Security & Compliance
How WOCOM protects card payments, voice traffic, and the data our clients trust us with — and the independent validation behind it.
PCI DSS Validated
WOCOM Limited is certified compliant with the Payment Card Industry Data Security Standard (PCI DSS). Our compliance was independently validated by SecurityMetrics, a PCI-approved Qualified Security Assessor and Approved Scanning Vendor, against Self-Assessment Questionnaire A, version 4.0.1.
PCI DSS is the security standard endorsed by Visa, Mastercard, American Express, Discover and JCB. It governs how businesses that accept card payments must protect cardholder data.
Compliance is maintained continuously: our self-assessment questionnaire is revalidated every twelve months, and external vulnerability scans are performed every three months against our internet-facing systems.
How Card Payments Work
The strongest protection for your card details is that we never handle them. WOCOM does not store, process, or transmit cardholder data on its own systems.
When you pay WOCOM online, the payment fields on our checkout are served directly by Stripe — a PCI DSS Level 1 certified service provider, the highest level of validation available. Your card number, expiry date and security code are captured inside Stripe's own secure fields and travel from your browser straight to Stripe.
- Card numbers are never transmitted to WOCOM servers.
- Card numbers are never written to WOCOM databases, logs, or backups.
- WOCOM staff cannot view your full card number at any time.
- We retain only a Stripe payment reference and the last four digits, for reconciliation and support.
- All traffic to our sites and to Stripe is encrypted with TLS 1.2 or 1.3.
This design is why WOCOM qualifies for SAQ A — the questionnaire reserved for merchants who fully outsource card handling to a validated provider.
Certificate Details
| Merchant | Wocom Limited |
|---|---|
| Standard | PCI DSS — Payment Card Industry Data Security Standard |
| Validation type | Self-Assessment Questionnaire A, version 4.0.1 |
| Compliant date | 22 July 2026 |
| Last passing scan | 22 July 2026 |
| Validated by | SecurityMetrics — Qualified Security Assessor & Approved Scanning Vendor |
| Card brands | Visa, Mastercard, American Express, Discover, JCB |
| Revalidation | Questionnaire annually; external scans quarterly |
A copy of our Certificate of PCI DSS Merchant Compliance is available to clients and prospective clients on request — contact info@wocomja.com.
Platform & Network Security
- Encryption in transit — TLS 1.2 and 1.3 only. Older protocols (TLS 1.0, TLS 1.1, SSLv3) are disabled entirely.
- HTTP Strict Transport Security enforced, so browsers refuse to connect over unencrypted HTTP.
- Content Security Policy and a full set of hardening headers restrict what may execute on our pages.
- Web application firewall running in enforcing mode, with per-IP rate limiting against brute-force and scraping.
- Vulnerability scanning quarterly by an Approved Scanning Vendor, plus ongoing internal review and patching.
- Least-privilege access with role-based controls, audit logging, and multi-factor authentication for administrative access.
- Licensed carrier network — WOCOM owns and operates its own network infrastructure in Jamaica, with a 99.999% uptime commitment.
Voice & Call Data
Voice traffic is carried across WOCOM's own licensed network. Call recordings, transcripts and AI-generated summaries are encrypted in transit and at rest, and are accessible only to the authorised users of the account that owns them.
Where WOCOM processes call data on behalf of a business client, the client is the Data Controller and WOCOM acts as Data Processor. Supervision features such as live call monitoring are restricted to nominated supervisor extensions, scoped by department, and every session is written to an audit trail.
Data Protection
WOCOM processes personal data in accordance with the Data Protection Act, 2020 of Jamaica. Our full Privacy Policy sets out what we collect, the lawful basis for processing, retention periods, cross-border transfers, and your rights as a data subject — including how to raise a complaint with the Office of the Information Commissioner.
Reporting a Vulnerability
If you believe you have found a security vulnerability in a WOCOM website, portal, or service, we want to hear from you. Please email security@wocomja.com with enough detail to reproduce the issue.
We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure, and that testing does not degrade service for other customers or access data that is not your own. We will acknowledge reports and keep you updated on progress.