Live data from Hacker News

Spreedly Core, PCI-DSS, Gateway Autonomy and commerce. A Guest Post on our blog

blog.spreedly.com

1–10 of 13 posts

Re: Spreedly Core, PCI-DSS, Gateway Autonomy and commerce. A Guest Post on our blog

#7

What specific parts of PCI-DSS do they cover?

Spreedly Core isn't for handling specific requirements per se, but changing the entire scope of compliance. Basically, if you're only only doing card-not-present transactions and you never store, process or transmit cardholder data, you qualify for SAQ A. The full eligibility requirements for SAQ A consists of the following:

  * Your company handles only card-not-present (e-commerce or mail/telephone-order) transactions;
  * Your company does not store, process, or transmit any cardholder data on your systems or premises, but relies entirely on third party service provider(s) to handle all these functions;
  * Your company has confirmed that the third party(s) handling storage, processing, and/or transmission of cardholder data is PCI DSS compliant;
  * Your company retains only paper reports or receipts with cardholder data, and these documents are not received electronically; and
  * Your company does not store any cardholder data in electronic format.

Re: Spreedly Core, PCI-DSS, Gateway Autonomy and commerce. A Guest Post on our blog

#8
My first reaction after going to the parent website (http://spreedly.com/) was that I don't understand what spreedly does exactly or why I would use it (vs. my paypal or 2CO account).

I'm guessing that Spreedly offers an API/front-end that 1) stores the credit card info for immediate (and future) billing + subscription purposes, then 2) sends the transaction to my paypal, and 3) offers some type of a billing/subscription panel I can use to manage everything.

The money stays in my paypal, and spreedly then bills my own CC for the use of the service.

I see the usefulness of the independent API and control panel, but...

Is that data (customer CC info) really transferable from spreedly to let's say more than 1 other provider right now (like Braintree)?

Re: Spreedly Core, PCI-DSS, Gateway Autonomy and commerce. A Guest Post on our blog

#9
post #2

Cool article. Need screenshots :-)

Agreed, except... we actually don't have a UI to show. The transparent redirect approach that Core takes means that we'd just be showing you our customers' payment pages, which while spiffy, don't really tell you anything about the integration. Which is kind of the point - our goal is to be invisible.

Re: Spreedly Core, PCI-DSS, Gateway Autonomy and commerce. A Guest Post on our blog

#10

My first reaction after going to the parent website ( http://spreedly.com/ ) was that I don't understand what spreedly does exactly or why I would use it (vs. my paypal or 2CO account). I'm guessing that Spreedly offers an API/front-end that 1) stores the credit card info for immediate (and future) billing + subscription purposes, then 2) sends the transaction to my paypal, and 3) offers some type of a billing/subscr…

I know the spreedly guys, as well as outside devs who independently adopted spreedly. Everyone I know has said what a pleasure it has been to use the Spreedly API.

If you want a feature list, you can always go hit their site: http://spreedly.com/info/features

Post reply on HN