2 Utilises card tokenisation for maximum security
Card tokensiation is the process of converting important cardholder data such as personal identifying information, card numbers, CCV’s etc. into randomly generated numbers called a “token”.
What this does is in the event of a data breach, hackers only have access to unusable tokens rather than data they can use to conduct credit card fraud or identity theft. Card tokenisation is not mandatory and as such an important feature to identify.
3 Is PCI Data Security Standard compliant
Perhaps the most crucial and easy to recognise security feature is PCI Data Security Standard (PCI DSS) compliant. PCI is the payment card industry security standard and is a set of requirements for organisations that handle credit card information.
There are twelve stringent technical requirements outlined by the PCI that must be met for companies to receive compliance approval. Without going into too much detail the standard mandates that companies must have the technical infrastructure to cover the following areas.
- Build and Maintain a Secure Network and Systems
- Protect Cardholder Data
- Maintain a Vulnerability Management Program
- Implement Strong Access Control Measures
- Regularly Monitor and Test Networks
- Maintain an Information Security Policy
The PCI is an independent and highly respected organization and as such looking for reference on payment providers website that they are “PCI Compliant” is a huge tick of approval.
4 Uses SSL (Secure Sockets Layer – https)
This security feature is in reference to the web browser of your platform provider. SSL in recent times has become standard practice for all websites but there are still a few entities yet to implement the technology.
The easiest way to identify whether a provider is using SSL is if the website is using “https:” at the start of the web address instead of a “http”. On most web browsers (Chrome, Safari etc.) you will see a small lock symbol next to the name of the website in your address bar.
SSL protects the internet connection between your data and a website, as a result securing online transactions and ensuring your data remains secure and confidential.