Payment Security Center


Security as a Service for Your Business

BillingTree's commitment to security remains at the highest level. The latest security tools ensure that merchants feel secure. We would like to highlight some of those key features.

Secure Socket Layers (SSL)
This security arrangement sits just below such protocols as HTTP and uses the lower-level TCP/IP to allow SSL-enabled PCs and servers to authenticate to each other. SSL creates single-session key exchange, using public and private key data encryption (usually 128-bit) from RSA Data Security for enciphering and deciphering encrypted SSL transmissions.

  • We offer the finest in currently available server-level protection behind a dedicated firewall and when applicable, a Virtual Private Network (VPN). The security at the server level is customized according to your needs.
  • Multiple layers of application-level control prevent intrusion.
  • We offer the highest levels of file (and messaging) security protection available and it is superior to any secure FTP server.
  • An ACH SecureFile product does not write unencrypted data to a disk, regardless of whether businesses or their customers are communicating ACH-file data or confidential, sensitive messages.
  • An ACH SecureFile's built-in secure data-storage system uses the 256-bit AES encryption certified by the United States and Canadian governments for their vendors.


SSL 1024-bit Data Encryption
All of BillingTree's communications and processing occur through Secure Socket Layers (SSL). To ensure a higher level of security, we use 1024-bit SSL encryption with every transaction. Any toolkits linked for use with the BillingTree gateway are also tested to be certain that security is established properly. With the proper security-layers setup between toolkits and the gateway, we ensure that no information can be stolen and all information is securely transacted.

Identification Through "Keys"
An older, more conventional way of communicating and identifying with gateways was the use of usernames, ID's and passwords. BillingTree realizes that this method is insecure. For this reason, we use a "Key System" for identification. Merchants' toolkits (for example, software) communicate with the gateway by using an assigned high-bit encrypted string called a key. When sent into the gateway, the key is processed to identify the specific merchant as well as the toolkit to which it belongs. This method allows merchants to feel safe knowing their toolkit source code doesn't contain such critical information as their usernames, and it allows merchants to separate their toolkits by assigning individual keys for each one. Merchants can revoke keys at any time if they notice that these keys are being misused by malicious online users, and different fraud protection layers can be applied to each key within the BillingTree Fraud Stopper.

Fraud Stopper
The BillingTree Fraud Stopper relies on its Module Stack Design. Each module controls a different aspect of security and merchants choose which modules to put on their fraud-control stacks. Some examples of modules are duplicate transaction control, block by country (and/or state, city, zip, name), auto detection of toolkit misuse by customers, block by IP, and many more. This design allows the merchants to add or change their fraud controls constantly and BillingTree is continually adding new modules to the Fraud Stopper, and always remains up to date on fraud-security issues.

Fraud Stopper also allows merchants to apply different fraud controls to different keys (sources), so merchants can maintain high levels of fraud control on their websites but low levels on the consoles for their employees.

A New Way of Storing Payment Data
BillingTree realizes that the most common merchant attack is the stealing of a list or database of payment information. With this in mind, BillingTree has developed a revolutionary new way of storing data to prevent such attacks. The BillingTree system contains no database or list; therefore the idea a malicious attacker stealing data is impossible. Payment data is stored on an individual basis and can only be viewed on an individual basis by unlocking or "de-encrypting" each one separately.

A merchant never has to call up a "list" of data. If certain information is needed, the data is decrypted and un-parsed from the system, a process that requries only seconds. Only one instance can be viewed at a time. This non-database design of storing payment data provides the utmost level of security toward payment storage to date.

Any More Questions?
We want merchants to be confident in our security standards at BillingTree. If any questions have not been answered concerning our security, please feel free to email our technical support group for answers at the following address support@mybillingtree.com.



NEWS & EVENTS

Events Calendar
 
Events:
Tradeshows in the Payments Industry
Press Room
 
Press Room:
Explore Latest Developments

 
Facebook:
Follow us on Facebook for the latest news

 
Twitter:
Follow us on Twitter for up-to-the-minute news

 
YouTube:
View our commercial on YouTube

Industry Resources    |   Payment Solutions    |   Partners    |   Company    |   Security    |   Customer Login   |  Privacy  

Electronic Payment Providers, Inc is a registered TPP / ISO / MSP of HSBC Bank USA, N.A., Buffalo, N.Y.
© Copyright 2006 - 2009 Electronic Payment Providers, Inc. All Rights Reserved

Click to Verify Domain