Payment Security & PCI Compliance

HAHA VENDING consistently maintains cardholder data security as a core compliance priority. Our digital systems and integrated smart vending machine architectures are engineered, deployed, and managed to adhere to the Payment Card Industry Data Security Standard (PCI-DSS) and applicable hardware security specifications, helping support payment security across the data lifecycle.

1. Hardware Terminal Layer: PCI PTS POI 6 Physical Security Certification

The physical payment hardware modules integrated within our smart vending systems have successfully completed formal testing and received official approval from the PCI Security Standards Council (PCI SSC), addressing sensitive data interception risks at the physical and firmware layers.

Official identification:

The endpoint payment hardware terminals integrated into our systems, including the PAX IM30 series, are officially certified to meet PCI Device Security Requirements POI 6 (PCI SSC PTS Approval Number: 4-40372).

Encryption mechanisms:

The hardware terminals natively support online and offline PIN entry via touch screen and leverage advanced key management mechanisms, including TDES and AES cryptographic algorithms under DUKPT and MK/SK architectures, to help secure data at the immediate point of card interaction.

SRED technology implementation:

The terminal fully implements Secure Reading and Exchange of Data (SRED) functions. Sensitive cardholder account data is encrypted immediately upon being read at the hardware layer and is not transmitted out of the hardware boundary in clear text.

2. Clearing Layer: PCI DSS v4.0.1 Level 1 Platform Compliance

The routing, authorization verification, and clearing processes of transactions are independently managed within the closed loops of globally certified Level 1 Service Providers, supporting the compliance of the Cardholder Data Environment (CDE).

Adyen platform compliance:

Our core acquiring and checkout systems interface with Adyen N.V., including Checkout, Acquirer Module, and In Person Payment platform components. The platform has undergone a comprehensive onsite assessment by Qualified Security Assessor Foregenix Ltd (QSA 202-957), securing a COMPLIANT status under PCI DSS v4.0.1.

Universal Processing compliance:

Our payment infrastructure and refund support systems leverage UNIVERSAL PROCESSING. The platform has successfully completed an onsite compliance validation audit resulting in a Report on Compliance (ROC) conducted by atsec (Beijing) Information Technology Co., Ltd (QSA 205-668), maintaining its compliant status under PCI DSS v4.0.1.

Nayax IoT compliance:

Our IoT transaction fulfillment channels interface with Nayax Ltd., which holds an official PCI DSS v4.0.1 Service Provider Level 1 ROC certificate of compliance issued by Qualified Security Assessor Yossi Trigger (QSA 206-357).

3. Data Lifecycle and Omni-Channel Masking Matrix

In accordance with the compliance conclusions of our partners' official Reports on Compliance (ROC), our platform enforces a strict zero-local-retention approach for sensitive cardholder data and applies mandatory masking across relevant channels.

Data CategoryThird-Party ProcessorsHAHA VENDING SystemsStorage & PCI Scope
Clear PANCollected, transmitted, and cleared independently as independent controllers.Isolated; not accessed or retained by our systems or servers.No clear-text record in local or cloud persistent databases.
CVV/CVC & PIN CodesDynamically captured and securely routed for authorization verification.Not read by HAHA VENDING software or hardware.Destroyed from memory immediately after authorization; never retained.
Truncated PANMasked segments may be transmitted for order fulfillment and reconciliation.Used only for fulfillment purposes (e.g. refund support, queries).Processed in volatile memory during active browser sessions.
Metadata & ExpirationTransmitted as encrypted metadata as part of reconciliation evidence.Recorded and stored as encrypted logs for historical merchant review.Managed under controlled encrypted storage with intranet segregation.

4. Network Transmission and Physical Boundary Security

Our infrastructure and communication links implement compliance-aligned network-layer safeguards to help protect the integrity of the cardholder data environment.

  • Protocol decommissioning (No SSL / Early TLS): Our digital infrastructure has decommissioned and disabled insecure legacy network protocols, including SSL, early TLS 1.0, and TLS 1.1.
  • Mandatory strong cryptography (TLS 1.2+): Network traffic communicating into or out of our environment over public networks is established through secure HTTPS channels using strong cryptography, including TLS 1.2 or higher, integrated with Cloudflare perimeter protections.
  • Intranet segregation: Core production databases are restricted to internal network access and do not open public network ports. Production and testing environments are isolated via network segments, with wireless networks disabled within the scoped environment.
  • Physical media protection: Physical storage media retaining operational metadata is subject to physical access controls. Persistent and backup media are housed within monitored and restricted secure physical cages inside cloud datacenters.

5. Continuous Security Testing and Organizational Governance

Our platform has integrated internal security auditing, vulnerability management, and organizational governance into a sustainable operational mechanism.

  • Operations auditing (SQL Auditing): Manual execution of SQL statements by internal operations staff must be conducted through the auditing function built into our data management tools, supporting real-time tracking and helping prevent unauthorized privilege escalation.
  • Regular penetration testing: Our core clearing and fulfillment ecosystem undergoes regular external penetration testing and vulnerability scanning conducted by professional QSAs, with the latest comprehensive assessment concluded in December 2025.
  • Governance and incident response: A dedicated internal Network and Data Compliance Leading Group coordinates cybersecurity and data safety compliance across the platform. We maintain a cybersecurity incident emergency response plan. In the event of an incident compromising system security, remediation will be activated, and affected users or merchants will be notified within statutory timelines through appropriate channels, such as email or system alerts.