Skip to content

Latest commit

 

History

History
7 lines (6 loc) · 592 Bytes

bonus.md

File metadata and controls

7 lines (6 loc) · 592 Bytes
How would you handle security for saving credit cards?
  1. I'd strongly encourage not to store credit card details in our own servers unless we really really need.
  2. Instead, use payment gateway's vault option to create and store credit cards and to use them with API calls
  3. If it's really necessary to store it in own servers
  • Use SSL and HSTS for transport, which ensures the server interacts with client securely
  • Encryption, server should provide strong encryption mechanism like AES-256 for encrypting and storing card numbers, and a way to securely store decription keys