skybook-global-logo-2
Home › Case Studies › NUDAX PCI DSS Compliance
Case Study · PCI DSS SAQ D Compliance

How NUDAX Achieved PCI DSS SAQ D Compliance for a Travel Card-Data Platform

Skybook Global led NUDAX through the complete PCI DSS SAQ D journey as a service provider — scoping the cardholder data environment, closing control gaps, coordinating External VAPT and ASV scanning, and securing the final Attestation of Compliance (AOC).

Talk to a Specialist
ClientNUDAX Data Exchange (SaaS)
IndustryTravel Technology
StandardPCI DSS SAQ D — Service Provider
HostingMicrosoft Azure (UAE) + DR (Frankfurt)
12
PCI DSS requirements assessed under SAQ D
4
Phases: Scoping, Gap Assessment, Remediation, Certification
A+
SSL/TLS rating on the public application hostname
AOC
Attestation of Compliance with compliant ASV and VAPT reports
01 · Client Overview

A travel data-exchange platform that stores cardholder data

NUDAX Data Exchange is a Software-as-a-Service platform built by a travel technology company to consolidate travel transaction data for card issuers and corporate programmes.

NUDAX ingests transaction records from GDS ticketing files (AIR, IUR and MIR), travel accounting back-office systems, and manual or CSV uploads. It consolidates them into card-specification handout files, which are uploaded securely to client SFTP folders or made available for client-side download.

Incoming data carries masked card numbers (first six and last four digits). To meet Mastercard issuer requirements, however, the platform stores the full PAN in encrypted form. NUDAX does not authorise, settle or acquire payments, but because it stores and transmits cardholder data, it falls fully within PCI DSS.

Why SAQ D?

SAQ D is the most comprehensive PCI DSS Self-Assessment Questionnaire. It is the route for service providers that don't qualify for a narrower SAQ, and it covers all 12 PCI DSS requirements, from network security and encryption to access control, logging, testing and security policy.

For a platform that stores PANs on behalf of travel businesses and card issuers, a valid SAQ D Attestation of Compliance is the evidence that partners, issuers and enterprise buyers expect before they integrate.

02 · Business Challenge

Cloud-native architecture, stored PANs and a strict standard

1

Defining the cardholder data environment

Microservices on Azure Kubernetes Service, PostgreSQL databases and a separate disaster-recovery site all had to be mapped precisely. Only the segments that store, process or transmit card data should come into scope.

2

Shared-responsibility clarity

Microsoft Azure is a PCI DSS-compliant hosting provider. The application layer, Kubernetes configuration, database management and security controls, however, were the platform team's responsibility and needed evidence.

3

External scanning findings

An infrastructure move changed the platform's public endpoints mid-engagement. The first ASV scan then flagged a default Kubernetes ingress certificate, which would block compliance unless resolved.

03 · Scope & Compliance Requirements

What was brought into the PCI DSS scope

1 · IngestAIR / IUR / MIR files, back-office feeds, CSV uploads
2 · ProtectMasked PAN received; full PAN encrypted at rest
3 · ConsolidateHandout files built to card specifications
4 · TransmitSecure SFTP delivery or client-side download
5 · RecoverEncrypted daily database replicas at the DR site
Scope ElementDetailResponsibility
Primary environmentAzure AKS cluster (UAE region) running SaaS microservices and PostgreSQL databasesPlatform team (application, cluster, DB) · Azure (infrastructure)
DR environmentDedicated BCDR server in Frankfurt holding encrypted daily replicas of tenant databasesPlatform team
Cardholder dataEncrypted full PAN storage and card-linked invoice/transaction recordsPlatform team
Out of scopePayment authorisation, settlement, acquiring and chargebacks (not performed)
Technical testingExternal VAPT and PCI SSC ASV scan of internet-facing componentsIndependent ASV, coordinated by Skybook Global
04 · Skybook Global's Role

End-to-end PCI DSS programme management

Skybook Global acted as the single accountable compliance partner between the platform's engineering team and the independent PCI assessors. We kept the scope accurate, turned control gaps into engineering actions, and drove every workstream through to attestation.

