PCI DSS

PCI-oriented architecture for merchant payment operations.

The frontend is designed to support a PCI DSS-compliant deployment. Certification depends on the full hosting, operational, provider and assessment environment.

Safeguards by design

Keep raw card data out

Use approved hosted or tokenized payment components. Raw PAN, CVV, PIN and magnetic-stripe data must never enter eKash Business application state.

Limit access by role

Apply least-privilege access, session controls and approval workflows so only authorized users can perform sensitive operational activity.

Protect the full environment

A compliant deployment requires appropriate hosting, providers, operational procedures, monitoring and independent assessment in addition to frontend design.

What a secure deployment requires

Application design

Use hosted, tokenized or provider-controlled payment components so sensitive card data is not collected or retained in frontend state.

Operational processes

Maintain appropriate user access reviews, incident processes, evidence and training for the people who operate payment workflows.

Deployment and assessment

Confirm the infrastructure, service providers and required assessments for the actual production scope before representing any environment as compliant.