Open
Description
Hi 👋
Is this library required to be used by "not PCI-compliant" apps? (having "PCI DSS SAQ A-EP" compliance level)
For example in Frames for Web card details are entred by customer inside iframe
element, making it impossible to access untokenized data even if my site was breached.
But there is no such "isolation layer" in this library, right? Does this mean I can ask user to enter card number into my own TextInput
and make own tokenization call too?
Metadata
Metadata
Assignees
Labels
No labels