No raw cardholder data
The application has no fields for PAN, CVV/CVC, track data, PIN or other sensitive authentication data.
Experia360 is engineered to minimize sensitive-data exposure and make high-risk operations explicit, tenant-scoped, reviewable and fail-closed.
Application safeguards reduce risk, but deployment, operations and organizational governance remain essential.
The application has no fields for PAN, CVV/CVC, track data, PIN or other sensitive authentication data.
Protected operations require authenticated organization membership and organization-scoped permission checks.
Bank credentials and sensitive identifiers are encrypted, hidden from serialization and excluded from audit payloads.
Connection activation, payout approval and onboarding review use separate-user controls where required.
Request IDs, audit events, status transitions and integrity hashes create evidence for operational review.
Money uses integer paise; posted journals are balanced and corrected through explicit reversals.
Source code alone cannot make an organization PCI DSS compliant. Any future card capture must use hosted or tokenized components supplied by a PCI DSS validated provider.