Splitit is committed to safeguarding the payment card data entrusted to us by merchants and their customers. Security is built into how our platform is designed, operated and independently assessed.
- Shopper
- GLBA Policy
- Loan Agreement and Cost Disclosure Example
- Terms of Service – APAC (English)
- Terms of Service – Canada (English)
- Terms of Service – Canada (French)
- Terms of Service – Hong Kong (Traditional Chinese)
- Terms of Service – Japan (Japanese)
- Terms of Service – Mexico (Spanish)
- Terms of Service – UK & EU (English)
- Terms of Service – UK & EU (French)
- Terms of Service – UK & EU (German)
- Terms of Service – UK & EU (Italian)
- Terms of Service – UK & EU (Spanish)
- Terms of Service – United States (English)
- Terms of Service – United States (Spanish)
- Merchant
- Governance
- Cookie Policy (English)
- Cookie Policy (Spanish)
- Data Protection Addendum & GDPR Compliance
- Data Subject Request Form (English)
- Data Subject Request Form (Spanish)
- Electronic Records Disclosure and Consent Agreement
- E-sign Disclosure Agreement
- Infringement, General Website, and Software Licensing Agreements
- Licensing
- PCI DSS Certification
- Privacy Policy – Global (English)
- Privacy Policy - UK and Europe (English)
- Privacy Policy - UK and Europe (Spanish)
- Privacy Policy For Surveys
- Risk Management Policy
- Shareholder Communications Policy
- User Rights Policy (English)
- User Rights Policy (Spanish)
- Credit Cardholder
PCI DSS Certification
Last updated: 17 September 2026Security
PCI DSS compliance
Splitit is a validated Level 1 PCI DSS Service Provider. We are assessed every year against PCI DSS version 4.0.1 by an independent Qualified Security Assessor (QSA). Our current Attestation of Compliance (AOC) is available from the Splitit Trust Center at https://trust.splitit.com/.
What is PCI DSS?
The Payment Card Industry Data Security Standard (PCI DSS) is the global security standard for any organisation that stores, processes or transmits payment card data. It is maintained by the PCI Security Standards Council, founded by the major payment card brands. Level 1 is the highest validation level for service providers and requires an annual assessment by a QSA.
The standard sets out twelve requirements grouped into six goals:
-
Build and maintain a secure network and systems
-
Protect account data
-
Maintain a vulnerability management program
-
Implement strong access control measures
-
Regularly monitor and test networks
-
Maintain an information security policy
How Splitit protects card data
Splitit applies industry-standard security controls, assessed annually, including:
-
Encryption at rest. Stored card data is encrypted using AES-256, with encryption keys generated and held in FIPS 140-validated hardware security modules. No individual, including Splitit administrators, can access the underlying key material.
-
Encryption in transit. All connections use TLS 1.2 or higher with strong cipher suites.
-
Data minimisation. Card data is retained only for as long as it is needed and is securely deleted under a documented retention schedule.
-
Network protection. A web application firewall and DDoS protection defend the platform at the network edge, with network segmentation isolating the cardholder data environment.
-
24×7 monitoring. Security events are logged centrally and monitored around the clock by a dedicated security operations centre, with intrusion detection and file integrity monitoring on in-scope systems.
-
Strong access control. Multi-factor authentication is required for all access to the cardholder data environment. Administrative access is time-limited and approval-based, and access to systems and card data is restricted to personnel whose role requires it and reviewed regularly.
-
Vulnerability management. Anti-malware protection, regular patching and vulnerability scanning on all in-scope systems, quarterly external scans by a PCI-Approved Scanning Vendor (ASV), and annual penetration testing by independent security testers.
Questions about Splitit’s security or compliance, or requests for our SOC 2 report, can be submitted through the Splitit Trust Center at https://trust.splitit.com/.