Fix PCI compliance issues with Online Express Payment Forms

Blackbaud should ensure that Online Express hosts all its form inputs containing card data within an IFRAME served from Blackbaud's domain—not the charities—so donor’s card information never touches the charity's servers. Blackbaud customer's are then able to only achieve SAQ A rather than the much harder to achieve SAQ A-EP. For a successful example of this implementation see Stripe's Checkout product. 

  • Guest
  • Dec 4 2018
  • Attach files

Privacy Policy | Safe Harbor Notice | Terms of Use | Acceptable Use Policy | © 2016 Blackbaud, Inc. All Rights Reserved