Overview
This article explains your PCI DSS compliance responsibilities as a customer of Aiwyn. Aiwyn uses Stripe Connect, a payment system fully integrated with our platform, to securely process card payments. The Aiwyn platform is designed so that cardholder data is never handled by your systems, which significantly reduces your PCI compliance obligations.
What Is PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements established by the major card brands to protect cardholder data. Any organization that stores, processes, or transmits cardholder data is potentially subject to PCI DSS requirements.
Why We Chose Stripe and How You Know It Is Secure
Stripe is a globally trusted payments provider that handles payments for Kickstarter, Shopify, Facebook, UNICEF, Lyft, Target, and hundreds of thousands of other companies. Stripe is one of the most security-aware companies in the industry.
As noted in Stripe's security documentation, anyone involved with the processing, transmission, or storage of card data must comply with PCI DSS. Stripe has been audited by an independent PCI Qualified Security Assessor (QSA) and is certified as a PCI Level 1 Service Provider — the most stringent level of certification available in the payments industry.
PCI compliance is a shared responsibility. The simplest way to be PCI compliant is to never see (or have access to) card data at all — and Aiwyn's Stripe integration is built to do exactly that.
How Payments Are Processed on Aiwyn
The payments tool uses multiple layers of security to protect sensitive payment information. It is built on Stripe's API integration, which manages the secure collection and transmission of payment data.
- All card payments are processed using Stripe's PCI-compliant, hosted payment infrastructure
- Card data is entered directly into Stripe-hosted payment components
- Payment credentials are encrypted and tokenized by Stripe, ensuring unauthorized parties cannot access sensitive payment information
- Card data is never exposed to your systems
Your PCI Compliance Responsibilities as an Aiwyn Customer
No SAQ or PCI Attestation Required
With most traditional payment processors, businesses that accept card payments must annually validate their PCI compliance by submitting documentation and undergoing network vulnerability scans. With Aiwyn, Stripe acts as the payment processor — so as long as you:
- Use Aiwyn's standard payment flows, and
- Do not handle card data outside the Aiwyn platform,
you are not required to:
- Complete a PCI DSS Self-Assessment Questionnaire (SAQ)
- Submit an Attestation of Compliance (AOC)
- Undergo PCI scans or audits
Aiwyn completes the required annual SAQ A on behalf of the platform.
Why Customers Are Out of PCI Scope
You are considered out of PCI scope because:
- You do not store card numbers
- You do not process card data on your servers
- You do not transmit card data through your systems
- You do not host payment pages that collect card information
Your role is limited to accessing payment results and reports via Aiwyn's firm portal.
When PCI Requirements Would Apply
You may become responsible for PCI compliance if you independently:
- Accept card numbers via phone, email, or paper
- Store card data outside of Aiwyn's platform
If any of the above occur, you may need to complete a PCI SAQ appropriate to your setup.
Best Practices for Staying Out of PCI Scope
To maintain your current compliance posture:
- Only accept payments through Aiwyn's approved payment methods
- Do not request or store card numbers outside the platform
- Direct customers to Aiwyn for all card payments
Requesting Additional PCI Documentation
If you would like more information, or to request a copy of Aiwyn's SAQ document, please email support@aiwyn.ai.