pci-dss-rails

Installation
SKILL.md

PCI-DSS for Rails

PCI-DSS is the card brands' security standard. If your app touches Primary Account Numbers (PAN), the standard applies. The cheapest path to compliance: don't touch PAN. Use Stripe Elements / Braintree Hosted Fields. The card data never enters your servers. This skill is short by design — the long version is "delegate to a PCI Level 1 provider."

The opinion

NEVER store, transmit, or process PAN (the long card number) on your servers. Use Stripe Elements, Braintree Hosted Fields, or Adyen Drop-In — the iframe approach. Card data goes browser → payment processor, you get a token. This keeps you at SAQ-A scope (the lightest PCI questionnaire). Anything else (SAQ-A-EP, SAQ-D) blows up your compliance scope. NEVER log card numbers anywhere.

What is PCI-DSS?

The Payment Card Industry Data Security Standard, v4.0. 12 requirements, ~300 controls. Annual audit for high-volume merchants; self-assessment questionnaires (SAQ) for smaller ones.

SAQ Who Scope
SAQ-A E-commerce, fully outsourced to provider Lightest — confirm provider compliance, no card data on your servers
SAQ-A-EP E-commerce, partial outsourcing (e.g., you redirect through your server) Bigger — your servers are in scope
SAQ-D You store / process / transmit PAN Massive — full 300+ controls, annual audit

You want SAQ-A. Period.

Installs
1
GitHub Stars
21
First Seen
Sep 8, 2026
pci-dss-rails — sandeepmvl/rails-skills