<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does non-hosted SIM encrypt card data? in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Does-non-hosted-SIM-encrypt-card-data/m-p/48771#M24504</link>
    <description>&lt;P&gt;I am using non-hosted&amp;nbsp;CIM .NET API to add credit cards.&amp;nbsp;This is the one part of my&amp;nbsp;app that sends&amp;nbsp;cardholder data out. So my question is, does it send this data out encrypted?&amp;nbsp;My site does have an&amp;nbsp;SSL certificate, but&amp;nbsp;I&amp;nbsp;am concerned&amp;nbsp;about PCI compliance.&amp;nbsp;From what I understand SAC level C is what applies to my circumstance since&amp;nbsp;my app doesn't store&amp;nbsp;cardholder data directly, but it does transmit it only when sending it to CIM using the API they provided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So again, my question is is it encrypted and am I&amp;nbsp;correct in that this requires SAC C compliance? Any help would be grealy appreciated.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Nov 2014 17:16:57 GMT</pubDate>
    <dc:creator>JeffSGA007</dc:creator>
    <dc:date>2014-11-14T17:16:57Z</dc:date>
    <item>
      <title>Does non-hosted SIM encrypt card data?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Does-non-hosted-SIM-encrypt-card-data/m-p/48771#M24504</link>
      <description>&lt;P&gt;I am using non-hosted&amp;nbsp;CIM .NET API to add credit cards.&amp;nbsp;This is the one part of my&amp;nbsp;app that sends&amp;nbsp;cardholder data out. So my question is, does it send this data out encrypted?&amp;nbsp;My site does have an&amp;nbsp;SSL certificate, but&amp;nbsp;I&amp;nbsp;am concerned&amp;nbsp;about PCI compliance.&amp;nbsp;From what I understand SAC level C is what applies to my circumstance since&amp;nbsp;my app doesn't store&amp;nbsp;cardholder data directly, but it does transmit it only when sending it to CIM using the API they provided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So again, my question is is it encrypted and am I&amp;nbsp;correct in that this requires SAC C compliance? Any help would be grealy appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2014 17:16:57 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Does-non-hosted-SIM-encrypt-card-data/m-p/48771#M24504</guid>
      <dc:creator>JeffSGA007</dc:creator>
      <dc:date>2014-11-14T17:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: Does non-hosted SIM encrypt card data?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Does-non-hosted-SIM-encrypt-card-data/m-p/48779#M24508</link>
      <description>&lt;P&gt;Connecting&amp;nbsp;to a secure server--including &lt;A href="https://secure.authorize.net/" target="_blank"&gt;https://secure.authorize.net/&lt;/A&gt; as SIM does--includes automatically&amp;nbsp;negotiating TLS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will ensure the data will be encrypted as it leaves your server for ours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, it does nothing for the data handling prior to that. So you would want to make sure your application handles the data securely at every point. Even if the data isn't storing it in a database permanently, it's presumed it would be temporarily stored in a variable before posting to us. That could be exploited by a malicious third party.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2014 19:09:51 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Does-non-hosted-SIM-encrypt-card-data/m-p/48779#M24508</guid>
      <dc:creator>Lilith</dc:creator>
      <dc:date>2014-11-14T19:09:51Z</dc:date>
    </item>
  </channel>
</rss>

