Merchant Link SecurityCents

A blog that comments on the latest developments in the world of payments, payment data security and technology, PCI compliance, and more.

The Value of a Payment Gateway
Data security has become critical to any business. All of these new technologies can be confusing for any merchant, who at the end of the day only wants to ensure that all payment transactions are processed and arrive at the bank in a secure and timely fashion. Every time a card is swiped, a check is written or a gift card is redeemed, multiple institutions are involved in the process, including the merchant establishment, the gateway, the banks, the processors and the card associations. In the midst of this rapid change and emerging payment types, a payment gateway is at the core of the payment transaction process. The right payment gateway can better manage communication with the banks and processors.

New Tokenization Guidelines and TransactionVault
On August 12, 2011, the Payment Card Industry Security Standards Council (PCI SSC) issued an Information Supplement to provide guidance on how to implement a tokenization solution and how it may impact the scope of a merchant’s compliance efforts with the PCI Data Security Standard.

Already, there have been a lot of questions and buzz around this in the industry and the first question we want to answer for our customers is “Does Merchant Link meet these new guidelines?” More specifically, “Does TransactionVault meet these guidelines?” The answers are YES – we not only meet these guidelines, we exceed them.

Merchant Link TransactionShield™ and TransactionVault™ Technical Review
Merchants large and small continue to be plagued by data breaches caused by inadequate security controls or insecurely developed and deployed applications which leak or allow access to sensitive payment card data. Security professionals, service providers, application developers and hardware manufacturers are working across a number of security domains to address the data security needs of merchants. Two of the leading solutions intended to address the security of consumer credit card data in the merchant network are Point‐to‐Point Encryption (P2PE) and card data tokenization.

Exploring Different Approaches to Increasing DataSecurity Using Tokenization and Point-to-Point Encryption
A rise in massive, high profile credit card breaches in recent years has underscored the need for merchants, point‐of‐sale (POS) and property management system (PMS) providers, credit card processors and other third party organizations to do everything they can to secure sensitive payment data. Despite the many measures being taken – the billions of dollars spent to secure customer data, to harden and fortify payment systems, and to create policies to prevent unwanted intrusion or leakage of that sensitive data – those who seek to compromise and profit from it continue to find new ways to infiltrate security systems.