for the client to fill and post directly to 3rd payment app using JS, would I still need to be audited?
Hi Guillermo, a proper channel that have payment features should comply with PCIDSS standard. From your use case, you are transmitted and processsed payment data. Things such as storing credit card number etc are strictly regulated. First you will need to ensure that everything that in database is properly masked or obfuscated. Second you will need to ensure that everything in log file is also properly masked or obfuscated. Third, you will need to perform pentest by independent party. Fourth, you will need to be audited by reputable firms.
Обсуждают сегодня