Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What is considered cardholder data may surprise you. I’ve implemented many integrations. It’s very specific and requires the primary account number. For example if the PAN is stored separate the name and/or expiration data isn’t considered cardholder data.

For the record storing this information would be folly - can’t lose what you don’t have. Let the payment processor assume the responsibility by storing and handling that if needed.



(PAN = credit card number, for those outside the industry)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: