Security & Compliance

PCI-DSS Readiness Path

How UniWeb approaches Payment Card Industry Data Security Standard diligence — honesty first, no invented badges.

Effective: 15 August 2026 Version 2026.08 Uniweb Technologist PVT LTD
Important: UniWeb does not store, process, or transmit raw cardholder data (PAN, CVV, PIN). Card payments are handled by PCI-certified payment partners on their hosted pages. UniWeb is a merchant technology platform — we do not claim an independent PCI Level 1 certification or an RBI Payment Aggregator licence on this page. For diligence answers, start at Trust centre.
01

Our approach

UniWeb aims for SAQ-A style scope (lowest burden) because we do not touch raw card data when partners host card entry. This is a readiness path — not a completed independent assessment badge.

02

What we do NOT store

  • Primary Account Number (PAN) — full card numbers
  • Card verification values — CVV, CVC, CID
  • PINs or PIN blocks
  • Track data from magnetic stripes
  • Sensitive authentication data of any kind
03

What we DO store

  • Last 4 digits of card number (for display only, when the partner returns them)
  • Card brand (Visa, Mastercard, RuPay, etc.)
  • Card expiry month/year (for display only, when returned)
  • Gateway transaction reference / order ID
  • Tokenized references from gateways (if the customer opts for saved cards with the partner)
04

12 PCI-DSS Requirements — Readiness map

Statuses below are internal readiness notes for questionnaires — not a QSA attestation. Never treat green rows as “PCI Level 1 certified”.

RequirementStatusHow
1. Firewall configDelegatedHosting provider (Hostinger) manages network firewalls
2. Default passwordsControl in placeUnique app/DB secrets; never commit live keys
3. Stored cardholder dataOut of scope (design)No PAN/CVV on UniWeb. Only last 4 / brand when partner returns them
4. Encrypt transmissionControl in placeTLS via Hostinger. API and dashboard over HTTPS
5. Anti-virusDelegatedHosting provider manages server-side AV
6. Secure developmentControl in placePDO prepared statements, CSRF, input validation
7. Restrict accessControl in placeMerchant / staff roles; partner keys not on Support nav
8. Unique IDsControl in placeUnique accounts; staff 2FA available; session tracking
9. Physical accessDelegatedCloud-hosted; provider physical controls
10. Track & monitorControl in placeTransactions, staff actions, immutable audit export
11. Security testingIn progressIntegrity / smoke tests on deploy. External pen-test when Owner schedules
12. Security policyDocumented hereThis page + Trust centre + staff practices
05

SAQ-A style scope

Because card entry stays on partner hosted pages when configured that way, UniWeb targets SAQ-A style scope. That is a questionnaire path — complete only after Owner engages assessment / scans as required. Until then: no badge on the homepage.

06

Partner gateways

Card rails (Razorpay, Cashfree, PayU, banks) maintain their own PCI and network certifications. Ask partners for current AOC / attestation when a deal diligence requires it — UniWeb does not invent or re-badge their Level 1 status as our own.

07

Encryption

  • At rest: Sensitive fields (API keys, gateway credentials) encrypted
  • In transit: TLS for site and API traffic
  • Hashing: Passwords with modern password hashing
  • Key management: Encryption keys in live config — never in the public git repo
08

Incident response

In case of a suspected security incident:

  1. Isolate affected systems
  2. Notify affected merchants within applicable legal timelines
  3. Escalate to partners / regulators only as required by contract and law
  4. Post-incident review and remediation
  5. Record in the incident / status process
09

Roadmap (Owner-gated)

  • External penetration testing when Owner schedules
  • QSA / formal SAQ only when commercial diligence requires it
  • Quarterly vulnerability scans when contracted
  • Staff security awareness refresh
  • Partner AOC collection on a named deal checklist

Company and grievance contact

Uniweb Technologist PVT LTD
CIN: U46522UT2024PTC018164 · GST: 05AADCU6903A1ZT
356 NH344, Village Saliyar Salhapu, Rudrapur, Haridwar, Uttarakhand 247667, India

support@uniweb.co.in · +919837456654 · Registered office map