It wouldn't be fun if all this was done before. This is uncharted territory and we are not taking it lightly. We have involved the right talent (some payment industry experts) and have designed this carefully. We are confident that we will pass all certifications necessary to satisfy everyone (including our own high standards).
HN user
fayez
If you decide to build something on our platform, please fill out the form at http://goo.gl/forms/dgwMwDysAv to start a conversation with us. Good luck!
First things first; the card data is encrypted on read and the device will soon be PCI certified. So none of the card data will be accessible to anyone on the device.
The transaction data (amounts, items, transaction statuses, etc) is managed by the PoyntOS (owned by Poynt). That data has the necessary authentication and authorization around it to prevent just anyone with the device from having access to it. Only a merchant user logged into the app and with the appropriate level of privilege will be able to access the data.
Finally, 3rd party applications will go through a strict vetting process and will be signed. Therefore, it will not be possible for some fake app to work on the device. Also, PCI requires us to constantly monitor the installed application for any kind of tamper.