Enterprise-Grade AI Needs Enterprise-Grade Governance

PCI DSS Compliance

Learn how Justt can help you keep more revenue.

Book a demo today.

Gaining security certifications don’t usually make for exciting reading. This time may be an exception because they say something about where we think the chargeback management industry is headed. So please bear with me as I explain in detail what we’ve achieved with PCI DSS Level 1 compliance and our ISO/IEC 42001 certification because they change what’s possible for enterprise merchants and PSPs working with Justt.

For those that don’t know, PCI DSS Level 1 is the highest tier under the Payment Card Industry Data Security Standard. Meanwhile, ISO/IEC 42001 is the first international standard for AI management systems. Together, they mark a shift in how Justt can operate inside the payments ecosystem, and how we continue to innovate in the chargeback space.

Why PCI DSS Level 1 Changes the Equation

Most vendors in the dispute space operate at lower PCI tiers, which is fine for a lot of use cases but sometimes it becomes blocker for enterprise merchants and PSPs that require Level 1 compliance from any partner touching cardholder data. That requirement isn’t red tape. It reflects the fact that the systems involved, PSP and acquirer platforms, sit close to the most sensitive data in the payments chain, and access to them is gated accordingly.

Reaching Level 1 means Justt can now connect to those systems directly to automate data extraction on behalf of merchants and PSP/acquirer partners. Practically, that translates into stronger, more complete dispute evidence assembled with far less manual lift from merchant teams. It also means a segment of enterprise merchants who previously couldn’t work with us purely on compliance grounds now can. While the whole compliance process only took us 90 days, the point isn’t the speed. It’s that the highest level of certification is now table stakes for anyone serious about handling payments data at scale, and we wanted independent validation of that, not just our own assurances.

Why AI Governance Needed Its Own Standard

The ISO/IEC 42001 piece is less commonly discussed in payments circles, but it matters just as much, arguably more, given where the industry is going.

Justt has always been an AI-native platform. Our evidence generation, chargeback classification, and win-rate optimization all run on models making decisions at scale, decisions that affect real revenue outcomes for merchants. As AI systems take on more of that decision-making, the question of how those systems are governed, how bias is managed, how risk is assessed, how decisions can be audited, stops being a nice-to-have and becomes core infrastructure.

ISO/IEC 42001 is the first framework built specifically to answer that question. Passing certification means an independent body reviewed how we govern, develop, and operate our AI systems and confirmed it meets that bar. For a company building AI products in a regulated financial space, that’s not a marketing checkbox. It’s the same kind of due diligence enterprise buyers already expect on data security, now extended to the AI layer itself.

What This Combo Unlocks

Both certifications sit alongside our existing SOC 2 and GDPR/CCPA compliance, and the full list is public on our Trust Center. But the more interesting part isn’t the compliance stack itself, it’s what it enables going forward.

Level 1 PCI DSS status means merchants who require PCI compliance from vendors to work with their payments data can now work with Justt. It also opens the door to further our product development and innovation. We’re not treating this as a finish line. It’s the foundation for expanding into new dispute and chargeback products across the payments ecosystem, built on infrastructure that already meets the industry’s highest security and AI governance standards rather than retrofitting them later.

For merchants and PSP partners evaluating who they trust with payments data and AI-driven decisioning, that’s the distinction that should matter: not whether a vendor says security and responsible AI are priorities, but whether that’s been independently verified.

Shahar Tal

Written by

Shahar Tal

Chief Technology Officer at Justt. I'm working hard to build smarter and stronger B2B technologies that innovate industries, starting with our own.

Apply for this position