Hello,
A customer has come to me requiring proof of security method at each step of the way during the eBusiness Sales Order process when using a credit card. They want to know that credit cards are not being stored unencrypted on their servers at any time. I have a call into Sage but the customer is getting antsy. I have already sent them the 'Sage 100 ERP Credit Card Processing spec.pdf.
If anyone can shed any light on this i would appreciate it.
How does the Credit Card data travel through from eBM order page from Start to Finish and What method of encryption is being used at each point?
eBM Web Site – client enters credit card info
(encrypted by SSL) through customer firewall to
IIS Server – Which talks to another server
(encrypted by Certificate or SSL??)
Sage Web Engine (Sage WEb Engine and Sage 100 App Server and Paya are on one server ) thinking web engine might not ever hold data, just serves up web pages possibly to IIS?
(encrypted by ?) talks to
Sage 100 Which then sends info to Paya
(encrypted by ?)
Paya Virtual Terminal
Thank you.
------------------------------
Christine Kuhn
Consultant
RKL eSolutions, LLC
------------------------------