Background
As a merchant processor to tens of thousands of merchants, Braintree provides online payment processing tools that ensure payment card data is secure.
While Braintree’s products and tools are compliant with the PCI DSS, only about 15% of Braintree’s merchants were fully PCI compliant in 2012. Jonatan Rivera, Operations Lead at Braintree, said “the task of actually getting our merchants compliant hung over us like a black cloud.”
The following year, Braintree forged a partnership with SecurityMetrics focusing on increasing the compliance of their larger merchants. SecurityMetrics provided Braintree with tools that simplified the compliance process for their merchants and 95% of the targeted merchants achieved full PCI compliance in 2017.
“Where do I start? SecurityMetrics’ FastPass was definitely an answer to our prayers. We were really struggling with our compliance numbers, and now we have more merchants becoming compliant than ever before. I can definitely say that is a direct result of our SecurityMetrics partnership, and I don’t think we could have done it without them.”
- Jonatan Rivera
Operations Lead
Braintree
PCI Challenges You Faced
- The majority of our merchants did not understand the importance of PCI compliance
- The few merchants that did understand the importance of PCI compliance did not understand how to properly define their scope, and we did not have the knowledge or expertise to assist them
- The second-most common reason merchants contacted Braintree was because they had questions about PCI
compliance
Resolving Challenges with SecurityMetrics
- The educational tools that SecurityMetrics has developed definitely helped educate our merchants, such as the explanatory videos next to the SAQ questions and the blog posts
- SecurityMetrics listens to partners like us and helps resolve the challenges we have, which has improved our brand
- Before SecurityMetrics FastPass, 20% of incoming emails and phone calls to Braintree involved questions regarding PCI compliance. After implementing FastPass, this number dropped to 2%
Goals Achieved Working with SecurityMetrics
- FastPass has improved our merchants’ PCI experience
- Reduced the number of questions from merchants, allowing us more time to devote to other priorities
- Found a PCI compliance provider that we intend to keep as a long-term partner because of how much simpler FastPass has made our lives