Every payment device,
tracked and provable.
Meet PCI DSS Requirement 9 with confidence. Tag every card terminal and PED with a tamper-evident QR code, enforce scheduled check-ins, and keep an immutable audit trail your assessor can't argue with.
Ingenico Move/5000
Trusted by retailers, hospitality groups and payment operators who get assessed
A device inventory that holds up under assessment.
PCI DSS requires you to maintain an accurate inventory of every card-reading device, inspect it for tampering and substitution, and periodically verify each one is where it should be. A spreadsheet of serial numbers won't survive a QSA's questions. QR-Inventory turns each PED into a self-documenting record — scanned, checked and sealed.
A complete, current device register
Every POS terminal, card reader and PIN-entry device in one authoritative list — model, serial, firmware, location and custodian. Each device carries a unique tamper-evident QR tag, so identifying and verifying one takes a single scan, not a stock-take.
Evidence of monitoring, not just intent
Scheduled check-ins prove devices are inspected on a defined cadence. Every scan, seal-check, move and repair is written to an immutable log — so when an assessor asks "show me", you produce a dated history instead of a promise.
Everything you need for payment-device compliance.
Device inventory management
POS terminals, card readers and PIN-entry devices, each with a unique tamper-evident QR tag for instant identification.
Scheduled check-ins
Weekly or monthly verification reminders confirm each device is present, sealed and operational — on a cadence you set.
Immutable audit trail
Every location, check-in, repair and status change is appended and time-stamped — ready for any PCI DSS assessment.
Device lifecycle tracking
Record when devices are deployed, sent for authorised repair, swapped or decommissioned — a complete chain of custody.
Tamper-evident security
Metalised, tamper-evident QR labels leave clear visual evidence of any attempt to remove or alter the seal.
Compliance reporting
Device inventories, check-in compliance rates and full audit trails, exported in the formats your assessor expects.
Mapped to PCI DSS Requirement 9.5.1.
PCI DSS v4.0.1 is specific about how point-of-interaction (POI) devices that capture card data via direct physical interaction must be inventoried, inspected and protected. Here's where QR-Inventory does the heavy lifting.
Protect POI devices
POI devices that capture payment card data are protected from tampering and unauthorised substitution, with evidence captured whenever a device changes.
Up-to-date device list
Maintain a current inventory of every POI device — make and model, location, and serial number or other unique identifier — kept accurate as devices are added, moved or retired.
Periodic inspections
Surfaces of POI devices are inspected periodically to detect tampering and substitution, at a frequency defined by a targeted risk analysis performed under Requirement 12.3.1.
Staff training
Personnel in POI environments are trained to be aware of attempted tampering or replacement, with clear procedures and an auditable record of device checks.
QR-Inventory produces the defensible record that proves your device inventory was kept current and your inspections happened. It does not, by itself, make you PCI DSS compliant — requirement references here are indicative, and your scope, inspection frequency and validation route should be confirmed with your QSA or acquiring bank.
If a seal is broken, you'll know.
Our metalised QR labels are engineered to fracture on removal, leaving unmistakable visual evidence of tampering. Bound to the device record, each tag turns a routine scan into a documented integrity check.
- Visible, irreversible evidence of seal removal
- Each tag uniquely bound to one device record
- Seal status captured at every check-in scan
- Alerts raised the moment a tamper is reported
An unbroken record, written as it happens.
Nothing is editable after the fact. Every inspection, seal check, redeployment and repair is appended, attributed and sealed — so the device history you hand an assessor is the history that actually happened.
Tamper-evident by design
Each entry is hashed and chained to the last. Any alteration is detectable.
Time-stamped & attributed
Who, what, where and when — captured automatically at the point of scan.
Defensible in any PCI DSS assessment
Export a complete, signed evidence pack for one terminal or every device in scope.
Compliance that deploys in an afternoon.
Built for teams who need to be audit-ready quickly — and stay that way as they scale.
Instant implementation
Apply the tags, register the devices, start tracking. No heavy rollout, no new hardware and no integration project standing between you and a current inventory.
Mobile-first check-ins
Staff scan with any phone or tablet, on the shop floor or behind the counter — so the inspection happens where the device is, not back in an office.
Works with patchy signal
Scanning and check-in capture work offline in basements, stockrooms and back-of-house, then sync automatically once a connection returns.
