You didn't mention a 3rd choice of approaching the problem from a PCI standpoint and requesting excemption. Has anyone successfully done this when using a 3rd party to process cards such as Paypal?
Main Topics
Browse All TopicsHas anyone found a solution to the fact that Godaddy's Virtual Dedicated Servers are not PCI compliant. I contacted them and claim they are not responsible to keep theirs updated with the latest security updates.
My godaddy VDS is failing the PCI scans and I don't know what to do about it.
I am using paypal payflow link to collect the credit card info, so I feel I should be exempt from the scan.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
I doubt you will get any exemption if you are collecting CC info on the site.
What is the actual PCI vulnerability coming up in the scan? Maybe you can work to resolve the issue itself.
If it is serious and you cannot resolve it and GoDaddy wont help, you may want to move to another hosting company.
If you knowingly leave the vulnerability and you get hacked, you may get sued and I bet GoDaddy is protected in thier agreement. The laws are getting more and more strict on data protection every day.
Sorry if I wasn't clear. I do NOT collect any CC info on MY site.
I forward the amount to PayPal Payflow's website where THEY collect all of the CC info and process it.
That is my point: no CC info is entered, stored or processed on my site.
Have you heard of people getting PCI exemptions in these cases?
I am getting scans saying that my PHP is 5.2.8 or lower and the SSLv2 is being used instead of SSLv3... etc...
I could be wrong, but I think you are collecting the CC information and passing it to Payflow via the Payflow gateway. You may not store it, but if this is the case you are still passing, and that is why you must be compliant. If you are just redirecting to Paypal for payment, then that would be different.
To answer your question, I believe the onus is on you to say if you are compliant or have resolved an issue to PCI satisfaction or why it does not need to be. So unfortunately I do not think you will get an exemption.
Business Accounts
Answer for Membership
by: kyleb84Posted on 2009-03-09 at 16:28:39ID: 23842287
If they say they're not responsible, and refuse to help.
You have 2 choices:
- Use another company
- Host it yourself, at your premises