PCI DSS Compliance
It doesn't need to be. CrowdHandler does not store or transmit credit card numbers (PANs) and does not form part of your Cardholder Data Environment (CDE), so CrowdHandler is out of scope for PCI compliance.
However, we still meet relevant requirements of PCI DSS due to our role enabling ecommerce solutions and use of a third-party payment processor to bill our clients. Our PCI compliance measures include:
PCI Scoping
CrowdHandler is not considered a service provider that can impact the security of cardholder data under PCI DSS except for our own billing process. We have no visibility into client payment flows or card numbers as:
- We do not collect, transmit or store raw cardholder data (PAN) or sensitive authentication data (SAD) for client transactions or via our DNS implementation.
- We have no access to merchant environments where PAN/SAD could be present.
- Our service only interacts with end user interactions before a transaction and does not handle money movement.
However, we do use Stripe to bill our clients, and validate this use of a third-party payment processor under SAQ-A to confirm we meet best practices for securely handling our own payments and billing information collection.
PCI Reporting
PCI Self-Assessment Questionnaire A (SAQ-A) - We complete SAQ-A on an annual basis to evaluate security controls for our billing process and use of Stripe as our payment processor. Clients can request a copy of our SAQ-A report.
Here are some specifics for our supported integrations:
No integration
If you do not integrate with CrowdHandler, the only connection between CrowdHandler and your website is a link. CrowdHandler does not form part of your CDE, in the same way that Google, or any other site that links to your site is not part of your CDE.
JavaScript Integration
The JavaScript integration only looks at the CrowdHandler cookie, and very basic browser information to provide a place in the queue, and check it. No cardholder data is exchanged. Integrating CrowdHandler is like integrating any other snippet of JavaScript you might use - e.g. Google Analytics. Even then, JavaScript communicates with the CrowdHandler platform solely via the API, which is protected as you will see below.
API Integration
We're separated from your CDN by the API boundary and our network. Don't send credit card details to our API. We don't see why you would, there are no credit card parameters, because we don't deal with credit cards. But to be clear, you agree not to do this in the terms of service, and if you do, our outsourced and PCI-compliant firewall service will reject your request at the edge of our network. We don't transmit or store cardholder data.
DNS Implementation
But if I use your DNS implementation, surely CrowdHandler is becoming part of my CDE? Nope! The CDN we use to proxy your traffic is supplied by Amazon Web Services and is certified PCI compliant. However, as above, it is set to reject any traffic that incorporates PANs at the edge. If you have an old-school website that directly accepts credit card details (these are increasingly rare) then unfortunately, you will not be able to use the CDN integration option, as the PANs will be detected and blocked before reaching our network.
If you wish to use our CDN, and continue to take credit card details, you should ensure you isolate your website from your CDE by using a third-party API driven service to take and store cardholder data on your behalf. You could use a platform like Stripe. The vast majority of our clients already do this. Please note: If you are a merchant, you still have responsibilities to ensure you are effectively separating your CDE and using secure-coding techniques, and may be required to complete a Self Assessment Questionnaire in order to comply. Unfortunately we cannot provide general PCI compliance advice.
I used a credit card to sign up to your service!
We use Stripe for credit cards, we never see the PAN, we just get the last four digits. Stripe are one of the World's largest payment providers and are PCI certified.