Home / Companies / Upsun / Blog / Post Details
Content Deep Dive

Substantially reduce your PCI DSS control burden through inherited infrastructure

Blog post from Upsun

Post Details
Company
Date Published
Author
Greg Qualls
Word Count
723
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

For engineering leaders, PCI DSS audits often halt development as teams gather evidence to prove compliance, highlighting the challenges of managing raw infrastructure. Upsun advocates for "Inherited Compliance" by leveraging a secure-by-default cloud application platform that reduces the burden of manual maintenance through automated patch deployment and traceability, allowing teams to focus on securing their own code. Through a shared responsibility model, Upsun manages the infrastructure, including project isolation and audit trails, while customers handle application-level security. To prevent compliance drift, Upsun treats infrastructure as version-controlled code, ensuring consistent environments and auditable histories, and offers multi-cloud portability without security compromises. Companies are encouraged to use third-party processors for cardholder data and can rely on Upsun's PCI-certified clusters, though some regions are excluded. Transitioning to a managed platform helps streamline compliance workflows, with tools like the .upsun/config.yaml file facilitating secure and standardized deployments across cloud providers.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.