PCI DSS Compliance
The Payment Card Industry Data Security Standard (PCI DSS) governs how organizations store, process, and transmit cardholder data. AfriRoute is designed so that card data never touches your servers — dramatically reducing the compliance burden on merchants using our Payments API.
🛡️ How AfriRoute Handles Cardholder Data
AfriRoute operates a PCI DSS Level 1 certified payment environment — the highest level, required for processors handling large transaction volumes.
| Control | How AfriRoute Implements It |
|---|---|
| Data encryption | TLS 1.2+ in transit; AES-256 at rest |
| Network segmentation | Cardholder data environment (CDE) isolated from general infrastructure |
| Access control | Role-based access, least privilege, full audit logging |
| Tokenization | Raw PANs replaced with non-reversible tokens (see below) |
| Annual audit | Independent QSA assessment + quarterly ASV scans |
Sensitive authentication data (CVV, full magnetic stripe) is never stored after authorization.
🔑 Tokenization
When a card is captured through AfriRoute's hosted fields or payment widget, the raw card number (PAN) is sent directly to our CDE over an encrypted channel. We return a token that you store and reuse:
curl -X POST https://api.afriroute.ai/api/v1/payments/tokens \
-H "Authorization: Bearer $AFRIROUTE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"card": {
"number": "4111111111111111",
"exp_month": 12,
"exp_year": 2028,
"cvv": "123"
}
}'
{
"token": "card_tok_9f2a7b3c",
"brand": "visa",
"last4": "1111",
"exp_month": 12,
"exp_year": 2028
}
The token is meaningless if leaked and can be safely stored in your database. Charge it later without re-handling card data:
await fetch('https://api.afriroute.ai/api/v1/payments/charges', {
method: 'POST',
headers: {
'Authorization': 'Bearer $AFRIROUTE_API_KEY',
'Content-Type': 'application/json'
},
body: JSON.stringify({
source: 'card_tok_9f2a7b3c',
amount: 1500,
currency: 'KES'
})
});
📉 SAQ Scope Reduction
Because card data is entered into AfriRoute-controlled fields and never transits or rests on your systems, most merchants qualify for the simplest Self-Assessment Questionnaire:
| Integration Method | Typical SAQ | Why |
|---|---|---|
| Hosted payment page (redirect) | SAQ A | No card data touches your environment |
| Hosted fields / iframe | SAQ A | Card fields served by AfriRoute |
| Direct API with tokenization | SAQ A-EP | Your page orchestrates but does not transmit PAN |
| Server-side PAN capture | SAQ D | Avoid — keeps you in full scope |
Using hosted fields or the redirect flow can reduce a typical SAQ D (300+ controls) down to SAQ A (around 20 controls).
✅ What Merchants Are Responsible For
PCI DSS is a shared responsibility. AfriRoute secures the payment environment; you must still:
- Use the hosted fields or redirect flow — never collect raw PANs on your own forms.
- Keep your API keys secret; rotate them if exposed, and never embed secret keys in client-side code.
- Serve all payment pages over HTTPS.
- Maintain your own access controls and logging for systems that touch tokens or transaction data.
- Complete the annual SAQ appropriate to your integration and any required scans.
- Display required opt-in/consent and handle refunds per card-scheme rules.
📄 Requesting Compliance Documentation
Our Attestation of Compliance (AOC) and Responsibility Matrix are available to customers on request via Support. Reference these when completing your own assessment.
📚 Related Resources
- Payments API Reference
- Payments Overview
- Fraud Prevention
- Security Compliance
- Security Best Practices
- Data Protection
Last Updated: May 2026