PCI DSS
Payment card data security standard.
Why we need this / what value this brings
Mishandling card data is both a major security risk and a compliance violation with real financial penalties.
When to use this
As soon as any part of the system touches card data directly, even in transit.
How to use or implement this
Use a PCI-compliant payment processor's hosted fields/tokenization so card data never touches Localz's own servers, keeping Localz out of the highest PCI scope tiers.
Research questions
- Directly relevant the moment Localz touches card data — does the payment integration keep Localz out of PCI scope (e.g. via Stripe-hosted fields)?
Empty folder — drop notes, links, and findings here as you research.