Payment data and PCI
written by Albert
Updated June 5, 2026
Card numbers never touch MeloDocs servers — they go straight from your client's browser to the payment processor, which is PCI DSS Level 1 certified.
What we keep is the receipt trail: amounts, dates, last four digits.
This architecture is what keeps you out of PCI scope too: your business never handles, stores or even relays a card number, so there is no cardholder data environment on your side to audit. The processor holds the card; you hold the receipt.
Still stuck? Contact support — a person reads every one.