View Single Post
  #117  
Old 04-03-2012, 11:59 AM
 
joelrhome joelrhome is offline
 

Advanced Member
  
Join Date: Dec 2003
Posts: 89
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

In Case anyone is interested, we have decided to take another approach and work with our cc processor/gateway and create a new module that will work like this:

1. On the One Page Checkout, the customer selects "Credit Card".

2. When they click the Submit Button, the X-Cart Dialog modal box(like the login modal box) opens over top of the Checkout page, where the customer enters their CC info and clicks submit.

3. Upon a successful payment processing, the page is directed to the X-Cart receipt page as normal.

The benefits of this method are:
1. The customer never leaves the site to enter their CC Info.

2. The X-Cart installation is out of scope for PCI and PA DSS Compliance - meaning that you do not need to have your website or web server validated. This is because technically, credit card info only "looks" like it is being entered into X-Cart via a modal box, but in fact it is being entered into a PCI DSS validated middleware. This is a great solution for any size X-Cart site, but especially for small sites that are on shared hosting accounts.

3. We want to make it available at no cost for merchants who switch to our payment processor/gateway (the one we work with). If anyone is interested, PM me for details. They tell me they can match whatever rates people already pay.
__________________
Joel Rhome
x-cart 4.4.X