Security

Your customers' data stays theirs.

Card numbers and personal details are tokenized the moment they're entered. Your team sees only what their role allows, and every action is on the record.

Cards and personal data swapped for tokens
Tokenized
All your servers ever see of a card
last4
Each person sees only what they need
Role-based
Logged with who did it and when
Every action

Commitments

How we protect customer data

  1. 01

    We don't sell customer data.

    We use your customers' details to process payments and meet our obligations as the seller. We don't sell them to advertisers or data brokers.

  2. 02

    Card numbers live in a Level 1 vault.

    Cards are stored with a PCI DSS Level 1 certified vault. Your servers and your database only ever hold tokens and the last four digits.

  3. 03

    PCI DSS compliant.

    Pandabase validates its compliance with a PCI DSS Self-Assessment Questionnaire, and keeps your own scope as small as it can be.

  4. 04

    Hosted on tier-one clouds.

    Pandabase runs on Cloudflare, AWS and Akamai, which are PCI DSS Level 1 service providers.

  5. 05

    Access is earned, and logged.

    Roles decide who can issue refunds, change payout details or create API keys. Every action is recorded with who did it and when.

Vulnerability
Disclosure Program

Found a security issue? Our disclosure program pays researchers up to $5,000 USD for responsibly reporting qualifying vulnerabilities. We assess severity using CVSS.

  1. 1DiscoverFind a vulnerability
  2. 2ReportSend details to our team
  3. 3Get rewardedUp to $5,000 USD
Report a vulnerabilitysecurity@pandabase.io

FAQ

Frequently asked questions

Answers about compliance, card data and privacy. Ask us anything else.

  • Yes. Pandabase validates its PCI DSS compliance with a Self-Assessment Questionnaire (SAQ), and card data itself is stored with a PCI DSS Level 1 certified vault.