3 ms·
> Since the data never touches your servers, you never need to go through PCI compliance work. Is that actually true? My understanding is that since the HTML f
by storborg 16y ago
> Since the data never touches your servers, you never need to go through PCI compliance work.
Is that actually true? My understanding is that since the HTML form is still served up by your site, you'll still need to go through PCI compliance (although it will be easier with no data stored), since a compromise of your server would compromise card data.
- bradleyjoyce 16y agoFrom the email they sent out to current spreedly customers: "while you can already do this with our Subscriptions Payments API, doing so places the burden of PCI compliance on your shoulders. Core keeps the PCI burden on our side and allows you to focus on growing your business." not sure exactly how the specifics of this will work...
- ntalbott 16y agoOur understanding after talking to multiple QSA's about the transparent redirect is that it allows the merchant to legitimately claim that they do not "store, process, or transmit" credit card data, which means they only have to fill out SAQ-A. And trust me, you definitely want to fill out SAQ-A.