Security & compliance

PCI DSS compliance and email signatures

The policy work and the polish — the details that make a business look organised.

Card payment terminal and documents on an office desk

£1.20

Per user per month for Exclaimer

Every device

Signatures applied server-side

Documented

Policies ready for an audit

Overview

Two very different jobs sit under this heading, and both are about consistency. PCI DSS compliance is the set of rules covering how card payment data is handled and stored — and most of the work is policy rather than technology: writing down how your business takes payments, who can access that data, how long it is kept and how it is destroyed.

Email signatures are the other end of the scale, but they are the thing your customers see on every single message. Exclaimer is a cloud-based signature tool that applies a consistent, authenticated signature to mail from every device — desktop, phone or webmail — with links that actually work. It costs around £1.20 per user per month.

What's included

How we deliver pci dss compliance and email signatures

PCI DSS policy documentation

Written policies covering the handling, storage, retention and disposal of cardholder data.

Scope and process review

Mapping how card data flows through your business and reducing that scope wherever possible.

Supporting technical controls

Access restrictions, network segregation, logging and encryption to back the policies up.

Exclaimer deployment

Central signature templates rolled out across Microsoft 365, applied server-side to every device.

Brand consistency

One correct, on-brand signature with working links, legal wording and campaign banners when you need them.

Ongoing management

New starters, job title changes and seasonal updates handled centrally in minutes.

How it works

What happens when you get in touch

    1

    Map the data

    How card payments flow through your business, who touches that data and where it rests.

    2

    Reduce the scope

    Cutting out the places card data does not need to go, which makes compliance far simpler.

    3

    Write the policies

    Handling, storage, retention and disposal documented in plain language, with controls to back them up.

    4

    Roll out signatures

    Exclaimer templates applied centrally across Microsoft 365, then maintained as people and campaigns change.

Who it suits

This is usually the right fit for

  • Businesses taking card payments by phone, online or in person
  • Organisations where every member of staff has a different signature
  • Companies who need documented policies for an audit

Common questions

Questions we are asked about this

Is PCI DSS mostly a technology job?

Mostly it is policy: writing down how you take payments, who can see that data and how long you keep it.

Why not just let staff set their own signature?

You get a dozen different versions, broken links and no legal wording. Exclaimer applies one correct signature to every message.

Do signatures work on phones?

Yes — they are applied server-side, so mail from a phone or webmail looks identical to mail from a desktop.

Interested in pci dss compliance and email signatures?

Tell us what's frustrating you and we'll tell you honestly what we'd do about it. No jargon, no pressure, no lengthy sales process.