Skip to main content

What is PCI Compliance in AXP?

Understand PCI DSS compliance in AXP, security requirements for handling payment card data, and best practices.

Updated yesterday

Summary: PCI DSS (Payment Card Industry Data Security Standard) compliance in AXP (Alliants Experience Platform) means that all payment card data is handled according to industry security standards. AXP uses tokenisation, encryption, and secure payment gateways to protect cardholder data. Staff never see or store full card numbers.

Permissions Required: Roles required in AXP to view this information are IT Administrators, Finance Directors, Compliance Officers.

PCI compliance is essential for any system that handles payment cards. AXP is designed to minimise your PCI scope by handling card data securely through certified payment gateways.

How AXP Protects Payment Data

Tokenisation

When a guest's card is captured, the actual card number is replaced with a secure token. AXP only stores the token, not the full card number.

Encryption

All payment data in transit is encrypted using TLS. Data at rest is protected with industry-standard encryption.

Secure Payment Pages

Pay-by-link and card capture use hosted payment pages from the payment provider, meaning card details are entered directly on the gateway's secure page, never in AXP itself.

Staff Responsibilities

While AXP handles the technical security, staff should never write down or verbally share card numbers, never take photos of payment cards, only use AXP's built-in payment features (not manual entry), and report any suspected security incidents immediately.

Did this answer your question?