UNSURPASSED SECURITY
Credit Card Transactions, Inc. combines Secure Socket Layer (SSL), PGP encryption,
and proprietary technologies to enable merchants to accept payments easily
and securely without the need to invest in costly security systems of their
own.
Additionally, Credit Card Transactions, Inc. is certified with Visa's
Cardholder Information Security Program (CISP) and adheres to the Payment
Card Industry (PCI)
Data Security Standard. CISP and PCI further ensure the security of customer
account information and are intended to protect cardholder data.
The following is a detailed description of Credit Card Transactions's secure online
payment systems.
A secure server is one which takes advantage of Secure Sockets Layer (SSL) technology. SSL is a protocol designed
to enable secure transmission of information on the Internet. SSL provides
encryption and integrity of communications along with strong authentication
using digital certificates. SSL uses a private key to encrypt data being
submitted from a browser before it is transferred over the Internet via
the SSL connection. When the data reaches the SSL-enabled web server,
it is decrypted. If the data were to be stolen during this transmission,
it would remain unreadable. Many web sites use SSL to obtain confidential
user information, such as credit card numbers. Web pages that incorporate
SSL have a web address starting with "https://" instead of the usual "http://".
One of the major misconceptions regarding Internet security is
that information submitted to a server using SSL will always remain encrypted
and secure. This is not true. A secure (SSL) server alone does
nothing to protect the data after it is received by the server. SSL creates
a secure path between the user's browser and the SSL-enabled server.
However, the information is only secure during the time that it
is being transmitted from the browser to the server. Once the information
reaches the server, the information is decrypted and SSL has no effect.
If there is no further encryption taking place once the information reaches
the server, the security of the information is compromised.
Credit Card Transactions takes advantage of advanced security and encryption
features to ensure the security and safety of customer data. After customer
data (credit card number or checking account number) arrives at Credit Card Transaction's
server via SSL, it is re-encrypted using PGP (RSA
algorithm), which makes the information unreadable. This information
is then pushed to an offline server (not accessible via the Internet)
where the information is safely decrypted and the transaction is completed.
Credit card and checking account data is never stored online in plain-text
(readable) format. In addition, this information is never transmitted
in plain-text via email, socket, GET, POST, etc.
Since most merchants accepting online payments do not have access
to a secure server, and even fewer utilize advanced encryption technologies,
Credit Card Transactions fills the need to simplify online commerce.
A merchant wishing to accept credit card and/or check payments online
simply creates an HTML order form using the templates supplied by Credit Card Transactions.
Each merchant is given a unique Merchant ID that is included in the HTML
source of the order form. There is no need for the merchant to have a
secure server. A customer wishing to make a purchase from the merchant
simply completes the merchant's online order form. The customer can then
be directed to Credit Card Transaction's secure server to enter their account information.
|