PCI DSS Level 1
Highest compliance level. Annual third-party audits, encryption at rest/transit, strict access controls. Using NMI's hosted page or Collect.js keeps card data off your server (SAQ A).
Tokenization
Customer Vault replaces card numbers with tokens. Useless to attackers. Reduces breach exposure.
MFA
Authenticator app or SMS second factor. Recommended for all accounts. Troubleshoot in login help.
iSpyFraud
Real-time detection: AVS, CVV, velocity, IP geo, BIN blocking, custom rules. Per-source key configuration.
TLS Encryption
All merchant-gateway traffic over TLS. AES-256 at rest. HSM key management.
Access Control
Sub-accounts with role-based permissions. Full audit trail per user ID.
Best Practices
- Enable MFA everywhere
- Unique passwords per service
- Sub-accounts for staff, never share master
- Review logs regularly
- Update fraud rules from chargeback patterns
- Bookmark official URL
See NMI Gateway | Features
NMI Login — sign in securely.