Hermes Wiki

PCI DSS

Payment card data security standard.

Why we need this / what value this brings

Mishandling card data is both a major security risk and a compliance violation with real financial penalties.

When to use this

As soon as any part of the system touches card data directly, even in transit.

How to use or implement this

Use a PCI-compliant payment processor's hosted fields/tokenization so card data never touches Localz's own servers, keeping Localz out of the highest PCI scope tiers.

Research questions

  • Directly relevant the moment Localz touches card data — does the payment integration keep Localz out of PCI scope (e.g. via Stripe-hosted fields)?

Empty folder — drop notes, links, and findings here as you research.

Hermes Wiki