SITE STATUS: LIVE | AUTHORIZED NMI RESOURCE
Guide

NMI Security

NMI security: PCI DSS Level 1, tokenization, MFA, iSpyFraud, TLS encryption, and access control best practices.

Updated June 2025

PCI DSS Level 1

Highest compliance level. Annual third-party audits, encryption at rest/transit, strict access controls. Using NMI's hosted page or Collect.js keeps card data off your server (SAQ A).

Tokenization

Customer Vault replaces card numbers with tokens. Useless to attackers. Reduces breach exposure.

MFA

Authenticator app or SMS second factor. Recommended for all accounts. Troubleshoot in login help.

iSpyFraud

Real-time detection: AVS, CVV, velocity, IP geo, BIN blocking, custom rules. Per-source key configuration.

TLS Encryption

All merchant-gateway traffic over TLS. AES-256 at rest. HSM key management.

Access Control

Sub-accounts with role-based permissions. Full audit trail per user ID.

Best Practices

  • Enable MFA everywhere
  • Unique passwords per service
  • Sub-accounts for staff, never share master
  • Review logs regularly
  • Update fraud rules from chargeback patterns
  • Bookmark official URL

See NMI Gateway | Features

NMI Login — sign in securely.

Related Articles