eddone
Home
Website
Contact Us
PCI-DSS Compliance Statement
YINHE TRADING LIMITED · Highest Payment Security Standard

PCI-DSS Compliance Statement
Protecting Cardholder Data · Building Trust

YINHE TRADING LIMITED strictly adheres to the Payment Card Industry Data Security Standard (PCI-DSS) and, through a multi-layered security protection system, ensures the absolute security of cardholder data during storage, processing, and transmission.

✓ Secure Network ✓ Encryption ✓ Access Control ✓ Continuous Monitoring ✓ Annual Compliance

1. Policy Statement

YINHE TRADING LIMITED ("we", "our", or "the Company") places the highest importance on the security of payment card data and is fully committed to complying with the Payment Card Industry Data Security Standard (PCI-DSS). We are dedicated to building, maintaining, and continuously improving a top-tier information security protection system to protect cardholder data of customers, partners, and stakeholders from leakage, tampering, and unauthorized access.

This policy applies to YINHE TRADING LIMITED and all its global branches, subsidiaries, affiliates, as well as all employees, officers, agents, and third‑party service providers involved in the processing, storage, or transmission of cardholder data.

2. What is PCI-DSS

PCI‑DSS (Payment Card Industry Data Security Standard) is a global information security standard developed by the PCI Security Standards Council, designed to ensure that all entities that accept, process, store, or transmit cardholder data maintain a secure environment. PCI‑DSS comprises 12 core requirements organized into 6 major goals:

  • Goal 1: Build and maintain a secure network and systems (firewall configuration, security updates)
  • Goal 2: Protect cardholder data (encrypted transmission, secure storage)
  • Goal 3: Maintain a vulnerability management program (antivirus, secure development)
  • Goal 4: Implement strong access control measures (least privilege, unique identification)
  • Goal 5: Regularly monitor and test networks (log monitoring, penetration testing)
  • Goal 6: Maintain an information security policy (employee training, annual review)

YINHE TRADING LIMITED strictly builds its compliance system in accordance with the above 12 requirements and undergoes independent assessments by external audit firms on a regular basis.

3. Build and Maintain a Secure Network

We build and maintain a secure network environment through the following measures:

  • Firewall Configuration: Deploy enterprise‑grade firewalls at all boundaries of the cardholder data environment to strictly control inbound and outbound traffic.
  • Security Configuration Standards: All servers, network devices, and endpoints are hardened according to industry security benchmarks (e.g., CIS).
  • Network Segmentation: The cardholder data environment (CDE) is strictly isolated from internal office networks to reduce the attack surface.
  • Regular Vulnerability Scanning: Internal and external vulnerability scans are performed quarterly on networks and systems, with high‑risk vulnerabilities patched promptly.

4. Protect Cardholder Data

We employ industry‑leading encryption and tokenization technologies to protect cardholder data:

  • Encrypted Transmission: All cardholder data transmitted over public networks is encrypted using TLS 1.2+ protocols.
  • Secure Storage: Cardholder data is stored using strong encryption algorithms (AES‑256), with keys managed through a dedicated key management system.
  • Data Masking: Only necessary masked data is displayed and logged (e.g., showing only the last four digits of the PAN).
  • Minimized Storage: We follow the principle of data minimization, storing only cardholder data that is strictly necessary for business, and securely destroying it after the authorized retention period.
  • Prohibited Storage of Sensitive Authentication Data: We never store CVV2/CVC2, magnetic stripe data, or PIN blocks.

5. Maintain a Vulnerability Management Program

We implement a proactive vulnerability management program to identify and remediate potential security weaknesses:

  • Antivirus / EDR: Deploy next‑generation antivirus / endpoint detection and response (EDR) solutions on all endpoints and servers, keeping them updated in real time.
  • Security Patch Management: Establish a patch management process to deploy critical security patches within 30 days of release.
  • Secure Coding Practices: Development teams follow secure coding standards (e.g., OWASP Top 10) and undergo code security reviews before production.
  • Vulnerability Scanning: Internal and external scans are performed quarterly, with high‑risk vulnerabilities remediated within 30 days.

