1. Policy Statement
YINHE TRADING LIMITED
("we", "our", or "the Company") places the highest importance on the security of payment card data and is
fully committed to complying with the Payment Card Industry Data Security Standard (PCI-DSS). We are
dedicated to building, maintaining, and continuously improving a top-tier information security protection
system to protect cardholder data of customers, partners, and stakeholders from leakage, tampering, and
unauthorized access.
This policy applies to YINHE TRADING LIMITED and all its global branches, subsidiaries, affiliates, as
well as all employees, officers, agents, and third‑party service providers involved in the processing,
storage, or transmission of cardholder data.
2. What is PCI-DSS
PCI‑DSS (Payment Card Industry Data Security Standard) is a global information security standard developed
by the PCI Security Standards Council, designed to ensure that all entities that accept, process, store,
or transmit cardholder data maintain a secure environment. PCI‑DSS comprises 12 core requirements
organized into 6 major goals:
-
Goal 1:
Build and maintain a secure network and systems (firewall configuration, security updates)
-
Goal 2:
Protect cardholder data (encrypted transmission, secure storage)
-
Goal 3:
Maintain a vulnerability management program (antivirus, secure development)
-
Goal 4:
Implement strong access control measures (least privilege, unique identification)
-
Goal 5:
Regularly monitor and test networks (log monitoring, penetration testing)
-
Goal 6:
Maintain an information security policy (employee training, annual review)
YINHE TRADING LIMITED strictly builds its compliance system in accordance with the above 12 requirements
and undergoes independent assessments by external audit firms on a regular basis.
3. Build and Maintain a Secure Network
We build and maintain a secure network environment through the following measures:
-
Firewall Configuration:
Deploy enterprise‑grade firewalls at all boundaries of the cardholder data environment to strictly
control inbound and outbound traffic.
-
Security Configuration Standards:
All servers, network devices, and endpoints are hardened according to industry security benchmarks
(e.g., CIS).
-
Network Segmentation:
The cardholder data environment (CDE) is strictly isolated from internal office networks to reduce the
attack surface.
-
Regular Vulnerability Scanning:
Internal and external vulnerability scans are performed quarterly on networks and systems, with
high‑risk vulnerabilities patched promptly.
4. Protect Cardholder Data
We employ industry‑leading encryption and tokenization technologies to protect cardholder data:
-
Encrypted Transmission:
All cardholder data transmitted over public networks is encrypted using TLS 1.2+ protocols.
-
Secure Storage:
Cardholder data is stored using strong encryption algorithms (AES‑256), with keys managed through a
dedicated key management system.
-
Data Masking:
Only necessary masked data is displayed and logged (e.g., showing only the last four digits of the PAN).
-
Minimized Storage:
We follow the principle of data minimization, storing only cardholder data that is strictly necessary
for business, and securely destroying it after the authorized retention period.
-
Prohibited Storage of Sensitive Authentication Data:
We never store CVV2/CVC2, magnetic stripe data, or PIN blocks.
5. Maintain a Vulnerability Management Program
We implement a proactive vulnerability management program to identify and remediate potential security
weaknesses:
-
Antivirus / EDR:
Deploy next‑generation antivirus / endpoint detection and response (EDR) solutions on all endpoints and
servers, keeping them updated in real time.
-
Security Patch Management:
Establish a patch management process to deploy critical security patches within 30 days of release.
-
Secure Coding Practices:
Development teams follow secure coding standards (e.g., OWASP Top 10) and undergo code security reviews
before production.
-
Vulnerability Scanning:
Internal and external scans are performed quarterly, with high‑risk vulnerabilities remediated within 30
days.
6. Implement Strong Access Control Measures
We strictly limit access to cardholder data, following the principle of least privilege:
-
Least Privilege Principle:
Employees are granted only the minimum level of data access necessary to perform their job duties.
-
Unique Identification:
Each user has a unique login ID; shared accounts are prohibited.
