Do you have a guide for PCI Compliance?
PCI Scope Overview for High Trek POS Customers
This article explains how PCI DSS applies to your environment, why most requirements are out of scope for you, and how to correctly answer the PCI Self‑Assessment Questionnaire (SAQ).
For a step-by-step instructions please visit: Step-by-Step Instructions
For a video walk through please visit: Video Walk Through
1. How Our Platform Minimizes PCI Scope
Our platform is intentionally designed so that raw credit card data never enters your systems or ours. Because of this architecture, the majority of PCI DSS requirements do not apply to your environment.Card‑Present Payments (On‑Site Transactions)All in‑person transactions use PCI‑validated Point‑to‑Point Encryption (P2PE) terminals.
- Card data is encrypted immediately inside the terminal.
- Encrypted data is sent directly to the payment processor.
- Neither you nor our platform ever sees or stores the card number.
When customers enter card information online, the card field is a secure iframe hosted by CardConnect.
- Card numbers are entered directly into CardConnect’s vault.
- Our system receives only a token — a safe, non‑sensitive reference used to process payments.
- No cardholder data is stored, transmitted, or processed by your systems.
Because of these controls, your PCI responsibilities are limited to operational practices and basic administrative requirements.
2. Your Responsibilities Within PCI Scope
Even though card data never touches your environment, PCI still requires you to maintain certain practices.Operational Responsibilities
Your staff must follow secure handling procedures, including:- Not writing down, photographing, or storing card numbers in any unapproved manner
- Destroying any card information received verbally (e.g., over the phone) immediately after use
- Ensuring payment terminals remain secure and free from tampering or customer manipulation
These responsibilities focus on employee behavior and physical security — the only areas where you have direct PCI exposure.
3. Policy & Training Requirements
PCI DSS also requires that you maintain written policies and training covering the responsibilities listed above. At a minimum, you must:
- Document on how employees are expected to handle card data securely
- Train all staff who may interact with payment information
- Review and update these policies periodically
These administrative controls demonstrate that your organization understands its PCI obligations and enforces secure practices.
4. How to Answer Out‑of‑Scope Questions in the PCI Questionnaire
The PCI questionnaire includes many items that do not apply to your environment because you never store, transmit, or process raw credit card data. Examples include:
- “Do you lock up your physical media?”
- “How do you secure stored cardholder data?”
Example:
Question:“Do you secure physical media containing cardholder data?”You should answer:
“Yes — because no media containing cardholder data exists in our environment.”This approach:
- Prevents confusion
- Avoids additional PCI review steps
- Still accurately reflects your true PCI scope
Summary
Because of the security measures built into our platform — P2PE terminals and hosted payment fields — your PCI scope is extremely limited. Your responsibilities focus on:- Employee behavior
- Terminal security
- Written policies and training
- Answering out‑of‑scope questions in a way that avoids unnecessary follow‑up