PCI-DSS & Payment Security
We never store raw card numbers. Ever.
The PCI-DSS standard protects cardholder data: any system that transmits, processes, or stores credit card information must comply. InWork Global takes the highest-leverage path to compliance — tokenization first. Card data never touches our servers or code; it goes directly to Stripe.

InWork's approach
Tokenization first — minimal scope by design.
The Payment Card Industry Data Security Standard protects cardholder data. Any system that transmits, processes, or stores credit card information must comply. The most reliable way to comply is to never touch that data in the first place.
For all payment implementations, InWork uses Stripe — a PCI-DSS Level 1 certified payment processor. Card data never touches InWork's servers or code; it goes directly to Stripe's infrastructure via Stripe.js or Elements. As a result, InWork client systems operate at PCI SAQ A level — the minimal scope.
What this means
The compliance consequences of tokenization.
By keeping card data off InWork-built infrastructure, the scope of what we must secure shrinks dramatically.
PCI SAQ A scope
InWork client systems operate at PCI SAQ A level — the minimal self-assessment scope — because no card data is stored, transmitted, or processed on InWork-built infrastructure.
Stripe handles the hard parts
Stripe handles encryption, storage, and transmission of cardholder data, and provides the PCI DSS compliance certification as a Level 1 certified processor.
Direct-to-Stripe capture
Card data is captured client-side via Stripe.js or Elements and sent directly to Stripe's infrastructure — it never touches InWork's servers or code.
Fraud-prevention data only
We store only what's needed for display and fraud prevention: the Stripe Customer ID token, the last 4 digits, the card brand, and the billing address.
Data handling
What we store — and what we never do.
The line between a tokenized reference and raw cardholder data is the entire compliance posture.
Payment data we never store
The data that never lands on our infrastructure.
SAQ A
Tokenized payment handling on Stripe
InWork does not store raw credit card numbers. By routing all card capture directly to Stripe — a PCI-DSS Level 1 certified processor — client systems stay at PCI SAQ A level, the minimal cardholder-data scope.
