Payment Security and PCI Questions

Questions about PCI scope for a business whose AR team handles card numbers, tokenization, and keeping card data out of the ERP and out of email.

PCI scope for B2B sellers, tokenization, and keeping card data out of your ERP and out of email.

What this category covers

This category covers PCI scope for a business whose AR team handles card numbers, tokenization, and keeping card data out of the ERP and out of email. The answers are written to give you the structure of the decision - what has to be true, who decides it, and what to get in writing - rather than a single number that stops being accurate the moment your volume or card mix changes.

Where an answer depends on your own account, it says so and points at the statement line that would tell you. A page cannot know your effective rate, and any page that claims to is guessing.

Why it matters operationally

Card numbers on paper order forms and in email inboxes are the most common and most avoidable exposure in B2B.

The cost of getting this wrong is rarely dramatic. It is a few basis points on every transaction, every month, which is exactly why it goes unexamined for years.

Where operators go wrong

  • Card numbers emailed to AR and left in a mailbox indefinitely.
  • Assuming PCI scope is the processor's problem rather than a shared one.

0 questions in this category

    This category is still being built out. We keep it linked from the questions hub, but hold it back from search listings until it carries at least 3 published answers — a page with nothing to list is not worth anybody's click.

    What to read next

    /b2b-payment-processing covers tokenization and keeping card data out of your systems.

    Related reading on this topic

    The guides, analysis, state references and tools on this site that deal with the same subject as the questions above.