Overview
The Stripe integration monitors your payment platform’s security posture: webhooks, API keys, team members, and security settings. LowerPlane uses read-only access via API key to collect compliance evidence automatically.Prerequisites
How to Connect
Log in to Stripe
Log in to your Stripe Dashboard.
Create a Restricted API Key
Navigate to Developers > API Keys and create a new Restricted Key with read-only permissions for the resources LowerPlane monitors.
What LowerPlane Monitors
Webhooks
Webhook endpoint configurations and delivery status.
API Keys
Active API keys, restrictions, and last-used timestamps.
Team Members
Team member accounts, roles, and access permissions.
Security Settings
Two-factor authentication status and security configurations.
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Payment processing security controls are enforced |
| PCI-DSS | Cardholder data environment security is managed |