Jotform PCI Compliance Payment Form Security Explained
Jotform is PCI DSS Level 1 compliant, the highest tier of payment security certification. Jotform does NOT store raw credit card numbers โ all card data is handled by integrated payment processors (Stripe, PayPal, Square, etc.) via tokenization. Any paid Jotform plan can collect payments through PCI-compliant integrations.
Is Jotform PCI Compliant โ The Verdict
Jotform PCI compliance is achieved through PCI DSS Level 1 certification โ the highest of four PCI DSS levels, required for any processor handling over 6 million transactions per year. This certification applies to Jotform's entire platform infrastructure, not just payment-specific features.
PCI DSS (Payment Card Industry Data Security Standard) is the security framework developed by Visa, Mastercard, American Express, and other card networks to protect cardholder data. Compliance at Level 1 means Jotform's systems have been audited by a Qualified Security Assessor (QSA) and meet all 12 PCI DSS requirements.
How Jotform Handles Payment Data
Jotform uses a payment gateway passthrough model for all payment processing:
- A user submits a payment form on Jotform
- The payment fields (card number, CVV, expiry) are captured directly by the payment processor's secure iframe or API โ never by Jotform's own servers
- The payment processor (Stripe, Square, etc.) tokenizes the card data
- Jotform receives only a transaction confirmation and order details โ not card numbers
- Transaction records are stored in your Jotform submissions without card numbers
Supported Payment Processors in Jotform
| Payment Processor | PCI Compliant | Payment Methods | Best For |
|---|---|---|---|
| Stripe | โ | Cards, Apple Pay, Google Pay | General use, SaaS, donations |
| PayPal | โ | PayPal, cards, Venmo | Consumer-facing forms |
| Square | โ | Cards, gift cards | Small businesses, events |
| Authorize.net | โ | Cards, ACH | US businesses, subscriptions |
| Braintree | โ | Cards, PayPal | Enterprise, global |
| Mollie | โ | Cards, iDEAL, SEPA | European businesses |
What Jotform Stores vs What It Does Not
| Data Type | Stored by Jotform? |
|---|---|
| Credit card number | No โ handled by processor only |
| CVV / CVC | No โ never transmitted to Jotform |
| Card expiry date | No |
| Transaction ID | Yes โ for reference |
| Payment amount | Yes |
| Buyer name / email | Yes โ from form fields |
| Billing address | Yes โ if collected in form |
How to Set Up a PCI-Compliant Payment Form in Jotform
- Create a new form in Jotform Form Builder
- Click Add Element โ scroll to Payment section
- Select your payment processor (Stripe recommended for most users)
- Connect your payment account through OAuth or API key
- Configure the product, amount, and currency
- Publish the form โ payment fields are now handled securely by the processor
For more on Jotform's overall security approach, see Jotform Security Analysis.