← Files Go: FintechARCHIVED FILE
skills/go-fintech-security-compliance/references/control-boundaries.md
970 Bytes · Oct 5, 2026 · 18:32 UTC
# Control boundaries - Tokenization reduces scope only when detokenization and routing paths remain isolated. - Encryption does not remove scope when the same service controls ciphertext and keys. - Applicable sensitive authentication data, including CVV/CVC, PIN/PIN blocks, and full track data, must not be retained after authorization even when encrypted; verify the current PCI DSS wording and assessor interpretation for the actual flow. - Authentication does not authorize a tenant, resource, amount, refund, or administrative action. - Audit records are weak when privileged actors can silently edit or delete them. - Data minimization includes logs, traces, retries, DLQs, backups, support exports, and model prompts. - Retention needs both deletion behavior and evidence that deletion completed across replicas and backups under policy. - Classify token-like values: reusable payment/network tokens and detokenization handles are not ordinary correlation IDs.
SHA-256: 59cea6c8e483fad1704f58cb6c4db0c03e4527ccf515af0498e19a450fc225f9