# 

PCI DSS is the card industry's security standard. Anyone who stores, processes or
transmits cardholder data is in scope for it, and the size of that obligation
depends almost entirely on one choice: whether card numbers pass through your
systems.

This page is orientation, not compliance advice. Your acquirer and your assessor
decide what applies to you.

## Scope follows the data

| If your servers | Your scope |
|  --- | --- |
| Never see a card number | Smallest. Usually a short self-assessment |
| Receive card numbers and forward them | Larger. Every system that touches one is in scope |
| Store card numbers | Largest. Encryption, key management, retention, access control |


The gateway is PCI DSS compliant, which covers our side. It does not cover yours.

## Keeping card numbers out of your systems

The tokenization flow exists for this. Once a card has been charged, you hold a
[payment token](/docs/payments/save-and-reuse-a-payment-method) rather than a
number, and repeat charges never reintroduce one.

For the first charge, the practical options are:

* **Collect the card in a page your servers do not process** — a hosted or
embedded form — so the number goes to the gateway and not through you.
* **Accept the number server-side and forward it immediately**, storing nothing.
This is in scope, and it is a real obligation.


There is no third option where you hold card numbers and stay out of scope.

## Things that put you back in scope

Easy to do by accident:

* **Logging a request body** that contains `pan` or `cvv`. The most common one.
* **Storing a CVV.** Never permitted after authorization, by anyone, for any
reason.
* **Screenshots and support tickets** carrying full card numbers.
* **Database backups** of a table that once held card data.


The API never returns a full card number. Responses carry `truncated_pan`, which
is safe to store and display.

## What we handle

|  |  |
|  --- | --- |
| Card data at rest | Encrypted in our vault |
| Card data in transit | TLS on every connection |
| CVV | Used for the authorization, never stored |
| Tokenization | A token you can store freely |


## Next steps

* [Tokenization](/docs/concepts/tokenization)
* [Save and reuse a payment method](/docs/payments/save-and-reuse-a-payment-method)
* [AVS and CVV](/docs/concepts/avs-and-cvv)