Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • We have been working with SISA throughout the re-architecting process to ensure the new environment conforms to the Microsoft PCI model template. The new environment incorporates all of the controls added in response to the security incidents this year, as well as additional controls.

 

Questions for Tender Retail customers:

Why can’t Tender Retail be used within the Azure environment? 

  • Because security is our top priority, we will only be supporting payment gateways that remove or reduce PCI scope for both the web platform and our customers. As a result, the new platform will not support payments from Tender Retail. Shift4 and MiraPay both offer end-to-end point encryption of credit card data through their iFrame solutions.

As a Tender Retail customer, what are my options?

  • The best option for Tender Retail users is to transition to the Shift4 payment gateway for PrismWeb as soon as possible. The benefit to your store is that Shift4 offers point-to-point encryption and tokenization of credit card information. P2PE encrypts cardholder data right at the terminal, so sensitive cardholder data never enters the merchant’s environment, and tokenization replaces stored credit card data with random, alphanumeric value that is useless to data thieves.

Is Shift4 available in Canada? I thought it wasn’t. 

  • Shift4 is available in Canada, however, they currently cannot provide P2PE pin pads that can be used in Canada due to the laws regarding data transfer across border lines.

What are the issues regarding the use of Tender Retail in-store on POS versus for PrismWeb payment processing? 

  • From an eCommerce perspective, Tender Retail puts our system in PCI scope as it does not offer payment tokenization or an iFrame solution.

What are the implications of using Tender Retail in-store for POS transactions? 

  • If implemented according to standards, there is minimal risk at the POS/Core side for PCI, because the systems do not touch the credit card information.

How do I initiate the transition process to Shift4?

  • To get started with the Shift4 transition, it’s important to contact us as soon as possible at info@prismrbs.com.

  • We’ve been working diligently with Shift4 to create a seamless transition plan.

  • In order to get you set up on Shift4, there are a few things we need from you, including a signed contract addendum and a completed VAR sheet. Please note, you’ll need to engage with your bank in order to obtain the necessary details for the VAR sheet. After you initiate your transition process with us, we encourage you to contact your bank.

  • You also need to update to the latest version of PrismCore (28.2.7.7) prior to the transition.