Payment & PCI Compliance Policy
How card payments are taken, why your card details never reach our systems, and what we do keep for billing and accounting.
Maintained by Automated Governance Systems. Last reviewed August 2026. This page is app-owner maintained content, not an independent certification or audit report.
Payments are processed by Stripe
All card payments for the framework are taken through Stripe, our payment service provider. Checkout is presented in a Stripe-hosted embedded form, so card numbers, expiry dates and security codes are entered directly into Stripe's environment.
Stripe is a PCI DSS Level 1 certified service provider. Its certification is Stripe's own; this page does not claim any certification for Automated Governance Systems.
We do not hold your card data
- We never see, transmit or store full card numbers or security codes on our servers, in our database or in our logs.
- The framework only stores non-sensitive references returned by Stripe — a customer reference, a subscription reference, the card brand and last four digits, and the expiry month and year — so you can recognise the saved payment method.
- Saved cards are held by Stripe. Adding, updating or removing a card is done in the Stripe Customer Portal, which we link to from your account.
Our scope and responsibilities
Because card data is captured entirely by our provider, our own responsibilities are limited to keeping the integration secure. We do this by serving checkout only over HTTPS, restricting the pages that may load payment scripts through a content security policy, verifying Stripe webhook signatures before acting on any event, and keeping API keys in server-side secret storage that is never exposed to the browser.
Test and live payment environments are kept separate, and only authorised AGS finance staff can access billing tooling.
Billing records
We keep invoices, payment status, subscription tier and renewal dates so we can operate your subscription, meet UK accounting and tax obligations, and answer billing queries. You can view and export your billing history from your account at any time.
Billing records are retained for the period required by UK tax law, then deleted or anonymised.
Failed payments and disputes
If a payment fails we notify you and retry in line with Stripe's dunning schedule before any change to access. If you believe a charge is wrong, raise it with us first through HELIX or the Support & escalation page — most billing issues are resolved faster this way than through a card dispute.
Refund requests are handled under our Refund Policy.
Reporting a payment security concern
If you suspect fraudulent use of your card on the framework, contact your card issuer immediately and email hello@automatedgovernancesystems.com so we can investigate the account activity at our end. Security weaknesses can also be reported under our Security Policy.
Version history
Last updated . Earlier versions are listed for reference; the newest version is the one that applies.
- Version 1.0Current
First published payment and PCI position.
Questions about this policy?
HELIX — Help Assistant
Ask anything about ALFI + EDIE, governance, or the SAMU apps.
Try HELIX now
Type a question below, or pick a quick prompt to get started.
HELIX is an AI assistant. Replies may be incomplete or wrong — check anything important with a person.