Scales 10 to 10,000
From a single store to a national estate — one register, one set of controls and one place to see which sites are behind on their inspections.
Expert support
A team that understands PCI DSS device requirements and can configure check-in cadences to the scope you have agreed with your QSA.
Exception-led dashboards
Check-in rates by site and device class, with overdue inspections surfaced first — so you fix the gap before it becomes a finding.
Tag it. Check it. Prove it.
The terminal becomes the front door to its own record — no logins to hunt for, no device spreadsheet to find.
Tag & register
We map your device estate on a scoping call. You apply a tamper-evident QR tag to every terminal and register its make, model, serial and location.
Check in
Set the cadence your risk analysis supports. Staff scan each device to confirm it is present, inspect its surfaces and record that the seal is intact.
Prove
Track check-in rates, catch exceptions early, and export a dated inspection history for one terminal or every device in scope.
Built for card-present environments.
Every lane, every store, one register.
Tills, handheld readers and unattended terminals tracked across every branch, with check-in rates per store — so a site that quietly stops inspecting surfaces on your dashboard, not in an assessment.
- Per-store device registers and check-in rates
- Serial and location kept current as devices move
- Seal state captured at every scan
- Exception dashboard for branches falling behind
Mobile terminals that come back.
Pay-at-table handhelds move between staff, floors and venues all night. Bind each one to a tagged record so custody, presence and seal state are logged rather than assumed.
- Handheld custody logged by scan at handover
- Shift-based presence checks
- Loss and swap events evidenced
- Multi-venue grouping under one account
Card-present payments in clinical settings.
Pharmacy counters, patient-services desks and private clinics take card payments inside estates that already carry heavy audit. One register holds the terminals alongside everything else you are inspected on.
- Terminals tracked beside wider equipment registers
- Role-based access for large mixed teams
- UK data residency, UK GDPR aligned
- Evidence packs exported on demand
Procurement-grade evidence.
Leisure centres, car parks, registrars and council receptions all take card payments. Keep one authority-wide inventory with the inspection trail internal audit and your acquirer expect to see.
- Unlimited sites under one authority-wide register
- SSO / SAML for large user bases
- Open API and full data export
- Inspection trail ready for internal audit
One subscription. The whole ledger.
Every plan includes unlimited check-ins, the immutable audit trail and evidence-pack exports. You scale by devices and people — not by feature paywalls.
- Up to 250 assets, 5 users
- Inspections, certificates & audit trail
- £59 / month if billed monthly
- Up to 5,000 assets, unlimited users
- Ticketing, training, PPE & evidence packs
- £239 / month if billed monthly
- Unlimited assets, SSO / SAML & SCIM
- API & ERP/CAFM integrations
- Bespoke builds for non-standard operations
All prices exclude VAT. Compare plans in full →
Enterprise controls. Public-sector grade.
The record is only as valuable as it is trustworthy. QR-Inventory is built to satisfy procurement, IT and audit from day one.
Immutable audit log
Append-only, hash-chained events that cannot be altered or back-dated.
Role-based access
Granular permissions by team, store and device class. Least-privilege by default.
SSO & SAML
Connect your identity provider — Microsoft Entra, Okta or Google Workspace.
UK data residency
Data hosted in the UK, processed in line with UK GDPR.
Open API & exports
Your data is yours. Sync to your ERP/CAFM or export in full at any time.
Backups & uptime
Continuous backups and a 99.9% uptime commitment on Business plans and above.
PCI DSS device tracking, answered.
Does QR-Inventory make us PCI DSS compliant?
How often do POI devices need inspecting for tampering?
What has to be in the device inventory?
How does a tamper-evident tag help with the inspection itself?
Can we prove staff were trained to spot tampering?
One system of record for everything you're a duty-holder for.
Fire door compliance
Quarterly and annual fire-door checks under Regulation 10, with self-closer results and photo evidence against every door.
Fire door compliance softwarePAT testing records
Portable appliance test results held against each item, with retest dates and pass/fail history one scan away.
PAT testing softwareCompliance management
Scheduled inspections, certificates and reminders across every statutory asset class in one register.
Compliance management softwareMake PCI DSS device tracking a non-event.
See how QR-Inventory keeps every payment terminal inventoried, inspected and provable — in a 30-minute walkthrough with our team.