generated: '2026-07-14' method: searched probe: false source: https://www.checkout.com/docs/payments/ensure-regulatory-compliance/pci-compliance url: https://www.checkout.com/docs/payments/ensure-regulatory-compliance/pci-compliance description: >- Checkout.com's security & compliance posture, captured from its PCI compliance documentation. Checkout Technology Ltd (a company within the Checkout.com group) is certified as a PCI DSS Level 1 Service Provider — the highest standard set by the payment card industry. Integrating via Flow, Hosted Payments Page, Payment Links, or the Mobile SDKs lets merchants accept payments without ever handling card data, simplifying their own PCI scope (typically SAQ A). This is the human-verified searched fill; the automated trust-center probe did not record it because Checkout.com surfaces compliance through its docs rather than a trust. subdomain meeting the probe's keyword threshold. certifications: - {name: PCI DSS, level: Service Provider Level 1, entity: Checkout Technology Ltd, note: Highest standard set by the payment card industry.} - {name: SOC 2, note: Reported by third-party security profiles; details provided to customers on request.} - {name: ISO 27001, note: Information security management certification reported for the Checkout.com group.} - {name: GDPR, scope: EU/UK data protection compliance.} merchant_scope_reduction: note: >- Merchants simplify their own PCI compliance by integrating with Flow, Hosted Payments Page, Payment Links, or Mobile SDKs (no card data handled), serving all payment pages over TLS/HTTPS, and validating annually (most via SAQ A). docs: - https://www.checkout.com/docs/payments/ensure-regulatory-compliance/pci-compliance - https://www.checkout.com/docs/payments/ensure-regulatory-compliance/sca-compliance evidence: - {source: https://www.checkout.com/docs/payments/ensure-regulatory-compliance/pci-compliance, keywords: [pci dss level 1, service provider, self-assessment questionnaire, tls]}