View Single Post
  #5  
Old 05-01-2012, 07:06 AM
  totaltec's Avatar 
totaltec totaltec is offline
 

X-Guru
  
Join Date: Jan 2007
Location: Louisville, KY USA
Posts: 5,823
 

Default Re: Does X-Payments have to live on a separate server?

I think that it is more important from a compliance standpoint to consider hosting the database on a separate server than x-payments. But I also believe that since x-cart is not PA-DSS validated, then it compromises the pci-compliance of whatever server it is installed on.

The point of the compliance is to prevent breaches and ensure the security of the web server, so a non-validated applications existence would seemingly bring the entire server out of compliance. So to be completely safe you might need 3 servers!!!

Getting your site to be compliant is such a grey area that it doesn't seem to be worth the effort. What we need to do is find out how many conversions will be lost due to re-direction before we can consider that option.

The general consensus is that re-directing customers away from the site to the hosted gateway will decrease conversions.

I found some opinions on the net to the contrary:
http://forum.boagworld.com/discussion/6549/payment-gateways-on-site-processing-or-hosted-page

One could make the argument that clients feel safer entering their info at PayPal or Authorize.net, but I am not a believer yet.
__________________
Mike White - Now Accepting new clients and projects! Work with the best, get a US based development team for just $125 an hour. Call 1-502-773-6454, email mike at babymonkeystudios.com, or skype b8bym0nkey

XcartGuru
X-cart Tutorials | X-cart 5 Tutorials

Check out the responsive template for X-cart.
Reply With Quote