Re: X-Cart and PCI-DSS / PA-DSS compliance
Thanks for your replies...
Amy, I assume you mean as a redirected 3rd party solution...?
If I'm reading you right, that would still result in a redirection - a separate URL in the address bar - and for whatever reason, it seems there are users that are still not as trusting of a redirected payment process, even with a known provider.
It's unfortunate, but it seems that many end users are just not aware that the security issues of today are more likely encountered at a site providing self hosted payment handling incorrectly (i.e. not pci compliant, etc.) than one that redirects to a known and trusted payment gateway.
I tried both ways a couple of years ago, and definitely experienced a difference between integrated and redirected payment handling - in my experience, the integrated always performed significantly better. With my online advertising costs vs. overall profit margin, I just can't afford to test those waters again and risk losing even a small percentage of conversions.
That's why this iframe concept has me intrigued...
__________________
XC 4.4.5 Gold
|