Security Considerations
As xServ operates from your server, you will need your own encrypted connection to securely transport
the user's card data from the browser back to your server before passing it over to xServ.
We recommend 128-bit encryption as a minimum.
We can provide SSL certificates from the major Certificate Authorities.
See our
SSL Certificates page.
Alternatively, discuss your requirements with your hosting provider.
PCI compliance is very costly and time-consuming.
If you do not store any credit card data on your site, you can avoid the most onerous parts of PCI compliance.
Store card data in the secure iCharge Card Store instead of in your own system by using the
Tokenization functions provided by xServ.
You can refer to stored cards using Tokens.
A token is a unique key assigned to represent each stored card that you can safely store in your system because it cannot be used to perform unauthorized transactions.