Payment Security and PCI Compliance
HAHA VENDING consistently maintains cardholder data security as a core compliance priority. Our digital systems and integrated smart vending machine architectures are engineered, deployed, and managed to adhere to the Payment Card Industry Data Security Standard (PCI-DSS) and applicable hardware security specifications, helping support payment security across the data lifecycle.
1. Hardware Terminal Layer: PCI PTS POI 6 Physical Security Certification
The physical payment hardware modules integrated within our smart vending systems have successfully completed formal testing and received official approval from the PCI Security Standards Council (PCI SSC), addressing sensitive data interception risks at the physical and firmware layers.
- Official identification: The endpoint payment hardware terminals integrated into our systems, including the PAX IM30 series, are officially certified to meet PCI Device Security Requirements POI 6 (PCI SSC PTS Approval Number: 4-40372).
- Encryption mechanisms: The hardware terminals natively support online and offline PIN entry via touch screen and leverage advanced key management mechanisms, including TDES and AES cryptographic algorithms under DUKPT and MK/SK architectures, to help secure data at the immediate point of card interaction.
- SRED technology implementation: The terminal fully implements Secure Reading and Exchange of Data (SRED) functions. Sensitive cardholder account data is encrypted immediately upon being read at the hardware layer and is not transmitted out of the hardware boundary in clear text.
2. Clearing Layer: PCI DSS v4.0.1 Level 1 Platform Compliance
The routing, authorization verification, and clearing processes of transactions are independently managed within the closed loops of globally certified Level 1 Service Providers, supporting the compliance of the Cardholder Data Environment (CDE).
- Adyen platform compliance: Our core acquiring and checkout systems interface with Adyen N.V., including Checkout, Acquirer Module, and In Person Payment platform components. The platform has undergone a comprehensive onsite assessment by Qualified Security Assessor Foregenix Ltd (QSA 202-957), securing a COMPLIANT status under PCI DSS v4.0.1.
- Universal Processing compliance: Our payment infrastructure and refund support systems leverage UNIVERSAL PROCESSING. The platform has successfully completed an onsite compliance validation audit resulting in a Report on Compliance (ROC) conducted by atsec (Beijing) Information Technology Co., Ltd (QSA 205-668), maintaining its compliant status under PCI DSS v4.0.1.
- Nayax IoT compliance: Our IoT transaction fulfillment channels interface with Nayax Ltd., which holds an official PCI DSS v4.0.1 Service Provider Level 1 ROC certificate of compliance issued by Qualified Security Assessor Yossi Trigger (QSA 206-357).
3. Data Lifecycle and Omni-Channel Masking Matrix
In accordance with the compliance conclusions of our partners’ official Reports on Compliance (ROC), our platform enforces a strict zero-local-retention approach for sensitive cardholder data and applies mandatory masking across relevant channels.
(1)Clear PAN
完整银行卡号(Clear PAN)
- Third-party processors: Collected, transmitted, and cleared independently by third-party payment processors acting as independent controllers.
- HAHA VENDING systems: Isolated from HAHA VENDING systems; not accessed or retained by our systems, servers, or local media.
- Storage and PCI scope status: No clear-text record is maintained in local or cloud persistent databases.
(2)CVV/CVC and PIN Codes
CVV/CVC 与 PIN 码
- Third-party processors: Dynamically captured and securely routed by third-party payment processors for authorization.
- HAHA VENDING systems: Not read by HAHA VENDING software or hardware systems.
- Storage and PCI scope status: Destroyed from memory after authorization and not retained.
(3)Truncated PAN
已截断/脱敏卡号(Truncated PAN)
- Third-party processors: Masked segments may be transmitted for order fulfillment and reconciliation.
- HAHA VENDING systems: Used only for fulfillment purposes, such as refund support and inquiries.
- Storage and PCI scope status: Processed in volatile memory during active browser sessions.
(4)Transaction Metadata and Expiration Date
交易元数据与到期日
- Third-party processors: Transmitted as encrypted metadata as part of reconciliation evidence.
- HAHA VENDING systems: Recorded and stored as encrypted logs for historical account review.
- Storage and PCI scope status: Managed under controlled encrypted storage with intranet segregation and primary-backup redundancy.
4. Network Transmission and Physical Boundary Security
Our infrastructure and communication links implement compliance-aligned network-layer safeguards to help protect the integrity of the cardholder data environment.
- Protocol decommissioning: Our digital infrastructure has decommissioned and disabled insecure legacy network protocols, including SSL, early TLS 1.0, and TLS 1.1.
- Mandatory strong cryptography: Network traffic communicating into or out of our environment over public networks is established through secure HTTPS channels using strong cryptography, including TLS 1.2 or higher, integrated with Cloudflare perimeter protections.
- Intranet segregation: Core production databases are restricted to internal network access and do not open public network ports. Production and testing environments are isolated via network segments, with wireless networks disabled within the scoped environment.
- Physical media protection: Physical storage media retaining operational metadata is subject to physical access controls. Persistent and backup media are housed within monitored and restricted secure physical cages inside cloud datacenters.
5. Continuous Security Testing and Organizational Governance
Our platform has integrated internal security auditing, vulnerability management, and organizational governance into a sustainable operational mechanism.
- Operations auditing: Manual execution of SQL statements by internal operations staff must be conducted through the auditing function built into our data management tools, supporting real-time tracking and helping prevent unauthorized privilege escalation.
- Regular penetration testing: Our core clearing and fulfillment ecosystem undergoes regular external penetration testing and vulnerability scanning conducted by professional QSAs, with the latest comprehensive assessment concluded in December 2025.
- Governance and incident response: A dedicated internal Network and Data Compliance Leading Group coordinates cybersecurity and data safety compliance across the platform. We maintain a cybersecurity incident emergency response plan. In the event of an incident compromising system security, remediation will be activated, and affected users or merchants will be notified within statutory timelines through appropriate channels, such as email or system alerts.