-
Multi‑Factor Authentication (MFA):
All remote access and critical system access require MFA.
-
Physical Access Control:
Data centers and server rooms are subject to strict physical access controls, allowing only authorized
personnel entry.
-
Regular Access Reviews:
User access permissions are reviewed quarterly; permissions of departed or transferred employees are
promptly revoked.
7. Regularly Monitor and Test Networks
We ensure the effectiveness of security controls through continuous monitoring and regular testing:
-
Log Monitoring:
Real‑time logging and monitoring of all critical systems and network devices in the cardholder data
environment.
-
SIEM:
Use a SIEM system to centrally analyze log data, detect anomalies, and identify potential threats.
-
Penetration Testing:
Conduct external and internal penetration tests at least once a year, simulating real attack scenarios.
-
IDS/IPS:
Deploy IDS/IPS at key network points to detect and block malicious traffic in real time.
8. Maintain an Information Security Policy
We establish a security culture through comprehensive information security policies and employee training
programs:
-
Information Security Policy:
Develop and maintain a comprehensive information security policy framework covering data classification,
access control, incident response, and more.
-
Employee Training:
All employees handling cardholder data receive PCI‑DSS compliance training upon hire and annual
refresher training thereafter.
-
Security Awareness:
Conduct regular phishing simulations and security awareness campaigns to enhance employees' ability to
recognize social engineering attacks.
-
Annual Compliance Review:
Perform a comprehensive PCI‑DSS compliance assessment (SAQ or ROC) each year to ensure ongoing
compliance.
9. Third‑Party Service Provider Management
We partner only with third‑party service providers that meet PCI‑DSS compliance requirements:
-
Compliance Verification:
All third‑party service providers involved in cardholder data processing must provide valid PCI‑DSS
compliance evidence (e.g., AoC).
-
Contractual Obligations:
Contracts with service providers clearly define data protection responsibilities, security requirements,
and audit rights.
-
Ongoing Monitoring:
Regularly review the security posture and compliance status of third‑party service providers.
-
Minimized Sharing:
Share only the minimum data necessary for specific business functions with third parties, using
tokenization or masking where possible.
We recommend that clients use third‑party payment gateways (such as Stripe, PayPal, etc.) whenever
possible, so that cardholder data is processed through their compliant platforms, further reducing risk.
10. Incident Response and Data Breach Notification
We have established a robust incident response plan to quickly address potential security incidents:
-
Incident Response Team:
A cross‑functional team composed of information security, legal, public relations, and business
departments.
-
Response Process:
Standardized procedures for detection, containment, investigation, remediation, and recovery.
-
Data Breach Notification:
In the event of a cardholder data breach, we will promptly notify affected customers, payment brands,
and regulators in accordance with applicable laws.
-
Business Continuity:
Ensure continued operation of critical business functions during security incidents.
-
Post‑Incident Review:
Conduct root cause analysis and implement improvement measures after each incident.
11. Compliance Statement and Commitment
YINHE TRADING LIMITED hereby states:
-
We strictly implement all 12 PCI‑DSS requirements and undergo an annual compliance assessment by an
independent external audit firm.
-
We commit to applying the highest level of security protection to all cardholder data and will never use
cardholder data for any unauthorized purpose.
-
We continuously monitor updates and evolutions of the PCI‑DSS standard and adjust internal security
policies promptly to remain compliant.
-
We encourage customers and partners to contact us directly with any security or compliance concerns.
If you require our PCI‑DSS compliance documentation (AoC), please submit a formal request through the
"Contact Us" section below.
12. Contact Us
If you have any questions about this PCI‑DSS Compliance Statement, or if you would like more information
about our information security practices, please contact us through the following channels:
Company Name:
YINHE TRADING LIMITED
Address:
4959 Colorado Blvd, Denver, CO 80216, United States
Compliance Email:
admin@eddone.com
We will treat all inquiries seriously and respond within a reasonable time.