Security
Your customers' data
stays theirs.
Card numbers and personal details are tokenized the moment they're entered. Your team sees only what their role allows, and every action is on the record.
- Cards and personal data swapped for tokens
- Tokenized
- All your servers ever see of a card
- last4
- Each person sees only what they need
- Role-based
- Logged with who did it and when
- Every action
Commitments
How we protect customer data
- 01
We don't sell customer data.
We use your customers' details to process payments and meet our obligations as the seller. We don't sell them to advertisers or data brokers.
- 02
Card numbers live in a Level 1 vault.
Cards are stored with a PCI DSS Level 1 certified vault. Your servers and your database only ever hold tokens and the last four digits.
- 03
PCI DSS compliant.
Pandabase validates its compliance with a PCI DSS Self-Assessment Questionnaire, and keeps your own scope as small as it can be.
- 04
Hosted on tier-one clouds.
Pandabase runs on Cloudflare, AWS and Akamai, which are PCI DSS Level 1 service providers.
- 05
Access is earned, and logged.
Roles decide who can issue refunds, change payout details or create API keys. Every action is recorded with who did it and when.
Vulnerability
Disclosure Program
Found a security issue? Our disclosure program pays researchers up to $5,000 USD for responsibly reporting qualifying vulnerabilities. We assess severity using CVSS.
- 1DiscoverFind a vulnerability
- 2ReportSend details to our team
- 3Get rewardedUp to $5,000 USD
Yes. Pandabase validates its PCI DSS compliance with a Self-Assessment Questionnaire (SAQ), and card data itself is stored with a PCI DSS Level 1 certified vault.
