Payment security & compliance

PCI DSS payment-page security & scanning.

Card data is increasingly stolen right in the customer's browser, through tampered scripts on the payment page — e-skimming. PollySec watches your payment page and your public surface, and gives you both the protection and the evidence for PCI DSS v4.0.1 — including the new e-commerce requirements 6.4.3 and 11.6.1.

What you get for PCI DSS

PCI DSS v4.0.1 raised the bar for e-commerce with two new, mandatory requirements — payment-page script control (6.4.3) and tamper detection (11.6.1). PollySec delivers 6.4.3 today — payment-page script inventory and integrity checks — with 11.6.1 tamper monitoring on the roadmap, alongside the surrounding vulnerability, encryption and exposure requirements.

6.4.3

Payment-page discovery

Finds the payment page — and the page that embeds the payment iframe — where e-skimming (Magecart) attacks actually happen.

6.4.3

Script inventory in a real browser

Inventories every script and third-party origin loaded in the customer's browser — the foundation for knowing exactly what runs on your checkout.

6.4.3

Integrity & security-header checks

Verifies script integrity (SRI) and evaluates Content-Security-Policy, HSTS, X-Frame-Options and more — as the browser actually receives them.

11.6.1 · roadmap

Tamper & change monitoring (on the roadmap)

Baseline-vs-current comparison of payment-page scripts and security headers, alerting when something is added, changed or removed — the continuous 11.6.1 control we are building next.

6.4.3

Script authorization & inventory export

Approve each script with a business or technical justification, and export a complete script inventory as audit evidence.

11.3.2.1 · 6.3.1

External vulnerability scanning

Finds vulnerabilities, known CVEs and exposed services across your public surface; runs on schedule and after a significant change.

4.2.1

Encryption & certificates

Checks TLS strength, certificate validity and that weak or outdated protocols are not in use.

6.3.3

End-of-life software detection

Surfaces components and versions past vendor security support that no longer receive fixes.

11.3.1 · 11.3.1.2

Internal vulnerability scanning

Scans from inside the network via a local sensor — authenticated and unauthenticated — without data leaving your environment.

The quarterly ASV scan attestation (Requirement 11.3.2) may only be issued by a PCI-accredited Approved Scanning Vendor. PollySec provides this through an accredited ASV partner, while running the continuous monitoring and remediation support around it.

The new e-commerce requirements: 6.4.3 & 11.6.1

Mandatory since March 2025, these requirements target e-skimming — malicious scripts that capture card data in the shopper's browser. They demand that you know, authorize and monitor every script and security header on your payment page.

6.4.3

Authorize, integrity-check and inventory every payment-page script

11.6.1 · roadmap

Detect and alert on unauthorized changes to scripts and security headers, at least weekly — the continuous control we are building next

PCI DSS for Swedish e-commerce

Every Swedish merchant that accepts card payments falls under PCI DSS. PollySec — built by a Swedish company — gives small and mid-sized retailers continuous payment-page protection and the technical evidence to show their work, whether they run in our cloud or fully self-hosted. One platform also carries the NIS2 and ISO 27001 evidence story.

PollySec supports your PCI DSS work with continuous technical monitoring and evidence — it is not an ASV attestation, not a QSA assessment, and not a guarantee of compliance. Your acquiring bank and QSA determine final validation.

Stop e-skimming before it reaches checkout.

Book a 20-minute demo — we'll scan a live payment page with you and show the script inventory and header posture on the spot.