  • Cardholder data environment scoping and data-flow documentation
  • Gap assessment coordination across all 12 PCI DSS requirements
  • Remediation tracking with owners, priorities and weekly follow-ups
  • Shared-responsibility mapping between Azure and the platform team
  • External VAPT and ASV scan coordination, including scope re-baselining
  • Joint technical troubleshooting between engineers and assessors
  • SPOC, SAQ D and AOC documentation management

Resolving the ASV certificate finding

The flagged public IP belonged to a Kubernetes Ingress load balancer that only serves traffic when a request carries the correct hostname (SNI). When a scanner connects to the bare IP, Kubernetes returns its default self-signed certificate. This is expected behaviour, and real users never see it.

Real users reach NUDAX through its fully qualified domain name, protected by a publicly trusted CA-signed wildcard certificate: A+ rating, TLS 1.2/1.3 only, weak ciphers disabled, HSTS enabled. Skybook Global set up a joint session with the ASV, and the scan target was aligned to the public hostname, an approach PCI ASV guidance permits. The rescan returned compliant.

05 · Step-by-Step Process

From scoping to Attestation of Compliance

Phase 0 · Scoping

Scope, governance and project plan

The team mobilised and project governance was set up. The cardholder data environment was defined: the AKS cluster, PostgreSQL databases and DR server. Out-of-scope functions and Azure's responsibilities were documented, and requests for information and access requirements were issued.

Phase 1 · Gap Assessment

Control-by-control review against SAQ D

Stakeholder interviews and walkthroughs of processes, technology and application controls were mapped to all 12 PCI DSS requirements. Findings were captured in an observation tracker and gap report with a prioritised roadmap.

Phase 2 · Gap Remediation

Closing the gaps

Each gap was assigned to an owner and tracked through status meetings and stakeholder follow-ups. The work covered encryption and key handling for stored PANs, access control, logging and monitoring, secure configuration, and information security policies.

Phase 2 · Technical Testing

External VAPT

External penetration testing was run on the platform's internet-facing endpoints after the scope was updated for the new infrastructure. A compliant External Network VAPT report was issued.

Phase 2 · Technical Testing

ASV scanning, remediation and rescan

The initial ASV scan flagged the default ingress certificate. Skybook Global coordinated validation of the certificate chain and a joint session with the ASV. A hostname-based rescan then returned a compliant result.

Phase 3 · Final Certification

SAQ D and Attestation of Compliance

Once all open observations were closed, the SAQ D was completed and SPOC details were submitted. The Attestation of Compliance was issued with the ASV Detailed, Executive and Attestation reports.

06 · Outcome

PCI DSS SAQ D compliant, with evidence at every layer

CheckpointBeforeAfter
Cardholder data environmentNot formally definedDocumented scope, data flows and responsibilities
PCI DSS control postureUnassessed against SAQ DGaps identified, remediated and closed
External VAPTNot assessedCompliant report issued
ASV scanNon-compliant (default ingress certificate)Compliant
Certificate & TLSUnverified by third partyTrusted CA wildcard · A+ · TLS 1.2/1.3 · HSTS
AttestationNonePCI DSS SAQ D Attestation of Compliance
PCI DSS SAQ D & AOCFormal service-provider compliance attestation
Gap Report & Observation TrackerDocumented closure of every finding
External Network VAPT ReportIndependent penetration-test evidence
ASV ReportsDetailed, Executive Summary and Attestation
07 · Business Impact

A card-data platform travel partners can trust

Issuer and partner confidence

NUDAX can show card issuers, travel management companies and agencies a current PCI DSS AOC instead of relying on self-declarations.

Faster enterprise security reviews

Ready-made evidence (AOC, VAPT and ASV reports) shortens vendor due diligence in sales and onboarding cycles.

Stronger protection of stored PANs

Encryption, access control and monitoring for cardholder data are now formally assessed, documented and maintained.

Repeatable compliance baseline

With documented scope, data flows and SPOC details, future ASV scans and annual re-attestation can run without re-scoping.

IP addresses, environment hostnames and internal system details are withheld from this case study for security reasons.

Does your travel platform store or transmit card data?

Skybook Global manages PCI DSS compliance for travel technology providers, agencies and OTAs, from scoping and gap remediation to VAPT, ASV scanning and the final Attestation of Compliance.

PCI DSS SAQ DGap AssessmentRemediation ManagementExternal VAPTASV ScanningCloud & Kubernetes Security
info@skybookglobal.com
This website uses cookies to improve your web experience.