@bflipp@vmst.io The answer to PCI compliance? No credit card info was retained (even though the app supported it) and we had a nightly job check to make sure those fields remained null. #bodge