PCI DSS v4.0

Last updated: 2026-04-11 • ← All frameworks

Overview

The Payment Card Industry Data Security Standard (PCI DSS) version 4.0 is the current baseline set of requirements maintained by the PCI Security Standards Council for any organization that stores, processes, or transmits cardholder data, or that can affect the security of the cardholder data environment (CDE). Backbuild customers who accept card payments on top of the platform inherit scoping obligations that this page is intended to clarify.

Current status

Controls aligned — Backbuild is not a CDE

Backbuild does not store, process, or transmit cardholder data. Payment card operations are fully offloaded to Stripe under Stripe's PCI DSS Level 1 Service Provider attestation. As a result, Backbuild's own infrastructure is out of scope for PCI DSS, and customer PCI audits generally need only cover the integration boundary between the customer's application and Stripe.

Scoping Backbuild out of your CDE

To keep cardholder data out of Backbuild infrastructure and minimize your PCI scope, use one of the following Stripe-provided collection methods:

In all supported integration patterns, only opaque payment method tokens, identifiers, and metadata pass through Backbuild. Primary account numbers, expiration dates, and CVV values never traverse Backbuild workers, storage, or databases.

Controls that support customer PCI compliance

While Backbuild itself is not a CDE, the platform implements controls that support customers' own PCI DSS obligations:

Shared responsibility matrix

Requirement areaBackbuildCustomerStripe
Req 1–2: Network and system configurationSharedShared✓ CDE
Req 3: Protect stored cardholder dataN/A (no PAN)N/A (no PAN)
Req 4: Encrypt transmission of cardholder dataN/A (no PAN)Shared
Req 5–6: Vulnerability and secure developmentPlatform controlsApplication controls
Req 7–8: Access control and authenticationPlatform SSO, MFA, RBACUser management
Req 9: Physical securityInherited from CloudflareCustomer facilities
Req 10: Logging and monitoringPlatform audit logsApplication logs
Req 11: Security testingPlatform testingApplication testing
Req 12: Security policy and programBackbuild programCustomer program

Contact

For PCI DSS scoping guidance, SAQ assistance, or shared responsibility documentation: