Jump to content

WHMCS credit card storage - PCI level/Gateways


Twobit

Recommended Posts

Good Day All,

 

There seems to be a number of sites explaining the PCI requirements. If WHMCS stores the clients credit card for recurring payments, does this force us into Level 1? if so, would this apply for the offline payment module?

 

We are looking at using WHMCS for licensing software and will require recurring payments. Our software will be under $20 pm and average at 10 clients. Is this a level 4 PCI?

 

We are based in Australia and have limited options, even the PayPal Website Payments Pro is not available. Of all the gateway options we have explored, most require a merchant account and the gateway. And they dont provide a token api so we still store credit card details.

 

Does anyone have some suggestions for a low cost gateway with a token api for WHMCS that works for Australian companies? Also, what PCI level are you on if you store credit cards?

 

Regards

Twobit

Link to comment
Share on other sites

We use Authorize.net. Not sure if thats available in Australia or not, but it's worked well for us.

 

Hi Frank,

 

Thank you for your reply. We have spoken to authorize.net, but they only accept US based customers. Most of the AU gateways are over priced for our needs.

 

We are happy to do manual payments for our small customer base, but that requires PCI Certification. We have never undertaken this task before. If storing data in whmcs for offline processing only requires level 4 with SAQ D, we will go that route using a virtual POS.

 

Does anyone have some tips for PCI requirements?

 

Regards

Twobit

Link to comment
Share on other sites

Good Day ninak,

 

Thamk you for the link. We are using that site for the documentation etc. Based on their guidelines, we should be a level 4 SAQ D - under 20k but store data. However when we run the self evaluation wizards on PCI scan vendors websites - as soon as we save save details its a level 1. Is that correct?

 

Regards Twobit

Link to comment
Share on other sites

  • 11 months later...

Hi Twobit,

 

We are in the exact same situation as yourself. Small business with low processing requirements. However we also want to store the CC details so we can automate the billing. Figuring out which PCI level we fall into is very confusing.

 

Did you ever get to the bottom of it? Are you guys Level 4, and just needed to do SAQ D?

 

Or like you mentioned previously, because you store the CC details, does that push you straight into Level 1?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated