PCI DSS Guidance
Any merchant accepting payments must comply with the PCI Data Security Standards (PCI DSS). Microform Integration’s approach facilitates PCI DSS compliance through self-assessment and the storage of sensitive PCI information.
Self-Assessment Questionnaire
Microform Integration handles the card number input and transmission from within iframe elements served from controlled domains. This approach can qualify merchants for SAQ A-based assessments, the least burdensome level of PCI compliance. Related fields, such as cardholder name or expiration date, are not considered sensitive when not accompanied by the primary account number (PAN).
To meet this requirement, Microform Integration renders secure iframes for these payment information fields:
- Card information input fields: payment card or primary account number (PAN), card verification number (
CVN) - eCheck information input fields: routing number, account number
These iframes are hosted by Microform Integration, and the payment data is submitted directly to through the secure Flex API v2 suite. This means that this data never passes through your systems.
Storing Returned Data
Microform Integration strips responses of sensitive PCI information such as card number. Fields included in the response, such as card type and masked card number, are not subject to PCI compliance and can be safely stored within your systems. If you collect the card verification number (CVN), note that it can be used for the initial authorization but not stored for subsequent authorizations.
Thanks for your feedback!
Last published: September 29, 2026