Payment card data discovery

Know where card data lives.

Support PCI DSS scope, retention and remediation decisions with evidence from structured files, documents, images, scanned PDFs and compressed archives. Scans run locally, so files and findings stay inside your environment.

PANScout at a glance
PLATFORMSWindows · macOS · Linux
INTERFACESDesktop + command line
PROCESSINGLocal by design
Technical overview

Test your PCI DSS scope against the data.

Scan selected systems and file locations to identify card data outside the expected cardholder data environment, document completed searches and give every file a recorded outcome. Use that evidence to confirm or refine scope and focus remediation where it matters.

  • Find unexpected card data

    Identify data that may need to be securely deleted, migrated into the defined CDE or included in a revised scope.

  • Document selected environments

    Record where a completed scan found no card data across supported content, together with the scan record and any exclusions.

  • Retain evidence for scope confirmation

    Keep masked findings, file outcomes and coverage evidence for annual review and assessor conversations.

See how PANScout records coverage

Card data can appear far beyond tables and rows.

It turns up in tabular exports and spreadsheets, as well as screenshots, scanned documents, old archives and shared folders. PANScout follows it across both structured and unstructured files and leaves teams with evidence they can act on.

DETECT

Structured and unstructured files, one detection path

Inspect CSV, JSON, XML and spreadsheets alongside documents, PDFs and images. The scanner combines card-number validation with surrounding context to separate likely card data from everyday numeric noise, giving teams a more focused set of findings to review.

PROTECT

Findings you can review without creating another card-data store

Full card numbers are handled in memory during scanning. PANScout saves only masked findings, alongside the context teams need to review and act.

INSPECT

OCR and archive inspection, built in

Inspect searchable and scanned PDFs, common image files and supported content inside ZIP, TAR, GZIP and ZLIB archives. Everything needed is part of PANScout. No separate OCR products, plug-ins or licences are required.

REPORT

Reporting ready for PCI DSS evidence work

Document findings with review outcomes and notes that carry into the report. Export them with masked evidence and a complete scan record in self-contained HTML and versioned JSON, ready to support scoping, retention and remediation work, annual PCI DSS reviews and assessor conversations.

A useful report turns a scan into evidence.

Bring masked findings, documented outcomes, reviewer notes and recorded file outcomes together for retention decisions, remediation work, annual reviews and assessor conversations.

See the reporting workflow
  1. SCAN

    Record coverage

    A recorded outcome for every file, with practical follow-up where needed.

  2. REVIEW

    Assess masked findings

    Masked candidates, test-number recognition and confidence context support focused review.

  3. DECIDE

    Document the outcome

    Review statuses and notes carry the team’s decision into the evidence record.

  4. REPORT

    Retain the trail

    Export a local HTML evidence report and versioned JSON for remediation and assessor conversations.

Verified demonstration20 files inspected18 published test numbers recognised20 file outcomes recorded

Structured or unstructured, the same detection path.

PANScout identifies supported content instead of trusting filename extensions. The same detection and reporting rules apply whether data starts in a table, export, document, image, PDF or supported archive.

Structured data and tables
CSV, TSV, JSON, XML and XLSX
Documents and text
TXT, logs, Markdown, DOCX and PPTX
PDF and images
PDF, PNG, JPEG, TIFF, GIF, BMP, WebP, JPEG 2000, PBM, PGM and PPM
Archives
ZIP, TAR, GZIP and ZLIB, including supported content inside them

PDF and image inspection includes packaged OCR for scanned documents and photographed cards. Archive inspection uses safety limits for nesting, file count, expanded size and extreme compression.

Bring the scanner to the data.

Install PANScout on the Windows, macOS or Linux system performing the scan. Everything needed is included, with no additional tools or licences to purchase or configure. Use the desktop application for guided work or the command line for servers and repeatable workflows.

Compare desktop and command-line use

Security software should earn its place in your environment.

A card-data scanner may inspect some of your most sensitive systems and files. PANScout has a defined product boundary, with fixed inspection components, local processing and interfaces limited to scanning, review and reporting.

  • Package integrity can be checked before deployment
  • Built-in inspection does not depend on separate host scanning tools
  • Scanning and licence activation do not require a new network connection
  • Source data and findings are not sent to a remote scanning service
Use the card-data scanner buyer’s checklist

TRY THE COMPLETE SCANNER

Try PANScout free for 14 days.

No purchase is required. The trial includes the same inspection and reporting capabilities as paid editions.

14 days
Complete inspection and reporting
1 installation
Desktop application and command line
No payment card
Start and scan locally