Trust Centre · Payment security

PCI DSS readiness policy

24-SEVEN is designed to minimise payment-card scope and to fail closed until each gateway is formally commissioned.

Version 3.0Status: commissioning policyControl owner: Security and Finance roles
No PCI certification claim. This page documents readiness controls. It is not a PCI DSS certificate, Attestation of Compliance, Report on Compliance or Self-Assessment Questionnaire.

Purpose and scope

The policy applies to the 24-SEVEN website, shared-hosting application, administration and partner workflows, payment-provider integrations, people with payment duties, and any connected service that can affect the security of a payment page. Outsourcing payment processing does not by itself remove the merchant’s PCI DSS responsibilities.

Card-data minimisation

  • Guests are handed to an approved provider-hosted HTTPS checkout. 24-SEVEN forms do not request or intentionally store primary account numbers, card-security codes or magnetic-stripe data.
  • Browser redirects never prove payment. The server accepts a financial outcome only after signature validation and provider-side reference, amount, currency and status verification.
  • Secrets are encrypted at rest, excluded from source and entered only by an authorised administrator. Provider and property payment switches remain disabled until commissioning evidence is recorded.
  • Logs and support workflows must not contain card numbers or CVV values. Suspected card-data exposure is handled as a security incident.

Commissioning evidence gate

1Classify the installation and legal operator as merchant, service provider or both with the acquiring bank.
2Confirm the payment-page architecture and applicable validation route, including SAQ A eligibility where relevant.
3Complete the applicable SAQ, AOC or ROC process and any required approved scanning-vendor scans.
4Record gateway sandbox, webhook, reconciliation, refund and failure-path evidence.
5Obtain acquirer, payment brand or QSA acceptance where required; retain evidence under access control.

Operating responsibilities

Finance owns provider onboarding, settlement and reconciliation. Security owns scope, vulnerability and incident controls. Operations must use payment references—not card details—when helping guests. Engineering maintains secure configuration and release evidence. A third-party property may not enable payments until its verification, commercial terms and payment-readiness gate are complete.

Current status

The direct GlobalPAY contract is implemented for hosted checkout, transaction queries, encrypted notifications and reconciliation. It becomes selectable only after real merchant credentials, registered callbacks and production acceptance are recorded. Other gateways remain subject to their own credential, webhook and reconciliation gates.

Authoritative PCI SSC references