Hacker News new | ask | show | jobs
by michaelfairley 4845 days ago
We recommend that you don't store or log credit card data encrypted with Braintree.js.

As far as PCI compliance, Braintree.js minimizes your PCI scope as much as tokenization. As long as you serve your site over SSL and maintain adequate security around access to servers, administrative passwords, etc., when using Braintree.js, you'll fall under SAQ A (the lowest possible PCI scope for online merchants).