3 ms·
It also puts you squarely in PCI scope which is a massive burden. I believe many of the modern payment processors offer embedded iframe solutions these days wh
by bspn 9y ago
It also puts you squarely in PCI scope which is a massive burden. I believe many of the modern payment processors offer embedded iframe solutions these days where they handle the sensitive bits (card and CVV#) but allow you to style the payment form however you like.
- LesZedCB 9y agoto an extent yes. There is another lever, PA-DSS compliance which is less stringent than full PCI-DSS compliance because you aren't actually storing card data on your servers, they are just passing through, or pages that collect them are being rendered by that server.