|
|
|
|
All our products and services are PCI-CISP compliant. You can choose to run them in compliant or non-compliant mode, subject to your requirements.
What is PCI-CISP?PCI-CISP are global standards issued by Visa and Mastercard which govern how card details are stored. Our products support PCI-CISP, although it can be "turned off" for Merchants which do not meet PCI-CISP thresholds.
The Cardholder Information Security Program (CISP) is a set of rules established by VISA and other card issuers for securing computer systems and data from unauthorised access and loss of credit card information. The Payment Card Industry (PCI) data security standard is an industry wide standard which incorporates many of the CISP standards and adds additional requirements. Mastercard, Visa, American Express, Discover use the PCI standard in their security programs.
Does it apply to you?For VISA any M
erchant processing over 500,000 transactions per year must comply with PCI-CISP For Mastercard any Merchant processing over $125,000 USD in any month must comply with PCI-CISP Other card issuers have their own requirements and you must check with your merchant service provider/bank if you have any doubts. The thresholds specified are subject to change and are for guidance only.
Our ProductsWhether you enable PCI-CISP or not our products encrypt card data using "strong encryption" methods which meet Government standards.
|
| PCI-CISP "On" | PCI-CISP "Off" | | Card details encrypted | Yes | Yes | | CCV number stored in database | No | Yes | | Search by card number (4 digits max) | Yes | Yes | | Search by card number (any digits) | No | Yes |
|
Use the "Settings" option in each product Configuration section to turn PCI-CISP on or off.
In PCI-CISP mode, transactions/bookings (online or otherwise) which have card details included to "Secure a booking" will retain the CVV code until the first payment has been processed. Once that payment is processed the CVV will be cleared. Fresh card details can be stored with a new CVV and each payment will clear the CVV. Also card details stored permanently for the client will not store the CVV at all when using PCI-CISP mode. |
|
|
|