More information

PayPal Express Checkout

PayFlow Pro

PCI Compliance

The netFORUM product supports the applicable requirements of Payment Card Industry (PCI) compliance Requirement 3 (Protect Stored Cardholder Data) and Requirement 6 (Develop and Maintain Secure Systems and Applications)

See https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml for more information about these requirements.

Specifically within netFORUM, the cardholder PAN is encrypted when saved with strong cryptography and masked when displayed to the user. Cardholder data is transmitted encrypted through a Transport Layer Security (TLS) 1.2. The DoNotSaveCreditCardInfo system option can be configured to not store any credit card information. However, doing so will disable the autopay features for membership renewal and installment orders.

Some additional features we have added for increased protection include no longer storing CVV Numbers and developing a stored procedure that can be set up as a scheduled task to remove old credit card information (See Technical Information).

Our hosted systems are protected by network and web application firewalls, intrusion detection and prevention systems, and anti-virus software. We also use file integrity software and have penetrating testing and vulnerability scanning performed on a regular basis. Our systems are monitored 24 hours a day, 7 days a week and housed in a restricted access facility.

The last remaining task of PCI Compliance of Abila as a service provider is the training of Abila staff, which is currently underway.

The netFORUM product currently stores the following information:

Notes:

  1. Credit cards are used for recurring billing and in some cases refunds within netFORUM thus they are decrypted for these functions .
  2. We no longer store the CVV Number for credit cards. The number is transmitted directly to PayPal™ and no longer stored in our database.
  3. The DoNotSaveCreditCardInfo system option can be configured to not store any credit card information. However, doing so will disable the autopay features for membership renewal and installment orders.

Technical Information