PCI Level 1 Certified
Click & Pledge is a PCI Level 1 provider. PCI DSS compliance standards require strict adherence to a large number of security requirements to maintain our certification. All servers, workstations, network connections, products and offices are audited annually by a 3rd party PCI DSS qualified security assessor (QSA). Additionally, the QSA performs in-depth scans and vulnerability tests quarterly. Other tests and scans are performed on a semi-annual or annual basis.
Some of the requirements for security include:
- All servers must maintain up-to-date system patches, and antivirus software.
- All firewalls and security appliance patches are kept up-to-date.
- Only employees with specific needs are able to access systems within the Click & Pledge network.
- Encryption protocols are the most secure available. Weaker encryption methods are retired on a strict schedule.
- Two-Factor authentication and high-level encryption is required for employee access from outside of our network. Additional two-factor authentication is required to access specific computer systems once inside.
- Physical access to Click & Pledge’s offices and data centers are controlled with a logged Access Control System. Additionally, CCTV monitors the office and data-center 24/7.
- Other security procedures, above and beyond PCI requirement include:
-
- Firewall and security appliance logs are monitored continuously using multiple collection/analysis applications. Any attempted intrusions are blocked immediately.
-
- Our Internet service is monitored continuously to maintain maximum network uptime and performance.
-
- There are no wireless devices inside the Click & Pledge security perimeter.
-
- All web-server requests pass through multiple layers of security checks prior to reaching our servers.
Our Data Infrastructure
Click & Pledge’s primary data center is colocated in a 1-milliion square-foot Tier4+ 2N facility with on-site security that is staffed 24/7. All servers and equipment are fully redundant. Our facilities include the following redundant and high-availability features.
- All servers have redundant power-supplies.
- All servers receive power through two different sources (Separate power connections, separate high-capacity UPSs, separate primary power-feeds.)
- All servers have redundant network connections.
- Click & Pledge’s firewalls, load-balancers and network switches are fully redundant.
- The datacenter has a diverse network connection with access to a multiple gigabit connections to the Internet and is located at the heart of the Internet in Ashburn VA. It also provides multiple “direct connect” (aka zero-hop) links to AWS, Google Cloud, Azure and other cloud providers.
- 32 2.25MW Generators provide power to the center in the event of a primary power disruption.
- Click & Pledge employs a worldwide “cache server” network that optimizes delivery and ensures access with servers located in over 1500 locations worldwide.