement, and compliance is typically demonstrated through independent audits, official registries, or formal certifications. Timeframes vary — most organizations plan months, not weeks, to prepare, be audited, and certify. For exact requirements, refer to the official PCI DSS program ↗.

Which tools in our directory have PCI DSS?

1Password, Amazon Web Services, Brex, Cloudflare, CrowdStrike, Databricks, Datadog, DigitalOcean, GitHub, Gong, Google Cloud Platform, Microsoft Azure, MongoDB Atlas, Netlify, Okta, Ramp, Salesforce, SendGrid, Snowflake, Snyk, Twilio, Vercel.

Additionally, 6 tools hold it partially or conditionally: Supabase, Monday.com, ClickUp, Looker, Bill.com, Zendesk (per-tool conditions apply — see their profiles).

Which tools don't have PCI DSS?

Amplitude, Apollo, Asana, Confluence, dbt Labs, Deel, Figma, Gusto, HubSpot, Intercom, Jira, Linear, Miro, Mixpanel, Notion, Outreach, PagerDuty, Pipedrive, Rippling, Segment, Slack, Tableau.

"Not publicly documented" means we could not verify the status from public sources — it does not mean the vendor lacks the certification.

Browse by category

Don't see a tool you need? Submit it →

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026