Do you handle PCI-DSS for checkout and subscription billing?
Not as a live module in the gate, and we say so rather than claim a checklist that does not exist. What we do in a build: route cardholder data through a PCI DSS-certified, tokenized payment processor so card numbers never reach your servers or ours. That is how a PCI-DSS scope is kept small. It is a design commitment we make as a service, not a gate module, and your own attestation process stays yours. PCI DSS 4.0's future-dated requirements have been mandatory since 2025-03-31.