{"statement_id":"st_cf2fa7bfe988c44b94f6","subject":{"kind":"product","slug":"netlify","name":"Netlify","url":"https://sourcetier.com/products/netlify"},"attribute":{"key":"pci_dss","label":"PCI DSS stated","unit":null,"core":true},"scope":null,"region":null,"first_recorded_at":"2026-09-02T02:28:11.061Z","current":{"claim_id":"2d21c706-2c9a-450d-bf61-3397d2b163ce","value":true,"unit":null,"verification_state":"verified","confidence_recorded":90,"observed_on":"2026-09-02","recorded_at":"2026-09-02T02:28:11.061Z","ended_at":null,"ended_by":null,"superseded_by_claim_id":null,"withdrawal_reason":null,"valid_from":null,"extraction":"muster:\\bPCI[\\s-]?DSS\\b","reader":"text pattern","parser_version":null,"method":null,"excerpt":"...ducts with these standards and updating practices as needed. Certified security ISO 27001 PCI DSS HIPAA SOC 2 ISO 27018 CCPA GDPR DORA Encryption All traffic over our networks is encrypte...","sources":[{"url":"https://www.netlify.com/security/","tier":1,"type":"security_documentation","retrieved_on":"2026-09-02","role":"evidence"},{"url":"https://www.netlify.com/security/","tier":1,"type":"security_documentation","retrieved_on":"2026-10-03","role":"evidence"}]},"version_count":1,"versions":[{"claim_id":"2d21c706-2c9a-450d-bf61-3397d2b163ce","value":true,"unit":null,"verification_state":"verified","confidence_recorded":90,"observed_on":"2026-09-02","recorded_at":"2026-09-02T02:28:11.061Z","ended_at":null,"ended_by":null,"superseded_by_claim_id":null,"withdrawal_reason":null,"valid_from":null,"extraction":"muster:\\bPCI[\\s-]?DSS\\b","reader":"text pattern","parser_version":null,"method":null,"excerpt":"...ducts with these standards and updating practices as needed. Certified security ISO 27001 PCI DSS HIPAA SOC 2 ISO 27018 CCPA GDPR DORA Encryption All traffic over our networks is encrypte...","sources":[{"url":"https://www.netlify.com/security/","tier":1,"type":"security_documentation","retrieved_on":"2026-09-02","role":"evidence"},{"url":"https://www.netlify.com/security/","tier":1,"type":"security_documentation","retrieved_on":"2026-10-03","role":"evidence"}]}],"changes":[{"id":"30987","type":"documented","label":"First documented","material":true,"sentence":"Netlify: PCI DSS stated documented (verified). This is a finding of ours, not necessarily a new certification.","noticed_at":"2026-09-02T02:28:11.061Z","subject":{"kind":"product","slug":"netlify","name":"Netlify"},"before":null,"after":{"value":true,"verification_state":"verified","confidence":90},"claim_id":"2d21c706-2c9a-450d-bf61-3397d2b163ce","statement_id":"st_cf2fa7bfe988c44b94f6","corrected":null}],"page_url":"https://sourcetier.com/statements/st_cf2fa7bfe988c44b94f6","contract":"A statement is the question a claim answers: one subject, one attribute, one scope and region. statement_id stays the same when a new value supersedes the old one, when we withdraw it and when two duplicate entities are merged (the old id then redirects). claim_id identifies one version. versions lists every version oldest first; ended_by is superseded, withdrawn or null for the current one. confidence_recorded is the confidence stored when that version was written, not a recomputation. unknown describes our research, never the product."}