Home

 

BCF Commerce Credit Card Protector

The BCF Commerce Credit Card Protector is designed to reduce the difficulty and cost of PCI compliance by using isolation; stated another way, we are removing all of the credit card data out of your backoffice system, the websites and any other operational systems.

We designed BCF Commerce Credit Card Protector with the following guiding principles:

  • Provide the highest possible level of credit card data security. The difficulties of PCI compliance aside, we all know the catastrophic cost of a data breach of this kind. As difficult as PCI Compliance is, it does provide a good blueprint for securely storing and processing sensitive data.
  • Reduce the cost of PCI Compliance. PCI Compliance is expensive and time consuming. The burden on the merchant is very high, especially for those who do not have internal IT staff.

Enforcing PCI compliance within your backoffice and eCommerce Websites is very difficult. These are very complex business systems and most of their functions have little or nothing to do with credit card data. They are very dynamic systems that are constantly changing. This creates a very difficult environment for PCI compliance. Every change to the system, the network, the software or the users are subject to restrictive PCI requirements because they are all part of the Credit Card Data Environment. By isolating the credit card data, so that it is not stored in these systems, we can dramatically reduce the scope of PCI compliance.

BCF Commerce Credit Card Protector can be thought of as a “black box” appliance that sits on its own network completely isolated from your backoffice and every other system. Its purpose is to store and process credit card data and credit card transactions securely. All the cardholder data is stored using the most advanced encryption techniques. All interfaces are locked down so that only the authorized systems and users can communicate with the BCF Commerce Credit Card Protector. The BCF Commerce Credit Card Protector exposes itself to authorized systems and users through secure web services.

How does it work? We use a technique called “tokenization”. Tokenization is a process of substituting a random and unique data element in place of sensitive data (i.e. a credit card number) to avoid disclosing the actual card number. The systems that subscribe to the services of the BCF Commerce Credit Card Protector are assigned unique tokens to use in place of the actual credit card numbers. For example, when your backoffice needs to authorize a credit card, it does so by presenting a token to the BCF Commerce Credit Card Protector Service. The BCF Commerce Credit Card Protector then processes the authorization request securely and sends the response back to your backoffice. Your backoffice can now process the authorized order.

We’re very excited about this new product because it will offer a solid, long-term solution for our customers. It will provide a secure environment for our customer’s PCI needs as well as a being very cost effective. There are other products out there that are similar, but we offer a set of features and delivery choices that will make our product unique and desirable.

If you have any questions regarding the BCF Commerce Credit Card Protector, please contact Bill Heaven via email at bheaven@bcfcommerce.com or at 330-726-6500.