We have secure URL for our platform i.e. https://dashboard.agencyplatform.com If you use this URL, every page of our software including payment page is secured by 2048bit encryption.
We never store credit card no and CVV on our server. As soon as client fills that information, we pass that information immediately to our payment processor which is “Braintree Payments”. Paypal is the owner of this company. This payment processor is PCI DDS complaint hence the security is topnotch. That company stores the CC details along with our details in their vault and gives us 6-digit encrypted token as ID and whenever we need to charge the clients card, we just pass that 6-digit encrypted number and Braintree does the rest from their own server.
The only thing we store in our database are
What happens if someone gets that 6-digit token? The answer is its useless for anyone else. Only our server is linked with Braintree and only our server can make a request to use that 6 digit token. Request from anywhere else will be discarded immediately.
What happens if someone gets access to our server along with that 6-digit token?The answer is our company account will get that money along with Credit card owner details because that 6 digit number is linked to our bank account. As soon as Braintree charges your card, we get that money in our account. This is how our accounting system understands who paid us and how much.