Results 1 to 8 of 8

Thread: WHMCS credit card storage - PCI level/Gateways

  1. #1
    Join Date
    Jan 2007
    Posts
    31

    Unhappy WHMCS credit card storage - PCI level/Gateways

    Good Day All,

    There seems to be a number of sites explaining the PCI requirements. If WHMCS stores the clients credit card for recurring payments, does this force us into Level 1? if so, would this apply for the offline payment module?

    We are looking at using WHMCS for licensing software and will require recurring payments. Our software will be under $20 pm and average at 10 clients. Is this a level 4 PCI?

    We are based in Australia and have limited options, even the PayPal Website Payments Pro is not available. Of all the gateway options we have explored, most require a merchant account and the gateway. And they dont provide a token api so we still store credit card details.

    Does anyone have some suggestions for a low cost gateway with a token api for WHMCS that works for Australian companies? Also, what PCI level are you on if you store credit cards?

    Regards
    Twobit

  2. #2
    Join Date
    Feb 2009
    Location
    Atlanta, GA
    Posts
    1,683

    Default

    We use Authorize.net. Not sure if thats available in Australia or not, but it's worked well for us.

  3. #3
    Join Date
    Jan 2007
    Posts
    31

    Default

    Quote Originally Posted by laszlof View Post
    We use Authorize.net. Not sure if thats available in Australia or not, but it's worked well for us.
    Hi Frank,

    Thank you for your reply. We have spoken to authorize.net, but they only accept US based customers. Most of the AU gateways are over priced for our needs.

    We are happy to do manual payments for our small customer base, but that requires PCI Certification. We have never undertaken this task before. If storing data in whmcs for offline processing only requires level 4 with SAQ D, we will go that route using a virtual POS.

    Does anyone have some tips for PCI requirements?

    Regards
    Twobit

  4. #4

    Default

    Go to https://www.pcisecuritystandards.org/
    It will answer many or your questions.
    "To see is to see a better way, to perceive any problem clearly is to begin to create its solution. All we need is the wisdom and patience to keep looking and the love to hold what we see up to the light of understanding." Laurence Boldt.

  5. #5
    Join Date
    Jan 2007
    Posts
    31

    Default

    Good Day ninak,

    Thamk you for the link. We are using that site for the documentation etc. Based on their guidelines, we should be a level 4 SAQ D - under 20k but store data. However when we run the self evaluation wizards on PCI scan vendors websites - as soon as we save save details its a level 1. Is that correct?

    Regards Twobit

  6. #6

    Default

    Your best solution is to contact the security council with your specific questions. They would be the ones to give you any real information.
    "To see is to see a better way, to perceive any problem clearly is to begin to create its solution. All we need is the wisdom and patience to keep looking and the love to hold what we see up to the light of understanding." Laurence Boldt.

  7. #7
    Join Date
    Jan 2007
    Posts
    31

    Default

    Good Day ninak,

    Thanks we are working with a few PCI Compliance vendors here in Australia.

    As we touch CC data (stored in WHMCS), we will have to be SAQ D.

    Regards
    Twobit

  8. #8
    Join Date
    Jun 2011
    Posts
    64

    Default

    Hi Twobit,

    We are in the exact same situation as yourself. Small business with low processing requirements. However we also want to store the CC details so we can automate the billing. Figuring out which PCI level we fall into is very confusing.

    Did you ever get to the bottom of it? Are you guys Level 4, and just needed to do SAQ D?

    Or like you mentioned previously, because you store the CC details, does that push you straight into Level 1?

Similar Threads

  1. Question about Credit Card hash storage
    By drhoo in forum Pre-Sales Questions
    Replies: 14
    Last Post: 05-30-12, 12:43 AM
  2. credit card storage
    By mhaskell in forum Feature Requests
    Replies: 0
    Last Post: 01-14-10, 01:32 AM