PCI DSS
Payment card infrastructure for commerce and fintech
PCI DSS v4.0-aligned from network to logging
Reduce PCI scope with network segmentation, tokenization patterns, and documented shared-responsibility boundaries. Our infrastructure controls map to PCI DSS v4.0 across all 12 requirement domains.
Overview
PCI DSS v4.0 is the Payment Card Industry Data Security Standard governing the handling of cardholder data (CHD) and sensitive authentication data. VxCloud provides infrastructure controls that map to all 12 PCI DSS requirement domains, with documented shared-responsibility boundaries so your QSA can trace every requirement to either your responsibility, our responsibility, or a shared-controls arrangement.
Customers building in-scope systems (accepting, transmitting, storing cardholder data) benefit from network segmentation templates, tokenization patterns that minimize PCI scope, hardened compute baselines mapped to CIS benchmarks, immutable audit logging meeting Requirement 10, and quarterly internal vulnerability scan automation. Many customers reduce their PCI scope significantly by using VxCloud-managed tokenization and keeping raw PAN data out of their own environment.
What's included
Production-grade capabilities, ready to enable in your workspace.
Network segmentation
Templates and enforcement patterns that isolate the Cardholder Data Environment (CDE) from out-of-scope workloads.
Tokenization patterns
Replace PAN with tokens at the edge. Reduce PCI scope to the tokenization boundary; keep raw CHD out of your app.
Encryption at rest & in transit
AES-256 at rest with key rotation, TLS 1.2+ in transit with strong cipher suites. Meets Requirement 4.
Access control & MFA
Role-based access, mandatory MFA for CDE access, session timeouts, password policies. Meets Requirement 8.
Audit logging
Immutable audit trail with user, timestamp, source, and action for every CDE access. Meets Requirement 10.
Vulnerability scanning
Quarterly automated internal vulnerability scans and documented remediation workflows. Supports Requirement 11.
Business outcomes
Measurable impact teams see when they adopt pci dss.
PCI scope via tokenization
Customers using our tokenization patterns typically reduce in-scope systems by 70-90%, shrinking assessment scope.
Requirement domains mapped
Infrastructure controls are mapped requirement-by-requirement to PCI DSS v4.0 for your QSA.
Responsibility matrix
A documented matrix identifies which party (you, VxCloud, shared) owns each control, accelerating QSA assessment.
Internal scan automation
Automated quarterly internal vulnerability scans with findings routed to your ticketing system for remediation.
How customers use it
Real scenarios from VxCloud customers across regulated industries and fast-moving teams.
Online retailer processing ~1M transactions/year
Tokenization at the edge reduces in-scope systems to the payment gateway. Retailer qualifies for SAQ A-EP instead of full SAQ D.
Neobank handling card issuance and processing
Full CDE runs on VxCloud with segmented network, hardened compute, and audit log export to the bank's SIEM.
Billing platform for downstream merchants
PCI Level 1 assessment passes with VxCloud providing Requirements 1, 2, 7, 8, 10, 11 infrastructure controls.
Online travel agency with multiple payment integrations
Segmentation between CDE and non-CDE workloads allows the majority of services to remain out of PCI scope.
Frequently asked questions
Still have questions? Our enterprise team answers within one business day.
VxCloud operates as a Level 1 Service Provider for the specific services within the CDE scope. Our Attestation of Compliance (AoC) and responsibility matrix are available under NDA for customer QSAs.
Related enterprise capabilities
Ready to move forward with PCI DSS?
Talk to our enterprise team — we'll scope your requirements, map the right capabilities, and build a rollout plan tailored to your organization.