|
|
|
|
|
by aethr
4063 days ago
|
|
Does anyone know if using transparent redirects actually waives your responsibilities for PCI compliance? Even though the credit card details aren't sent to your backend, they are still collected on a form hosted on your infrastructure. If your servers are compromised and malicious JS is added to your payment form, couldn't an attacker siphon credit card details via AJAX? It seems like the PCI documentation always uses terminology like "sites that collect credit card data", which I think sounds broad enough to include sites that use transparent redirects. |
|
The iframe option still qualifies you for SAQ A, which is the short questionnaire without scanning/testing requirements.