You are viewing limited content. For full access, please sign in.

Question

Question

Laserfiche Forms - PCI-DSS/PA DSS

asked on March 20, 2023

Does Laserfiche forms meet the requirements of  Payment Card Industry Data Security Standard  (PCI-DSS/PA DSS)

0 0

Replies

replied on March 20, 2023

It appears that it is not unless you're using a compliant integration to handle the customer data/transactions.

The Forms Braintree and Authorize.net integrations collect all cardholder data within an Iframe and send it to a third party, so that the Laserfiche Forms Server does not store any cardholder data. This simplifies PCI compliance, as both Braintree and Authorize.net are PCI-compliant frameworks. You should still complete a Self-Assessment Questionnaire (SAQ) for PCI compliance validation

Configuring the Payment Gateway Integration (laserfiche.com)

2 0
replied on March 20, 2023

I agree with what Kevin Wells has laid out.  Also, in doing the PCI-DSS 3.x SAQ you will be able to make sure that your system is not storing any payment card data (redacted or not redacted). 

1 0
You are not allowed to follow up in this post.

Sign in to reply to this post.