---
title: "Information Security"
source_url: https://docs.rapyd.net/en/information-security.html
lang: en
---

# Information Security

Rapyd handles and maintains sensitive information in accordance with the most stringent PCI standards.

PCI Level 1

The [Payment Card Industry (PCI)](https://docs.rapyd.net/en/glossary.md#UUID-945d98cf-adae-e1cf-2606-c7fae8b4a7e1_pci "Payment Card Industry") has established strict security requirements for the processing, handling, transmission and storage of sensitive data that is required for processing card transactions when the card is not present. The requirements are set forth in the PCI [Data Security Standard (DSS)](https://docs.rapyd.net/en/glossary.md#UUID-945d98cf-adae-e1cf-2606-c7fae8b4a7e1_dss "Payment Card Industry Data Security Standard"). For further information, see [PCI Security Standards Council](https://www.pcisecuritystandards.org/).

Rapyd has passed stringent independent onsite assessments by a Qualified Security Assessor and is certified as a Level 1 service provider.

Rapyd and PCI-compliant clients can handle the following sensitive personal data:

- Name
- Card number
- Expiration date
- Card security code (CVV)

Clients without PCI certification must not collect any sensitive personal data and cannot use features of the Rapyd platform that require that data. To handle card transactions without PCI certification, use hosted pages.

- [Checkout Page](https://docs.rapyd.net/en/checkout-page.md "Checkout Page") - Card payments.
- [Card Token](https://docs.rapyd.net/en/card-token.md "Card Token") - A token for a card payment method that is stored in Rapyd's vault.
- [Beneficiary Token](https://docs.rapyd.net/en/beneficiary-token.md "Beneficiary Token") - A token for a beneficiary for payouts.
- [Hosted PIN Management](https://docs.rapyd.net/en/hosted-pin-management.md "Hosted PIN Management") - Managing card PIN numbers.
