We take online security seriously. All
of our online transactions go entirely through Sage Pay - the UK &
Ireland's leading independent payment service provider (PSP).
Sage Pay's security policy
As
a payment service provider (PSP), thousands of businesses outsource
their transaction security to Sage Pay, it is Sage Pay's top priority to ensure that customers’ transaction data is kept secure at all times, including Lovegrove Photography Ltd.
Transaction security
All
transaction information passed between merchant sites and Sage Pay’s
systems is encrypted using 128-bit SSL certificates. No cardholder
information is ever passed unencrypted and any messages sent to your
servers from Sage Pay are signed using MD5 hashing to prevent
tampering. You can be completely assured that nothing you pass to Sage
Pay’s servers can be examined, used or modified by any third parties
attempting to gain access to sensitive information.
Encryption and Data Storage
Once
on Sage Pay systems, all sensitive data is secured using the same
internationally recognised 256-bit encryption standards used by, among
others, the US Government. The encryption keys are held on
state-of-the-art, tamper proof systems in the same family as those used
to secure VeriSign's Global Root certificate, making them all but
impossible to extract. The data they hold is extremely secure and they are
regularly audited by the banks and banking authorities to ensure it
remains so.
System security
Sage
Pay’s systems are scanned quarterly by Trustwave which are an
independent Qualified Security Assessor (QSA) and an Approved Scanning
Vendor (ASV) for the payment card brands.
Sage pay
is also audited annually under the Payment Card Industry Data Security
Standards (PCI DSS) and is a fully approved Level 1 payment services
provider, which is the highest level of compliance. Sage Pay are also active
members of the PCI Security Standards Council (SSC) that defines card
industry global regulation.
View Sage Pay's PCI DSS certificate
Links to banks
Sage
Pay has multiple private links into the banking network that are
completely separate from the Internet and which do not cross any
publicly accessible networks. Any cardholder information sent to the
banks and any authorisation message coming back is secure and cannot be
tampered with.
Internal security
Sage Pay is controlled by Iris Scanners, which are the latest and most
precise biometric security devices available for identification. As
used by; chemical plants, airports, police stations, prisons and other
facilities where security is paramount. No one can enter or leave the
building without a valid security pass.
Staff validation
All
employees at Sage Pay are Criminal Records Bureau (CRB) checked prior
to employment and no unauthorized individual has access to or is able
to decrypt transaction information or cardholder data. Sage Pay's systems only
allow access to our most senior staff and only in extenuating
circumstances (such as investigations of Card Fraud by the Police). All
transaction information and customer card information is secure even
from our own employees.
Disaster Recovery
Sage
Pay operates on twin data centres to ensure optimal system security and
up-time and has a full disaster recovery and business continuation
policy.