PCI DSS 4.0 made the payment page a controlled surface.
Requirements 6.4.3 and 11.6.1 mean every script reaching a payment page must be inventoried, authorised and integrity-checked, with tamper detection you can show firing. Here is how Flowmynt produces the inventory, the detection and the evidence as one run.
- Industry
- Fintech
- Flowmynt product
- Security & Controls
- Deadline set by
- Your assessor
- Stays with you
- Assessor scope, risk acceptance, allowed third parties
PCI DSS 4.0 requirements 6.4.3 and 11.6.1 are no longer future-dated. Every script that reaches a payment page has to be inventoried with an owner and a justification, its integrity assured, and unauthorised changes detected and alerted. The assessor asks to see the inventory, and asks for proof that the detection actually fires.
The controls are well understood. Assembling them for an assessor, in the shape an assessor wants, is the cost.

What the assessor will ask for
A payment page loads scripts, and those scripts load scripts. Without an inventory, nobody can say which third parties can read the fields a customer types into.
The evidence has to be real: a seeded change must fire the detection, and that firing must be on record. A policy document does not pass the assessment.
What you send us
The pages in scope, the current script inventory if one exists, and your assessor's evidence expectations.
Where a page can be taken out of scope instead, that is the first question, not the last.
How the evidence is produced
The engagement starts by shrinking the surface, because a page that never sees card data has far less to prove. What remains is inventoried script by script, watched for change, and shown to raise an alarm when a change is seeded. The evidence pack is built as the work happens, in the shape an assessor asks for.
Reduce the surface first
Where authorisation can move to a hosted provider page, card data never enters your page at all. That is the Flowmynt default: the customer authorises on the provider's page and only a status comes back.
Inventory
Every script reaching the remaining payment pages is listed, including scripts loaded by other scripts, each with an owner and a justification.
Detect
Integrity checks and change detection are implemented with alerting, on an isolated branch in your codebase.
Independent review
The change and the evidence pack are reviewed by someone who did not build them.
Prove
A seeded change must fire the detection, and acceptance requires that proof to exist in the record.
Hand to the assessor
The inventory, the detection and the evidence are delivered in the shape an assessor asks for.
What goes to the assessor
Three things go to the assessor, each produced by the run rather than assembled afterwards.
- A script inventory with an owner and a justification against each entry.
- Detection shown to fire, with the seeded-change evidence retained in the same record.
- Scripts that cannot be justified, raised as a decision for you rather than removed.
Your calls
Flowmynt produces the inventory, the detection and the proof. The relationship with your assessor, the scope you agree with them and which third parties you allow on the page are yours.
- The assessor relationship and the assessment scope.
- Risk acceptance.
- Which third parties you allow on the page.
Where this lives in Flowmynt
Flowmynt keeps card data out of chat, out of the adaptor and out of your platform: payments are authorised on the provider's secure page, and card-number patterns typed into a conversation are refused and purged at the door. That design decision is what keeps your PCI scope small.
The same principle runs through Flowmynt Issuance and WhatsApp payments: the provider that holds the card data is the party in scope, and your customer journey stays outside it.
Source pattern: PCI DSS 4.0 payment page controls, Exekova fintech use cases
Is your assessor waiting on the inventory?
Send the pages in scope and the assessor's expectations. Flowmynt replies with the scope-reduction options first, then the plan for the inventory, the detection and the evidence.
Talk to Flowmynt