Who we serve

For online stores where the checkout is the target.

Card skimming moved from the till to the browser years ago. PCI DSS v4.0.1 caught up: since 31 March 2025, merchants must inventory and authorise every script on their payment pages and detect when they change. We test the store, and get you ready to prove it.

What we usually find

Where stores lose money and card data.

01 Payment-page scripts Tag managers, analytics and chat widgets loading on the checkout with no inventory, integrity check or change detection.
02 Discount and gift-card logic Coupons that stack, apply after tax, or can be redeemed twice in parallel requests.
03 Account takeover Login and password-reset flows with no rate limiting, open to credential stuffing at scale.
04 Plugins and extensions Store platforms extended by dozens of third-party components, each with its own update cycle.
Frameworks this sector answers to

PCI DSS v4.0.1 (including requirements 6.4.3 and 11.6.1), the OWASP Top 10 and the CIS Controls v8.1.

Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.

Is your checkout ready for PCI DSS v4.0.1?

Tell us what you ship and who is asking for proof. We will come back with a scope and a range.