Keep raw card data out
Use approved hosted or tokenized payment components. Raw PAN, CVV, PIN and magnetic-stripe data must never enter eKash Business application state.
PCI DSS
The frontend is designed to support a PCI DSS-compliant deployment. Certification depends on the full hosting, operational, provider and assessment environment.
Use approved hosted or tokenized payment components. Raw PAN, CVV, PIN and magnetic-stripe data must never enter eKash Business application state.
Apply least-privilege access, session controls and approval workflows so only authorized users can perform sensitive operational activity.
A compliant deployment requires appropriate hosting, providers, operational procedures, monitoring and independent assessment in addition to frontend design.
Use hosted, tokenized or provider-controlled payment components so sensitive card data is not collected or retained in frontend state.
Maintain appropriate user access reviews, incident processes, evidence and training for the people who operate payment workflows.
Confirm the infrastructure, service providers and required assessments for the actual production scope before representing any environment as compliant.