Hacker News new | ask | show | jobs
by rtanaka 4247 days ago
We are in the process of both PA-DSS for our cloud services and PCI approval for the device. This is the primary reason we are not shipping to merchants until next year. We have line of site to certification and we would not (and can not) ship to merchants until this is complete.
1 comments

Afaik you should have PA-DSS to your app running on top of the Android OS that btw is not PCI. Just PA-DSS to your cloud services considering the architecture you are proposing is not enough. PCI-PTS to your hardware is another problem you are going to face in your certification because you are using a touchscreen 'pinpad'.
It wouldn't be fun if all this was done before. This is uncharted territory and we are not taking it lightly. We have involved the right talent (some payment industry experts) and have designed this carefully. We are confident that we will pass all certifications necessary to satisfy everyone (including our own high standards).