Skybook Global led NUDAX through the complete PCI DSS SAQ D journey as a service provider — scoping the cardholder data environment, closing control gaps, coordinating External VAPT and ASV scanning, and securing the final Attestation of Compliance (AOC).
Talk to a SpecialistNUDAX Data Exchange is a Software-as-a-Service platform built by a travel technology company to consolidate travel transaction data for card issuers and corporate programmes.
NUDAX ingests transaction records from GDS ticketing files (AIR, IUR and MIR), travel accounting back-office systems, and manual or CSV uploads. It consolidates them into card-specification handout files, which are uploaded securely to client SFTP folders or made available for client-side download.
Incoming data carries masked card numbers (first six and last four digits). To meet Mastercard issuer requirements, however, the platform stores the full PAN in encrypted form. NUDAX does not authorise, settle or acquire payments, but because it stores and transmits cardholder data, it falls fully within PCI DSS.
SAQ D is the most comprehensive PCI DSS Self-Assessment Questionnaire. It is the route for service providers that don't qualify for a narrower SAQ, and it covers all 12 PCI DSS requirements, from network security and encryption to access control, logging, testing and security policy.
For a platform that stores PANs on behalf of travel businesses and card issuers, a valid SAQ D Attestation of Compliance is the evidence that partners, issuers and enterprise buyers expect before they integrate.
Microservices on Azure Kubernetes Service, PostgreSQL databases and a separate disaster-recovery site all had to be mapped precisely. Only the segments that store, process or transmit card data should come into scope.
Microsoft Azure is a PCI DSS-compliant hosting provider. The application layer, Kubernetes configuration, database management and security controls, however, were the platform team's responsibility and needed evidence.
An infrastructure move changed the platform's public endpoints mid-engagement. The first ASV scan then flagged a default Kubernetes ingress certificate, which would block compliance unless resolved.
| Scope Element | Detail | Responsibility |
|---|---|---|
| Primary environment | Azure AKS cluster (UAE region) running SaaS microservices and PostgreSQL databases | Platform team (application, cluster, DB) · Azure (infrastructure) |
| DR environment | Dedicated BCDR server in Frankfurt holding encrypted daily replicas of tenant databases | Platform team |
| Cardholder data | Encrypted full PAN storage and card-linked invoice/transaction records | Platform team |
| Out of scope | Payment authorisation, settlement, acquiring and chargebacks (not performed) | — |
| Technical testing | External VAPT and PCI SSC ASV scan of internet-facing components | Independent ASV, coordinated by Skybook Global |
Skybook Global acted as the single accountable compliance partner between the platform's engineering team and the independent PCI assessors. We kept the scope accurate, turned control gaps into engineering actions, and drove every workstream through to attestation.
The flagged public IP belonged to a Kubernetes Ingress load balancer that only serves traffic when a request carries the correct hostname (SNI). When a scanner connects to the bare IP, Kubernetes returns its default self-signed certificate. This is expected behaviour, and real users never see it.
Real users reach NUDAX through its fully qualified domain name, protected by a publicly trusted CA-signed wildcard certificate: A+ rating, TLS 1.2/1.3 only, weak ciphers disabled, HSTS enabled. Skybook Global set up a joint session with the ASV, and the scan target was aligned to the public hostname, an approach PCI ASV guidance permits. The rescan returned compliant.
The team mobilised and project governance was set up. The cardholder data environment was defined: the AKS cluster, PostgreSQL databases and DR server. Out-of-scope functions and Azure's responsibilities were documented, and requests for information and access requirements were issued.
Stakeholder interviews and walkthroughs of processes, technology and application controls were mapped to all 12 PCI DSS requirements. Findings were captured in an observation tracker and gap report with a prioritised roadmap.
Each gap was assigned to an owner and tracked through status meetings and stakeholder follow-ups. The work covered encryption and key handling for stored PANs, access control, logging and monitoring, secure configuration, and information security policies.
External penetration testing was run on the platform's internet-facing endpoints after the scope was updated for the new infrastructure. A compliant External Network VAPT report was issued.
The initial ASV scan flagged the default ingress certificate. Skybook Global coordinated validation of the certificate chain and a joint session with the ASV. A hostname-based rescan then returned a compliant result.
Once all open observations were closed, the SAQ D was completed and SPOC details were submitted. The Attestation of Compliance was issued with the ASV Detailed, Executive and Attestation reports.
| Checkpoint | Before | After |
|---|---|---|
| Cardholder data environment | Not formally defined | Documented scope, data flows and responsibilities |
| PCI DSS control posture | Unassessed against SAQ D | Gaps identified, remediated and closed |
| External VAPT | Not assessed | Compliant report issued |
| ASV scan | Non-compliant (default ingress certificate) | Compliant |
| Certificate & TLS | Unverified by third party | Trusted CA wildcard · A+ · TLS 1.2/1.3 · HSTS |
| Attestation | None | PCI DSS SAQ D Attestation of Compliance |
NUDAX can show card issuers, travel management companies and agencies a current PCI DSS AOC instead of relying on self-declarations.
Ready-made evidence (AOC, VAPT and ASV reports) shortens vendor due diligence in sales and onboarding cycles.
Encryption, access control and monitoring for cardholder data are now formally assessed, documented and maintained.
With documented scope, data flows and SPOC details, future ASV scans and annual re-attestation can run without re-scoping.
IP addresses, environment hostnames and internal system details are withheld from this case study for security reasons.
Skybook Global manages PCI DSS compliance for travel technology providers, agencies and OTAs, from scoping and gap remediation to VAPT, ASV scanning and the final Attestation of Compliance.
Adding {{itemName}} to cart
Added {{itemName}} to cart