PCI-DSS compliance — SAQ-A scope and what it means
We don't touch card data — all payments via certified processor. SAQ-A scope means simplest, safest setup for Poland clients.
SAQ-A — outsourced cardholder data environment
SAQ-A applies because card data is fully outsourced to a PCI-DSS Level 1 processor. We never see PAN, never store CVV, never process card data on our servers. Our role is redirect/iframe only.
Tokenization for recurring billing
Repeat customers pay via tokens. Tokens are not card numbers — useless if exposed, scoped to our merchant ID. Token vault held by processor, not by us.
Network and quarterly scans
ASV-approved external scans quarterly. Internal vulnerability scans monthly. Pentest annually. Findings remediated to processor's SLA.
Poland — local payment context
Poland customers commonly pay via wire transfer or SEPA SDD for B2B. Card payments handled via processor with VAT 23% reverse-charge handling. KSeF flow happens after payment confirmation — never holds card data.
FAQ
Are you PCI-DSS Level 1?
No — SAQ-A. Level 1 applies to processors handling millions of transactions. We outsource to a Level 1 processor.
Can we see your AoC?
Yes — Attestation of Compliance shared under NDA.
3DS/SCA support?
Yes — Strong Customer Authentication via 3D Secure 2.x, mandatory for EEA card transactions under PSD2.
Refunds — how long?
Card refunds: 3-10 business days depending on issuer. SEPA: 1-3 days. Wire: 1-5 days.
Chargebacks?
Handled by processor — we cooperate with evidence package within 48 hours.