Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Retail

Security for the checkout and the till.

F Creative Studio 360 tests and reviews payment flows for retailers in any country, including the page, the scripts and the terminals. The work is authorised. It is not a surprise.

The gateway does not cover the page.

A hosted gateway reduces how much card data you store. The checkout, the third-party scripts on it, and the path to that gateway can still be abused. PCI DSS is the standard those flows are measured against.

Testing is done with written authorisation, on systems you approve. F Creative Studio 360 does not run denial-of-service tests, and we do not file a card-brand report.

Online and in store
The website and the point-of-sale estate can be one engagement or two. You choose.
Scripts are in the flow
A script you did not write can still read the page the customer is on.
Terminals are endpoints
A till that can be altered is a payment system, not just a shop fitting.
Monitoring is separate
Watching tills day to day is a monitoring engagement, not this review, unless it is written in.

What can be tested

Only the flows and stores you list.

Checkout
The payment steps, the APIs behind them, and the errors they return.
Third-party code
Scripts and tags loaded on the payment page.
Terminals
How the estate is built, updated and reached.
Scope for PCI
What the test says about data you still touch.

How an engagement runs

Shops can be anywhere. Production testing needs a written window.

  1. 1

    Draw the payment flow

    Gateway, page, terminal and who operates each.

  2. 2

    Agree the environment

    A test checkout where possible. Production only with authorisation.

  3. 3

    Test what was agreed

    Stop if the condition you set is met.

  4. 4

    Hand back the fixes

    In an order that shrinks card-data scope where that is possible.

What you receive

  • Findings on the flows in scope.
  • A note of third-party scripts on the payment page.
  • What the result means for PCI scope.
  • No card-brand filing, and no attestation.

The standard sits next door

If you need the gap list against PCI DSS rather than a test of the checkout, use the PCI page. They can be scoped together.

Common questions

Our gateway is compliant. Are we done?+

The gateway’s compliance does not cover your page, your scripts or your terminals. Those stay in the review when they are part of the flow.

Will you test live stores without warning?+

No. Time, systems and a stop condition are agreed first.

Where do you deliver this?+

For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.

How much does it cost, and how long does it take?+

It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Name the flow a card actually takes.

F Creative Studio 360 will look at the checkout and the tills, then say what can be tested safely.