Skip to main content

PCI DSS Compliance

The Payment Card Industry Data Security Standard (PCI DSS) governs how organizations store, process, and transmit cardholder data. AfriRoute is designed so that card data never touches your servers — dramatically reducing the compliance burden on merchants using our Payments API.

🛡️ How AfriRoute Handles Cardholder Data​

AfriRoute operates a PCI DSS Level 1 certified payment environment — the highest level, required for processors handling large transaction volumes.

ControlHow AfriRoute Implements It
Data encryptionTLS 1.2+ in transit; AES-256 at rest
Network segmentationCardholder data environment (CDE) isolated from general infrastructure
Access controlRole-based access, least privilege, full audit logging
TokenizationRaw PANs replaced with non-reversible tokens (see below)
Annual auditIndependent QSA assessment + quarterly ASV scans

Sensitive authentication data (CVV, full magnetic stripe) is never stored after authorization.

🔑 Tokenization​

When a card is captured through AfriRoute's hosted fields or payment widget, the raw card number (PAN) is sent directly to our CDE over an encrypted channel. We return a token that you store and reuse:

curl -X POST https://api.afriroute.ai/api/v1/payments/tokens \
-H "Authorization: Bearer $AFRIROUTE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"card": {
"number": "4111111111111111",
"exp_month": 12,
"exp_year": 2028,
"cvv": "123"
}
}'
{
"token": "card_tok_9f2a7b3c",
"brand": "visa",
"last4": "1111",
"exp_month": 12,
"exp_year": 2028
}

The token is meaningless if leaked and can be safely stored in your database. Charge it later without re-handling card data:

await fetch('https://api.afriroute.ai/api/v1/payments/charges', {
method: 'POST',
headers: {
'Authorization': 'Bearer $AFRIROUTE_API_KEY',
'Content-Type': 'application/json'
},
body: JSON.stringify({
source: 'card_tok_9f2a7b3c',
amount: 1500,
currency: 'KES'
})
});

📉 SAQ Scope Reduction​

Because card data is entered into AfriRoute-controlled fields and never transits or rests on your systems, most merchants qualify for the simplest Self-Assessment Questionnaire:

Integration MethodTypical SAQWhy
Hosted payment page (redirect)SAQ ANo card data touches your environment
Hosted fields / iframeSAQ ACard fields served by AfriRoute
Direct API with tokenizationSAQ A-EPYour page orchestrates but does not transmit PAN
Server-side PAN captureSAQ DAvoid — keeps you in full scope

Using hosted fields or the redirect flow can reduce a typical SAQ D (300+ controls) down to SAQ A (around 20 controls).

✅ What Merchants Are Responsible For​

PCI DSS is a shared responsibility. AfriRoute secures the payment environment; you must still:

  • Use the hosted fields or redirect flow — never collect raw PANs on your own forms.
  • Keep your API keys secret; rotate them if exposed, and never embed secret keys in client-side code.
  • Serve all payment pages over HTTPS.
  • Maintain your own access controls and logging for systems that touch tokens or transaction data.
  • Complete the annual SAQ appropriate to your integration and any required scans.
  • Display required opt-in/consent and handle refunds per card-scheme rules.

📄 Requesting Compliance Documentation​

Our Attestation of Compliance (AOC) and Responsibility Matrix are available to customers on request via Support. Reference these when completing your own assessment.


Last Updated: May 2026