PCI Compliance Stripe

Discussions focus on PCI DSS compliance for handling credit card data and how services like Stripe mitigate requirements by tokenizing cards without merchants storing sensitive information.

📉 Falling 0.3x Finance & Crypto
3,897
Comments
20
Years Active
5
Top Authors
#8980
Topic ID

Activity Over Time

2007
2
2008
33
2009
74
2010
234
2011
287
2012
259
2013
370
2014
291
2015
269
2016
232
2017
216
2018
215
2019
215
2020
238
2021
174
2022
234
2023
244
2024
157
2025
140
2026
13

Keywords

e.g stripe.com INFORMATION PSP FirstData THE Stripe.js AND VPS EP pci card stripe credit card credit compliance payment merchant cc secure

Sample Comments

lotsofcows Mar 1, 2013 View on HN

How does Stripe mitigate PCIDSS requirements?

EGreg Jan 5, 2016 View on HN

Guess the PCI Compliance thing works at least. Otherwise why do they need to ask his credit card authorization?

tinus_hn May 16, 2017 View on HN

They are not supposed to even store the ccv and certainly can't send it anywhere without encryption. Report them to your issuer.

aembleton Sep 17, 2018 View on HN

Well you're not holding credit card details, so no there should be no need to worry about PCI.

teyc Jan 3, 2012 View on HN

Don't VISA et al require some kind of PCI compliance for storing credit card details?

fuzzmeister Apr 23, 2010 View on HN

Certain companies (like Braintree) offer a service where the credit card data is POSTed directly to their server, relieving you of most aspects of PCI compliance.

m11a Aug 28, 2020 View on HN

Stripe.js creates an iframe hosted by Stripe which sends the card information directly to Stripe. The merchant cannot see or intercept that card info, during or after transmission, and thus cannot send it to another processor (at least not using the same payment card input boxes).

ashcairo Nov 15, 2013 View on HN

Can't the merchant just treat it like an online payment. Take the Card number, expiry date and security code?

smt88 Feb 28, 2019 View on HN

Apparently it uses Stripe, and as long as the dev isn't trying to intercept/store payment info (e.g. in logs), Stripe handles PCI compliance

gauravk92 Mar 20, 2012 View on HN

Stripe does this really well using a js lib. The sensitive data thus never hits your servers and it's a much better experience for devs who don't want/have to deal with PCI compliance.