Hosted Tokenization and PCI-DSS compliance

Hi,

We're looking into integrating the Moneris API with our NAC solution PacketFence (www.packetfence.org) in order to collect payments prior to granting network access.

We are looking for a solution that would avoid us having to make our solution and the environment its running in PCI compliant.

We already integrate with Stripe and other solutions that offer a client side payment platform with a token submission to our server that we validate with the Stripe API to confirm payment.

We're looking for something similar with Moneris. The closest thing I found is "Hosted Tokenization" but it seems we'd still be handling sensitive information so I'm not sure if this removes the need for our server to be PCI compliant.

If "Hosted Tokenization" doesn't fit our need, could you suggest what solution would work

Thanks in advance

- Julien

  • Being in the payment sector there is always a need to be PCI compliant. This does not mean you need to be assessed by a 3rd party and scanned. Using our hosted tokenization makes the entry of the card within an encrypted frame which means your server is not touching PCI sensitive data.