Hacker News new | ask | show | jobs
by jpkrohling_jpk 4964 days ago
You don't have to be PCI compliant to use Paymill, due to our "javascript bridge" solution. In short: the payment details never touches your server, removing the PCI compliance requirement.
1 comments

Any merchant that accepts credit card payments must be PCI compliant. Even if cardholder data never touches the merchant's servers, the merchant still falls under the scope of SAQ A[1].

1: https://www.pcisecuritystandards.org/documents/pci_saq_a_v2....