Hacker News new | ask | show | jobs
by mcpherrinm 3493 days ago
Yes, you can store tokens representing a credit card number (whether an hmac, database identifier, etc) outside of PCI scope. https://www.pcicomplianceguide.org/how-you-can-use-tokenizat...