PCI Compliant Token-Based System

PCI compliance is required for all merchants who accept credit cards. Client wanted to accept credit cards but had a legacy system that was not PCI compliant. Rather than updating the legacy system to make it PCI compliant, we worked together with the client to create a separate PCI environment and token-based credit card processing system.

This saved the client tens of thousands of dollars and allowed the PCI requirements to be met in a matter of weeks instead of months.

What we did
  • Created a web service in the PCI environment for processing credit cards. All credit card data is stored encrypted in the PCI environment.
  • A token is issued which can be used to make additional payments, issue refunds, etc.
  • For automated orders, strip the credit card data on the way in prior to passing the order to the legacy system for processing.
  • All requirements of the PCI DSS were met for a fraction of the cost.