Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you don't store credit card information locally, then it's pretty easy to be PCI-compliant. Just make sure everything's secured and only a few people have access, pay for security sweeps, and you're good.

If you're storing credit card numbers, things get much more complicated.



If you don't store it you get to skip Req 3 basically. You still have most of the other 11 Requirements to worry about... Multi-key strong encryption and key rotation isn't that hard... The policies, documentation, and other areas are harder imho.


"Not storing" is a better situation than "not handling" but it doesn't get you off the hook.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: