RevKeenDocs

Card Data and PCI Responsibilities

How RevKeen reduces card-data exposure and where merchants should obtain PCI guidance

RevKeen is designed to reduce exposure to sensitive card data by using NMI Collect.js tokenisation. This page describes the intended technical flow. It is not a certification, Attestation of Compliance, or determination that a merchant is eligible for a particular PCI DSS Self-Assessment Questionnaire.

Intended card-data flow

Customer browser  -->  NMI Collect.js / gateway  -->  Acquirer and card networks
                                  |
                             Returns token
                                  |
                         RevKeen stores reference
  1. A customer enters card details into fields connected to NMI Collect.js.
  2. The card information is sent to the gateway over an encrypted connection.
  3. The gateway returns a tokenised reference and transaction result.
  4. RevKeen stores the token and limited masked metadata needed to provide billing and payment reporting.

RevKeen does not intend to retain:

  • complete card numbers;
  • CVV or CVC values;
  • PIN data;
  • magnetic-stripe data; or
  • complete track data.

Merchant responsibilities

Merchants remain responsible for the PCI DSS requirements applying to their own websites, staff, systems, integrations, terminals, provider accounts, and method of using RevKeen. They should:

  • follow Elavon and NMI instructions;
  • complete the assessment or validation their acquirer requires;
  • use strong authentication and restrict account access;
  • never place complete card data in logs, email, support requests, APIs, or custom fields;
  • keep merchant-controlled sites and scripts secure; and
  • report suspected card-data compromise immediately.

Hosted and custom integrations

The applicable PCI scope depends on the actual integration, including how payment fields are delivered, which scripts can affect the payment page, and whether any merchant-controlled system can receive card data. RevKeen does not state that all hosted or embedded implementations qualify for SAQ A.

Before accepting live card payments, confirm the appropriate validation route with Elavon, NMI, or a PCI Qualified Security Assessor. Custom integrations that cause card data to pass through merchant or RevKeen servers are outside the intended tokenised design and must not be deployed without a separate security and PCI review.

Current status

RevKeen is not publishing a PCI DSS compliance or certification claim on the basis of this architecture alone. Any future claim must be supported by the applicable completed assessment and approved evidence.

For questions about RevKeen's implementation, contact security@revkeen.com.