Topic Options
#35897 - 03/05/13 01:23 PM PCI Compliance
Steve Schwartz Offline
Adagio God

Registered: 03/10/02
Posts: 4506
Loc: Wynnewood, PA
A client is being asked whether Adagio Receivables is PCI Compliant (PCI stands for Payment Card Industry). They are using version 8.1A, so they want to know for both that version and for 9.0.

Is there a document on the website they can read?

Thanks

Steve

Top
#35898 - 03/05/13 01:49 PM Re: PCI Compliance [Re: Steve Schwartz]
Retired_Guy Offline
Adagio Master

Registered: 03/16/99
Posts: 10504
Loc: Canada
No and No.

While it was at one point, the rules have been evolving and now it is no longer compliant. Being so requires a re-architecture of credit card handling throughout the product.

There is no requirement to store credit card information within Adagio.

Sorry.
_________________________
Andrew Bates

Top
#35902 - 03/05/13 03:07 PM Re: PCI Compliance [Re: Retired_Guy]
Douglas Dickie Offline
Adagio God

Registered: 06/02/99
Posts: 4410
Loc: Vancouver, BC
Andrew

Originally Posted By: Andrew Bates
There is no requirement to store credit card information within Adagio.


I disagree. For anyone taking credit card payments for regular use (OE, IN, POS etc.) and/or recurring charges (monthly payment plans with payment by credit card) the user of Adagio must store the credit card details somewhere. The most logical place is in AR. Using the banks payment processing software that is disconnected from Adagio is a pain.

Given that you are about to experience this problem yourself I surprised at your answer.
_________________________
Douglas Dickie
AccSys Solutions Inc
Phone: 1.888.534.4344
ddickie@accsyssolutions.com

Top
#35905 - 03/05/13 04:45 PM Re: PCI Compliance [Re: Douglas Dickie]
Retired_Guy Offline
Adagio Master

Registered: 03/16/99
Posts: 10504
Loc: Canada
Hi Doug,

I was answering Steve's question about Adagio being PCI compliant. It isn't and there is no documentation saying it is.

We're well aware that storing the credit card information in the banks disconnected system is a pain. We do this with Moneris for all our credit card customers (and we have been taking credit cards since 1985).

Again, changing this requires a complete re-architect of how credit cards are managed in Adagio. A project too large to consider at this particular time, although it is on our project R&D list for future consideration.
_________________________
Andrew Bates

Top
#35909 - 03/05/13 06:17 PM Re: PCI Compliance [Re: Retired_Guy]
Brian Stief Offline
Waterloo Guy

Registered: 04/04/06
Posts: 1736
Loc: Waterloo, Ontario, Canada
I agree with Andrew. We reviewed the requirements for PCI compliant with Adagio last year and Adagio is not PCI compliant.

Be careful, and do not store credit card details within Adagio AR. Yes, it will work work with OE but the consequences and exposure to credit card fraud from even storing the details in AR are scary.

We had someone want to use our Link2Points software to send out emails with their credit card details to their vendors to use their Credit card number for purchases, and we said no. So they would not use our software. And I'm glad.

Brian
_________________________
Brian Stief,CPA,CA
Stief Group www.stiefgroup.com
Link2 Systems www.link2systems.com
800.540.3164

Top


Moderator:  Christa_Meissner 
Who's Online
1 registered (Softrak Support), 62 Guests and 1 Spider online.
Key: Admin, Global Mod, Mod
Forum Stats
1865 Members
5 Forums
14453 Topics
70613 Posts

Max Online: 432 @ 01/20/25 10:17 PM
April
Su M Tu W Th F Sa
1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30