pci-dss-rails
PCI-DSS for Rails
PCI-DSS is the card brands' security standard. If your app touches Primary Account Numbers (PAN), the standard applies. The cheapest path to compliance: don't touch PAN. Use Stripe Elements / Braintree Hosted Fields. The card data never enters your servers. This skill is short by design — the long version is "delegate to a PCI Level 1 provider."
The opinion
NEVER store, transmit, or process PAN (the long card number) on your servers. Use Stripe Elements, Braintree Hosted Fields, or Adyen Drop-In — the iframe approach. Card data goes browser → payment processor, you get a token. This keeps you at SAQ-A scope (the lightest PCI questionnaire). Anything else (SAQ-A-EP, SAQ-D) blows up your compliance scope. NEVER log card numbers anywhere.
What is PCI-DSS?
The Payment Card Industry Data Security Standard, v4.0. 12 requirements, ~300 controls. Annual audit for high-volume merchants; self-assessment questionnaires (SAQ) for smaller ones.
| SAQ | Who | Scope |
|---|---|---|
| SAQ-A | E-commerce, fully outsourced to provider | Lightest — confirm provider compliance, no card data on your servers |
| SAQ-A-EP | E-commerce, partial outsourcing (e.g., you redirect through your server) | Bigger — your servers are in scope |
| SAQ-D | You store / process / transmit PAN | Massive — full 300+ controls, annual audit |
You want SAQ-A. Period.