6. Implement Strong Access Control Measures

We strictly limit access to cardholder data, following the principle of least privilege:

  • Least Privilege Principle: Employees are granted only the minimum level of data access necessary to perform their job duties.
  • Unique Identification: Each user has a unique login ID; shared accounts are prohibited.
  • Multi‑Factor Authentication (MFA): All remote access and critical system access require MFA.
  • Physical Access Control: Data centers and server rooms are subject to strict physical access controls, allowing only authorized personnel entry.
  • Regular Access Reviews: User access permissions are reviewed quarterly; permissions of departed or transferred employees are promptly revoked.

7. Regularly Monitor and Test Networks

We ensure the effectiveness of security controls through continuous monitoring and regular testing:

  • Log Monitoring: Real‑time logging and monitoring of all critical systems and network devices in the cardholder data environment.
  • SIEM: Use a SIEM system to centrally analyze log data, detect anomalies, and identify potential threats.
  • Penetration Testing: Conduct external and internal penetration tests at least once a year, simulating real attack scenarios.
  • IDS/IPS: Deploy IDS/IPS at key network points to detect and block malicious traffic in real time.

8. Maintain an Information Security Policy

We establish a security culture through comprehensive information security policies and employee training programs:

  • Information Security Policy: Develop and maintain a comprehensive information security policy framework covering data classification, access control, incident response, and more.
  • Employee Training: All employees handling cardholder data receive PCI‑DSS compliance training upon hire and annual refresher training thereafter.
  • Security Awareness: Conduct regular phishing simulations and security awareness campaigns to enhance employees' ability to recognize social engineering attacks.
  • Annual Compliance Review: Perform a comprehensive PCI‑DSS compliance assessment (SAQ or ROC) each year to ensure ongoing compliance.

9. Third‑Party Service Provider Management

We partner only with third‑party service providers that meet PCI‑DSS compliance requirements:

  • Compliance Verification: All third‑party service providers involved in cardholder data processing must provide valid PCI‑DSS compliance evidence (e.g., AoC).
  • Contractual Obligations: Contracts with service providers clearly define data protection responsibilities, security requirements, and audit rights.
  • Ongoing Monitoring: Regularly review the security posture and compliance status of third‑party service providers.
  • Minimized Sharing: Share only the minimum data necessary for specific business functions with third parties, using tokenization or masking where possible.

We recommend that clients use third‑party payment gateways (such as Stripe, PayPal, etc.) whenever possible, so that cardholder data is processed through their compliant platforms, further reducing risk.

10. Incident Response and Data Breach Notification

We have established a robust incident response plan to quickly address potential security incidents:

  • Incident Response Team: A cross‑functional team composed of information security, legal, public relations, and business departments.
  • Response Process: Standardized procedures for detection, containment, investigation, remediation, and recovery.
  • Data Breach Notification: In the event of a cardholder data breach, we will promptly notify affected customers, payment brands, and regulators in accordance with applicable laws.
  • Business Continuity: Ensure continued operation of critical business functions during security incidents.
  • Post‑Incident Review: Conduct root cause analysis and implement improvement measures after each incident.

11. Compliance Statement and Commitment

YINHE TRADING LIMITED hereby states:

  • We strictly implement all 12 PCI‑DSS requirements and undergo an annual compliance assessment by an independent external audit firm.
  • We commit to applying the highest level of security protection to all cardholder data and will never use cardholder data for any unauthorized purpose.
  • We continuously monitor updates and evolutions of the PCI‑DSS standard and adjust internal security policies promptly to remain compliant.
  • We encourage customers and partners to contact us directly with any security or compliance concerns.

If you require our PCI‑DSS compliance documentation (AoC), please submit a formal request through the "Contact Us" section below.

12. Contact Us

If you have any questions about this PCI‑DSS Compliance Statement, or if you would like more information about our information security practices, please contact us through the following channels:

Company Name: YINHE TRADING LIMITED

Address: 4959 Colorado Blvd, Denver, CO 80216, United States

Compliance Email: admin@eddone.com

We will treat all inquiries seriously and respond within a reasonable time.