LogMeIn Hamachi's compliance with PCI standards
GoTo understands that organizations that store, process, or transmit cardholder data must meet strict requirements to be PCI compliant. PCI compliance specifically relates to the security and controls around the payment applications and cardholder data within the merchant's IT environment.
my GoTo product is not a payment solution and at no time does GoTo handle, process, or store credit card data; therefore, my GoTo product falls outside of the scope of PCI review. According to the PCI Security Standards Council, it is the merchant or service provider's responsibility to ensure that they are using only products that support compliance. The role of GoTo (my GoTo product in particular) is to provide secure remote access and systems administration to PCI-compliant organizations without compromising compliance. There is currently no PCI evaluation or certification process for third party applications like my GoTo product. As a result, the question "Is my GoTo product Compliant?" is not the right question. As noted, the valid question is "How does GoTo help organizations comply with PCI requirements?"