InWork GlobalIntegrity. Urgency. Ownership.

PCI-DSS & Payment Security

We never store raw card numbers. Ever.

The PCI-DSS standard protects cardholder data: any system that transmits, processes, or stores credit card information must comply. InWork Global takes the highest-leverage path to compliance — tokenization first. Card data never touches our servers or code; it goes directly to Stripe.

Tokenization firstStripe PCI-DSS Level 1PCI SAQ A scopeNo card data stored
PCI-DSS tokenized payment architecture

InWork's approach

Tokenization first — minimal scope by design.

The Payment Card Industry Data Security Standard protects cardholder data. Any system that transmits, processes, or stores credit card information must comply. The most reliable way to comply is to never touch that data in the first place.

For all payment implementations, InWork uses Stripe — a PCI-DSS Level 1 certified payment processor. Card data never touches InWork's servers or code; it goes directly to Stripe's infrastructure via Stripe.js or Elements. As a result, InWork client systems operate at PCI SAQ A level — the minimal scope.

What this means

The compliance consequences of tokenization.

By keeping card data off InWork-built infrastructure, the scope of what we must secure shrinks dramatically.

PCI SAQ A scope

InWork client systems operate at PCI SAQ A level — the minimal self-assessment scope — because no card data is stored, transmitted, or processed on InWork-built infrastructure.

Stripe handles the hard parts

Stripe handles encryption, storage, and transmission of cardholder data, and provides the PCI DSS compliance certification as a Level 1 certified processor.

Direct-to-Stripe capture

Card data is captured client-side via Stripe.js or Elements and sent directly to Stripe's infrastructure — it never touches InWork's servers or code.

Fraud-prevention data only

We store only what's needed for display and fraud prevention: the Stripe Customer ID token, the last 4 digits, the card brand, and the billing address.

Data handling

What we store — and what we never do.

The line between a tokenized reference and raw cardholder data is the entire compliance posture.

Data elementNever storedStored safely
Credit card numberRaw PAN never storedLast 4 digits, display only
Card identityCVV codes never storedCard brand (Visa, Mastercard, etc.)
Cardholder dataFull name + card number, magnetic stripe dataStripe Customer ID (token reference)
BillingCard data with billingBilling address for fraud prevention

Payment data we never store

The data that never lands on our infrastructure.

Credit card numbers
CVV codes
Full cardholder names combined with card numbers
Magnetic stripe data

SAQ A

Tokenized payment handling on Stripe

InWork does not store raw credit card numbers. By routing all card capture directly to Stripe — a PCI-DSS Level 1 certified processor — client systems stay at PCI SAQ A level, the minimal cardholder-data scope.

Compliance by design

Take payments without the PCI burden.

Tokenized handling on Stripe keeps your cardholder-data scope minimal. Tell us about your payment flows and we'll architect the rest.

Integrity. Urgency. Ownership.

Schedule a security reviewRequest a proposal

40+ US businesses served · 65+ engineers · Zero long-term lock-in

Book a Strategy Call