Our approach
UniWeb aims for SAQ-A style scope (lowest burden) because we do not touch raw card data when partners host card entry. This is a readiness path — not a completed independent assessment badge.
What we do NOT store
- Primary Account Number (PAN) — full card numbers
- Card verification values — CVV, CVC, CID
- PINs or PIN blocks
- Track data from magnetic stripes
- Sensitive authentication data of any kind
What we DO store
- Last 4 digits of card number (for display only, when the partner returns them)
- Card brand (Visa, Mastercard, RuPay, etc.)
- Card expiry month/year (for display only, when returned)
- Gateway transaction reference / order ID
- Tokenized references from gateways (if the customer opts for saved cards with the partner)
12 PCI-DSS Requirements — Readiness map
Statuses below are internal readiness notes for questionnaires — not a QSA attestation. Never treat green rows as “PCI Level 1 certified”.
| Requirement | Status | How |
|---|---|---|
| 1. Firewall config | Delegated | Hosting provider (Hostinger) manages network firewalls |
| 2. Default passwords | Control in place | Unique app/DB secrets; never commit live keys |
| 3. Stored cardholder data | Out of scope (design) | No PAN/CVV on UniWeb. Only last 4 / brand when partner returns them |
| 4. Encrypt transmission | Control in place | TLS via Hostinger. API and dashboard over HTTPS |
| 5. Anti-virus | Delegated | Hosting provider manages server-side AV |
| 6. Secure development | Control in place | PDO prepared statements, CSRF, input validation |
| 7. Restrict access | Control in place | Merchant / staff roles; partner keys not on Support nav |
| 8. Unique IDs | Control in place | Unique accounts; staff 2FA available; session tracking |
| 9. Physical access | Delegated | Cloud-hosted; provider physical controls |
| 10. Track & monitor | Control in place | Transactions, staff actions, immutable audit export |
| 11. Security testing | In progress | Integrity / smoke tests on deploy. External pen-test when Owner schedules |
| 12. Security policy | Documented here | This page + Trust centre + staff practices |
SAQ-A style scope
Because card entry stays on partner hosted pages when configured that way, UniWeb targets SAQ-A style scope. That is a questionnaire path — complete only after Owner engages assessment / scans as required. Until then: no badge on the homepage.
Partner gateways
Card rails (Razorpay, Cashfree, PayU, banks) maintain their own PCI and network certifications. Ask partners for current AOC / attestation when a deal diligence requires it — UniWeb does not invent or re-badge their Level 1 status as our own.
Encryption
- At rest: Sensitive fields (API keys, gateway credentials) encrypted
- In transit: TLS for site and API traffic
- Hashing: Passwords with modern password hashing
- Key management: Encryption keys in live config — never in the public git repo
Incident response
In case of a suspected security incident:
- Isolate affected systems
- Notify affected merchants within applicable legal timelines
- Escalate to partners / regulators only as required by contract and law
- Post-incident review and remediation
- Record in the incident / status process
Roadmap (Owner-gated)
- External penetration testing when Owner schedules
- QSA / formal SAQ only when commercial diligence requires it
- Quarterly vulnerability scans when contracted
- Staff security awareness refresh
- Partner AOC collection on a named deal checklist
Company and grievance contact
Uniweb Technologist PVT LTD
CIN: U46522UT2024PTC018164 · GST: 05AADCU6903A1ZT
356 NH344, Village Saliyar Salhapu, Rudrapur, Haridwar, Uttarakhand 247667, India
support@uniweb.co.in · +919837456654 · Registered office map