---
title: Does Vercel support PCI compliance?
description: Learn about Vercel and PCI compliance.
url: /kb/guide/is-vercel-pci-compliant
canonical_url: "https://vercel.com/kb/guide/is-vercel-pci-compliant"
published: 2025-11-03
last_updated: 2026-06-17
authors: Allen Hai
related:
  - /docs/security/shared-responsibility
  - /docs/security/pci-dss
install_vercel_plugin: npx plugins add vercel/vercel-plugin
---
<!-- docsgraph:related -->
## Related pages

> **For AI agents:** Follow these links to understand how this page connects to the rest of the Vercel ecosystem. For the full cross-link map (inbound, outbound, prerequisites, and semantic neighbors), see the .graph.md link below.

- [Security & Compliance Measures](https://vercel.com/docs/security/compliance?from=related) — Learn about the protection and compliance measures Vercel takes to ensure the security of your data, including DDoS miti
- [Overview](https://vercel.com/docs/security?from=related) — Vercel provides built-in and customizable features to ensure that your site is secure.
- [Security](https://vercel.com/docs/cdn-security?from=related) — Learn how Vercel's CDN secures every request with HTTPS, TLS, DDoS mitigation, firewall protection, and security headers
- [Legal](https://vercel.com/docs/connect/legal?from=related) — Product terms governing your use of Vercel Connect, including Customer Managed Connectors, Vercel Managed Connectors, an
- [Encryption & TLS](https://vercel.com/docs/cdn-security/encryption?from=related) — Learn how Vercel encrypts data in transit and at rest.
- [How to conduct PCI scans on Vercel: A complete guide to IP safelisting](https://vercel.com/kb/guide/how-to-conduct-pci-scans-on-vercel-guide?from=related) — Scan and verify your Vercel deployments for secure, PCI-compliant payment processing.
- [Does Vercel support HIPAA compliance?](https://vercel.com/kb/guide/is-vercel-hipaa-compliant?from=related) — Learn about Vercel and HIPAA compliance.
- [Ensuring safe and effective infrastructure testing](https://vercel.com/kb/guide/ensuring-safe-and-effective-infrastructure-testing?from=related) — We conduct regular penetration testing through certified third-party assessors to secure the Vercel platform. This guide
- [HIPAA Compliance on Vercel](https://vercel.com/kb/guide/hipaa-compliance-guide-vercel?from=related) — Deploy HIPAA-compliant healthcare apps on Vercel with built-in security, BAAs, and scalable serverless infrastructure.
- [Supporting Compliance with Vercel WAF](https://vercel.com/kb/guide/supporting-compliance-with-vercel-waf?from=related) — Vercel Firewall provides edge-based traffic filtering and monitoring to help teams meet compliance requirements in secur

Full cross-link map for this page: [/kb/guide/is-vercel-pci-compliant.graph.md](/kb/guide/is-vercel-pci-compliant.graph.md)
<!-- /docsgraph:related -->


Vercel supports PCI compliance as a merchant and service provider. We can provide Attestation of Compliance (AOC) reports to customers upon request.

## What is PCI compliance?

[Payment Card Industry Data Security Standard (PCI DSS)](https://www.pcisecuritystandards.org/) is a standard that defines the security and privacy requirements for payment card processing. PCI compliance requires businesses that handle customer credit card information to adhere to a set of information security standards.

## Vercel as a Service Provider

In alignment with Vercel’s [shared responsibility model](/docs/security/shared-responsibility), Vercel serves as a service provider to customers who process payment and cardholder data. Customers should select an appropriate payment gateway provider to integrate an `iframe` into their application to ensure that any information entered in the `iframe` goes directly to their payment processor and is isolated from their application’s managed infrastructure on Vercel.

[Learn about PCI DSS iframe integration](/docs/security/pci-dss).

## Vercel as a Merchant

Vercel acts as a merchant by facilitating online transactions for the services we provide to our customers.

### Cardholder Data

Vercel relies on validated third-party payment processors to securely handle all aspects of payment processing, including data transmission, processing, and storage. These payment providers support compliance with PCI DSS standards and enable Vercel to deliver services without directly managing cardholder data from customers.

## Attestation of Compliance

Vercel provides a Self-Assessment Questionnaire D (SAQ-D) Attestation of Compliance (AOC) and a Self-Assessment Questionnaire A (SAQ-A) Attestation of Compliance (AOC) under PCI DSS v4.0. PCI DSS compliance is a shared responsibility between Vercel and its customers. Vercel also provides a Responsibility Matrix which outlines the security and compliance obligations between Vercel and its customers.

- The **SAQ-D AOC** supports Vercel’s adherence to PCI DSS requirements as a **service provider**, which is essential for customers handling payments through their applications, as it may impact the scope of their cardholder data environment per PCI DSS standards.
  
- The **SAQ-A AOC** supports Vercel’s adherence to PCI DSS requirements as a **merchant**, ensuring that all cardholder data is processed by authorized third-party payment processors.
  

A copy of our PCI DSS compliance documentation can be obtained through our [Trust Center](https://security.vercel.com/).