You should do a search for Merchant Groups that follow PCI rules.
Then search for "Hacked Sites using Hacker Safe".
It's a superficial scanning process not a network vulnerability scan which can only take place from within your network.
To top that off really who cares if someone can "Hack" your website. Data isn't stored in Web pages it's stored in Databases and the scans do not check your SQL MySQL servers weakness.
If you really want the truth ask Tom at
Merchant911.org the mailing list discussion over the last 4 days has only been about Hacker Safe and the results from Merchants isn't that impressive for the money.
Good Luck and hope you have deep pockets for a Remote Scanning Operation. (Keyword is Remote)
It's better to ask a Russian Hacker to just Hack your site for fun. Then you'll find your weaknesses and it would make me feel safer if I saw "Protected by the Mob" instead of "Hacker Safe".
Disclaimer: It's only one programmer's opinion.
By the way, the BBBOnline doesn't have guidelines regarding customers payment information.
Follow the PCI guidelines and show in your storefronts policy that you run an audit in compliance to the PCI guidelines. (PCI Visa)