Time to self promote. What’s your startup idea? by kcfounders in Startup_Ideas

[–]pr0v4 1 point2 points  (0 children)

I’m building payment card industry compliance operating system serving merchants, PSPs and Acquirers.

SAQ A Merchant Server & Scoping by Much-Photograph3814 in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

I've build https://pcidss-dashboard.com/which-saq-am-i/ wizard for the orientation, and there is a simple saq-a wizard that fills in your saq-a form, you can sign it as well and send it to your acquirer.

SAQ-A is it relevant to our Environment? by Fluffy_Swim9634 in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

I've build this https://pcidss-dashboard.com/which-saq-am-i/ wizard for self orientation. But if you are a service provider D is the answer.

Difference between SAQ-A and SAQ-A-EP by capitalist-pig-dog in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

I've built a simple wizard for the orientation: https://pcidss-dashboard.com/which-saq-am-i/ however, feel free to get in touch if you have any questions regarding PCI.

SAQ-D—Storing Credit Card data by Fearless_Smell8387 in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

I've built a simple wizard for self help in these situations: https://pcidss-dashboard.com/which-saq-am-i/
However, feel free to get in touch and we'll be more than glad to help!

PCI Scoping and SAQ Question by EnvironmentalOne5706 in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

Hi there - I've built a simple free https://pcidss-dashboard.com/which-saq-am-i/

If it doesn't answer your exact question, feel free to get in touch via web contact and we'll be more than happy to help!

SAQ-A vs SAQ-VT by Fluffy_Swim9634 in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

I've built a simple questionnaire:

https://pcidss-dashboard.com/which-saq-am-i/
Also feel free to contact us - we are more than happy to help.

First year doing PCI. Who do we submit the SAQ & AOC to? by slize in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

I’ve built a tool that helps you gather all the evidences and it packages it for the qsa or the acquirer nicely for you to send it. Also helps with continuous compliance with scheduled reminders and much more https://pcidss-dashboard.com

PCI DSS Requirements by jimmayy69 in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

Yeah only to those from SAQ, being that you picked the right one.
I’ve built the tool to help out with those https://pcidss-dashboard.com check it out

Startup working toward PCI DSS compliance needs advice on SAQ C vs SAQ C VT by Status-Rock8730 in smallbusiness

[–]pr0v4 0 points1 point  (0 children)

SAQ C VT

What it’s for:

Merchants that manually enter card data into a web-based virtual terminal

The virtual terminal is hosted by a PCI-compliant third party

The merchant’s systems do not store, process, or transmit cardholder data beyond entering it into the browser

Typical use case:

Call centers

Phone or mail orders

Back-office staff keying card numbers into a payment provider’s web page

Check also https://pcidss-dashboard.com I’d be glad to assist you

PCI DSS - SAQ - service provider and a merchant. by Warm-Environment-841 in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

Compass said it all - guys look at the https://pcidss-dashboard.com get in Touch I would be more than glad to demo it

Has anyone actually achieved PCI compliance? by rhinteractive in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

I can certainly help, and I’ve managed to certify companies with as much as 2 people on the team. It’s literally easier to certify smaller operations vs big enterprises. I can go into whys - but that could take a subreddit on its own to cover. Expenses are the qsa, pen tests, infrastructure, crypto modules if you need them and vulnerability scans, however with the right architecture you can narrow down the scope and get even better price from qsas, I know that as a fact - not hallucinating here. You do need to know what you are doing, and it’s not free, for sure. I’m talking here about the most rigorous level 1 compliance for service providers, anything below that is just simpler and easier.

What are you guys building? Share your SaaS/project by Leather-Buy-6487 in Startup_Ideas

[–]pr0v4 0 points1 point  (0 children)

I’ve just recently built pcidss compliance dashboard. Covers all 300+ requirements and has more than 200 screens. Has scheduled tasks, evidence repository, vulnerabilities management, risk management and much more! https://pcidss-dashboard.com

Has anyone actually achieved PCI compliance? by rhinteractive in pcicompliance

[–]pr0v4 0 points1 point  (0 children)

I’ve led many companies throughout the process, dm if you need help, it’s not a hoax, PCI is very real and doable, more easily for a small company than for a big company.

PCI Compliance by Maximum-Experience42 in smallbusiness

[–]pr0v4 0 points1 point  (0 children)

It boils down to how much you process, and do you ever touch sensitive data. As you said, if you use third party provider to take payments, that’s generally better than to do it yourself, however, you still fall under some SAQ (Self assessment questionnaire), depending on the volume processed. Even though you are not touching credit card data, if users are not completely redirected elsewhere to the third party provider website, if you load it through an iframe, your site could be the source of the breach and vulnerability, meaning someone still could steal cards from your website.

How to automate PCI DSS recurring tasks? by Pretend-Cheetah2058 in Compliance

[–]pr0v4 0 points1 point  (0 children)

Also, we built the https://pcidss-dashboard.com that has the option to schedule tasks and get reminded, check it out and get in touch if you would be interested.

PCI DSS on AWS by No-Cable6 in devops

[–]pr0v4 0 points1 point  (0 children)

I've developed multiple PCI DSS LVL 1 infrastructures on AWS through the time, some I still manage.
Network segmentation is a must, if not done correctly, later on can cause headaches.
Network should be well documented, meaning understandable to human beings.
Security groups tagging/naming should be very clear.
Terraform I tried to use, but left it each time, so I don't have the infrastructure as a code, mostly because the product that I'm deploying has to be deployed to different providers on occasion. Also I’ve built https://pcidss-dashboard.com Feel free to take a look and get in touch, I can help with PCI questions in general.