From time to time, Stripe will request that you validate your PCI compliance. Although this may sound complex, the good news is that if you are using the newer Donorfy Web Widgets or standard Campaign Pages, the validation process is straightforward.
Why PCI Validation Is Needed
PCI DSS (Payment Card Industry Data Security Standard) requires organisations that handle card details to confirm they meet security standards.
The level of responsibility depends on how card details are processed.
Donorfy’s modern payment tools are designed so that:
You never store, process, or transmit card data on your servers.
Card information is entered in the donor’s browser and sent directly to Stripe, bypassing Donorfy entirely.
This dramatically reduces your PCI scope.
Post-September 2019 Donorfy Payment Tools
All new Donorfy Stripe Web Widgets and standard Campaign Donation Pages created after September 2019:
Are SCA compliant
Use Stripe’s secure payment elements
Never touch your systems or Donorfy’s servers
Fall under the simplest PCI category
Because of this, validating PCI compliance usually involves only completing Stripe’s recommended Self-Assessment Questionnaire (SAQ A).
Stripe’s documentation includes:
A Knowledge Base article on integration security
A link to the relevant SAQ form for your integration type.
Older Web Widgets (Pre-September 2019)
If you are still using the old-style Web Widgets (pre-2019), these:
Use Stripe.js v2
Require SAQ A-EP, a much more complex compliance level
May require support from security specialists to complete
Stripe states:
"If you continue to use Stripe.js v2, you’ll be required to upload your SAQ A-EP annually to prove your business is PCI compliant. As this is more complex, we recommend you work with SecurityMetrics if you require additional assistance in completing your SAQ A-EP. "
Recommendation: Upgrade Your Web Widgets
To simplify PCI compliance and improve security:
This change moves you into SAQ A, which is far easier to complete.
You also gain SCA compliance, required for modern online payments.
Migrating to the new widgets reduces compliance overhead and ensures safer, smoother donation processing.
