Home / For Business / PCI payment-device audit trail
SkimGuard logs every action on your point-of-interaction (POI) devices and their inspections — who did it, what they did, when, from where, and the outcome, including denied attempts. Records are append-only, immutable, and mirrored to a write-once (WORM) store, with card numbers redacted. That's the who/what/when/where/outcome record PCI DSS v4.0 Requirement 10.2 asks an audit log to capture and Requirement 10.3 asks you to protect — exportable for your assessor. Included free in both B2B tiers.
This page is about the audit trail — the tamper-evident record of what happened to your devices. If you're looking for the inspection workflow itself (the inventory, tamper checklist, photos, risk-based frequencies and training), start with the PCI device inspection logbook. The audit trail described here runs underneath all of it.
Built for PCI DSS v4.0 Requirements 10.2 & 10.3
An audit log is only worth having if it can be trusted. If a record can be edited or deleted after the fact — even by an administrator — it proves nothing. PCI DSS v4.0 Requirement 10 exists for exactly this reason: capture what happened (10.2) and protect that record from modification (10.3). SkimGuard applies both to everything that happens to your payment devices.
Requirement 10.2 asks an audit log to capture enough to reconstruct who did what. SkimGuard writes an entry for every device and inspection action — a device acquired, deployed, moved, sent for service, returned or decommissioned; an inspection recorded; a schedule changed; a permission-checked action refused. Each entry carries:
Capturing failed and invalid attempts is a specific expectation of Requirement 10.2 — a blocked attempt to alter a device record is often the more interesting event than a routine successful one.
Requirement 10.3 asks that audit logs are protected from modification and that read access is limited to those with a need. SkimGuard's records are:
Free-text inspection notes are convenient, and convenient fields are exactly where a card number can accidentally end up. SkimGuard runs a PAN-redaction pass over free-text before anything is stored, so a primary account number pasted into a note doesn't become part of the retained record — keeping the audit trail useful without turning it into a place cardholder data is stored.
The device inventory audit, the inspection log and the training records export to CSV or PDF in one tap, so you can hand a QSA or acquirer the who/what/when/where/outcome record for your payment devices without reconstructing it by hand from screenshots and spreadsheets.
This audit trail covers your POI-device inventory and inspection activity. That is one part of an overall PCI DSS Requirement 10 logging program — you still need logging across the rest of your cardholder-data environment (systems, applications and network components) to satisfy Requirement 10 as a whole. SkimGuard helps you document and meet the device-side controls and gives you an exportable trail for them; it is not itself an attestation or certification of PCI compliance, and your overall compliance is assessed by your QSA or acquirer.
At a glance
The audit trail isn't a separate product — it's how the PCI device inspection logbook records everything, included at no extra charge in both B2B service tiers (Handheld and Automated).
An audit trail proves what your team did; always-on network skimmer detection watches the terminals between those actions, using the access points you already own. Together they cover the gap a periodic inspection leaves.
See the full B2B feature set and current pricing on the for-business page.
Get started
Every device and inspection action, logged with who/what/when/where/outcome, append-only and WORM-backed, exportable for your assessor — included free in both B2B tiers. Start setup for your locations, or see how the inspection logbook works.