Back
Security
Natty Hatty — PCI-DSS Attestation Statement
Version: v1.1
Effective Date: November 15, 2025
Natty Hatty, Inc. (“Natty Hatty”) is committed to maintaining the security of all payment-related information processed through our platform. This PCI-DSS Attestation Statement describes Natty Hatty’s compliance posture in relation to the Payment Card Industry Data Security Standard (PCI-DSS).
1. Natty Hatty’s Role in the PCI-DSS Payment Ecosystem
Natty Hatty does not store, process, or transmit cardholder data on its servers.
All card data entry, tokenization, transmission, and storage is handled exclusively by Stripe, a PCI-DSS Level 1 Service Provider.
Natty Hatty uses:
Stripe Elements
Stripe.js
Hosted Stripe tokenization
Secure redirect / iframe-based collection
As a result, all sensitive cardholder data bypasses Natty Hatty’s infrastructure completely.
2. Stripe PCI-DSS Level 1 Compliance
Stripe is independently certified as:
PCI-DSS Level 1 Service Provider (the highest available level)
Stripe’s PCI-DSS AOC (Attestation of Compliance) is available from Stripe upon request.
By utilizing Stripe exclusively for payments, Natty Hatty leverages Stripe’s validated PCI compliance controls.
3. Natty Hatty’s PCI-DSS Scope classNameification
Because Natty Hatty never stores, processes, or transmits cardholder data directly, Natty Hatty qualifies as:
“PCI-DSS SAQ-A Out-of-Scope Service Provider.”
Natty Hatty maintains all controls required for SAQ-A compliance, including:
Verified out-of-scope architecture
Use of tokenized/hosted payment fields
TLS 1.2+ enforced encryption end to end
No card data touching Natty Hatty infrastructure
Restricted access, logging, and monitoring
Annual internal PCI review
Security scans and penetration testing
Required Statement:
Natty Hatty is PCI-DSS compliant via SAQ-A using Stripe, Inc. (PCI Level 1 Service Provider).
This is our formal compliance statement for enterprise and audit requirements.
4. What Natty Hatty Does Not Do (Scope Clarification)
Natty Hatty does not:
Store card numbers
Process card information on Natty Hatty servers
Transmit PAN, CVV, or magnetic stripe data
Store any sensitive authentication data
Access raw cardholder data at any time
Stripe manages all PCI-scoped operations.
5. Annual Validation & Ongoing Security Controls
Natty Hatty conducts the following annually:
PCI-DSS SAQ-A validation
Internal compliance and architecture review
Vulnerability scans
Penetration testing
Verification that no card data enters Natty Hatty systems
HTTPS/TLS validation
Security training for all employees
Access control and token security audits
These measures ensure that Natty Hatty continuously meets PCI-DSS SAQ-A obligations.
6. Contact for PCI-DSS Inquiries
For PCI or security documentation requests:
security@nattyhatty.com
legal@nattyhatty.com
Enterprise customers may request:
Stripe AOC
Natty Hatty Security Overview
Natty Hatty Incident Response Policy
Natty Hatty BC/DR Plan
Platform Architecture & Data Flow Diagram
7. Statement of Attestation
Natty Hatty hereby attests that:
Natty Hatty is PCI-DSS compliant via SAQ-A, relying exclusively on Stripe, Inc., a PCI Level 1 Service Provider, for all cardholder data functions.
Natty Hatty does not store, process, or transmit cardholder data.
Natty Hatty maintains all technical and organizational controls required under PCI-DSS SAQ-A.
Natty Hatty’s architecture ensures no PCI-scoped data enters or passes through Natty Hatty infrastructure.