Skip to content
English - United States
  • There are no suggestions because the search field is empty.

Do you have a guide for PCI Compliance?

PCI Scope Overview for High Trek POS Customers

This article explains how PCI DSS applies to your environment, why most requirements are out of scope for you, and how to correctly answer the PCI Self‑Assessment Questionnaire (SAQ).

For a step-by-step instructions please visit: Step-by-Step Instructions
For a video walk through please visit: Video Walk Through

1. How Our Platform Minimizes PCI Scope

Our platform is intentionally designed so that raw credit card data never enters your systems or ours. Because of this architecture, the majority of PCI DSS requirements do not apply to your environment.

Card‑Present Payments (On‑Site Transactions)All in‑person transactions use PCI‑validated Point‑to‑Point Encryption (P2PE) terminals.
  • Card data is encrypted immediately inside the terminal.
  • Encrypted data is sent directly to the payment processor.
  • Neither you nor our platform ever sees or stores the card number.
This single control removes a large portion of PCI requirements from your scope.Online Payments (Website Transactions)

When customers enter card information online, the card field is a secure iframe hosted by CardConnect.
  • Card numbers are entered directly into CardConnect’s vault.
  • Our system receives only a token — a safe, non‑sensitive reference used to process payments.
  • No cardholder data is stored, transmitted, or processed by your systems.

Because of these controls, your PCI responsibilities are limited to operational practices and basic administrative requirements.

2. Your Responsibilities Within PCI Scope

Even though card data never touches your environment, PCI still requires you to maintain certain practices.

Operational Responsibilities

Your staff must follow secure handling procedures, including:
  • Not writing down, photographing, or storing card numbers in any unapproved manner
  • Destroying any card information received verbally (e.g., over the phone) immediately after use
  • Ensuring payment terminals remain secure and free from tampering or customer manipulation

These responsibilities focus on employee behavior and physical security — the only areas where you have direct PCI exposure.

3. Policy & Training Requirements

PCI DSS also requires that you maintain written policies and training covering the responsibilities listed above. At a minimum, you must:
  • Document on how employees are expected to handle card data securely
  • Train all staff who may interact with payment information
  • Review and update these policies periodically

These administrative controls demonstrate that your organization understands its PCI obligations and enforces secure practices.

4. How to Answer Out‑of‑Scope Questions in the PCI Questionnaire

The PCI questionnaire includes many items that do not apply to your environment because you never store, transmit, or process raw credit card data. Examples include:
  • “Do you lock up your physical media?”
  • “How do you secure stored cardholder data?”
Since no physical media or stored cardholder data exists, these requirements are technically Not Applicable. However, PCI requires you to explain why something is not applicable, which often leads to unnecessary follow‑up questions.To avoid that, you should answer “Yes” when the question refers to something that does not exist in your environment, and interpret the question based on intent.

Example:

Question:“Do you secure physical media containing cardholder data?”
You should answer:
“Yes — because no media containing cardholder data exists in our environment.”This approach:
  1. Prevents confusion
  2. Avoids additional PCI review steps
  3. Still accurately reflects your true PCI scope

Summary

Because of the security measures built into our platform — P2PE terminals and hosted payment fields — your PCI scope is extremely limited. Your responsibilities focus on:
  • Employee behavior
  • Terminal security
  • Written policies and training
  • Answering out‑of‑scope questions in a way that avoids unnecessary follow‑up
If you need help interpreting any specific PCI questions, our team is always available to assist.