How to make PCI App Engine compatible with Google?

I read several articles that say to have a PCI compatible cloud solution, you need to have a private cloud environment and not use the Google engine. Is it possible to create a PCI-compatible website that specifically stores credit card information and personal information in a Google engine application. Please list actual, non-esoteric reasons why this may not be possible or a list of high-level task directives that should have been implemented by the application engine developer and could be completed.

+5
source share
3 answers

"No matter what you do, your hosting provider should require support for PCI compliance." ... per @maple_shaft

+1
source

Performing PCI compatibility alone is very difficult. Details are available here .

The most common payment pattern in App Engine is to use a payment gateway that is responsible for PCI compliance.

Typically, these services provide you with an authorization token to correlate with users, which you can use to create payments.

Popular Python Gateways

Here are some links to payment gateways to get you started.

  • Braintree , I used this in the process of creating the application and it works great
  • Stripe, , .
+1

It might be interesting to know that the Google Cloud Platform has recently become a PCI DSS certificate . Since the Google App Engine builds on it , I assume that it should be “safe” to use it.

+1
source