Home / Restaurant, bar & event skimmer protection

Guests pay distracted, and the reader moves.

In hospitality, people pay fast and in a crowd, often late — so a tampered reader can sit unnoticed all night. And the reader isn't bolted down: it's carried to tables, pocketed, handed between shifts, sometimes taken home. SkimGuard tracks a reader that moves, checks it at handover, and keeps the record.

The hospitality problem

A device that doesn't stay put.

A bar or restaurant reader lives a different life than a bolted-down checkout lane. Over a night it's handed between servers, carried to tables, set down and picked up, and locked away at close — or not. That movement is exactly what makes an inventory hard to keep and a swap easy to miss.

Add the way people pay — quickly, in a crowd, distracted, often after a few drinks — and a reader that's been overlaid or swapped can run for a whole shift before anyone looks twice. The threat here isn't mainly a radio hidden in a cabinet; it's the overlay, the swap, and the reader nobody can quite account for at 2am.

Built for readers that move

Roaming devices and a shift-handover check.

Track a reader by its serial, not its spot. A roaming reader is followed by serial through the inventory as it moves, rather than pinned to a fixed position — so a device that spends the night travelling still shows up in the list PCI DSS Requirement 9.5.1.1 asks for.

Check it at handover. A shift-handover inspection is a quick check when a reader changes hands, so a swap or an added overlay is caught at the moment of custody change rather than at a monthly audit. The record shows who held it and who checked it.

Same overlay-and-swap checks. At the start of an inspection the serial is re-read; a mismatch is flagged as a substitution or wrong-slot pick with a mandatory reason, and never silently fails the inspection. The reader is compared against a stored reference photo — an assist that highlights a difference, never a verdict — so a person judges an overlay.

The honest case

No state mandate here — a business one.

Let's be straight: there is no state skimmer law that covers a restaurant, bar or event venue. The fuel-dispenser statutes apply to gas pumps with a card reader, not to your dining room. So the reason to do this isn't the law.

The reason is the record. When a card is compromised and the trail leads back to your venue, what protects you is being able to show your readers were inventoried and checked on a schedule — the evidence PCI DSS Requirement 9.5.1.x and the Requirement 10 audit trail describe, the thing an acquirer or insurer asks for, and the difference between a chargeback fight you can document and one you can't.

What this is, and isn't

SkimGuard helps you document and meet the point-of-interaction device controls in PCI DSS Requirement 9.5.1.x and keep the Requirement 10 record. It is not an attestation or certification of PCI compliance, and it is not a guarantee against fraud — a clear scan means nothing was detected, not that a reader is safe. Your qualified security assessor or acquirer assesses compliance.

Best fit: groups

Strongest for multi-venue operators.

Pricing is per location, calibrated to sites with several terminals — so a hospitality group or operator gets the strongest fit, with banded rates across venues. A single small bar with one or two readers is served, but the economics favour a multi-site plan. Talk to sales about your group.