Securing your data.
We prioritize keeping sensitive information secure and protected. So you can rest easy and focus
on running your business.
PointCraft is committed to helping our merchants stay secure and compliant.
We undergo rigorous audits, testing, and inspections to maintain the highest level of compliance in the industry. Our talented team of in-house developers, systems engineers, and security administrators work to maintain strict security standards at all times.
Data management.
Merchants trust PointCraft to securely manage and protect customer payment data, removing their systems from security and compliance scope using our custom PointCraft OS.
Daily Backups
Databases are automatically backed up daily to protect merchants against lost, corrupted, stolen or destroyed data. Backups are performed between data centers, as well as offsite. This is part of our commitment to ensuring ongoing business continuity.
Data Storage
We use self-replicating database clusters to store transaction, cardholder, and merchant data, ensuring uptime and load balancing. Customer and merchant data is logically separated and inaccessible to each other. Access by authorized PointCraft staff is logged for security and PCI-DSS compliance.
Network Setup.
PointCraft proactively safeguards data with firewalls, IDS, and IPS on servers. We conduct regular system updates and respond swiftly to major vulnerabilities by applying patches. Servers are hardened following security guidelines.
Firewalls and IDS/IPS
PointCraft employs firewalls with Intrusion Detection and Prevention Systems to guard against active and passive threats. These systems monitor network traffic for abnormalities, malicious code, and vulnerabilities. Servers also have locally installed IDS and IPS to detect and warn system administrators of unusual activity. If suspicious activity is detected, the IPS will take the action required to protect the servers while alerting PointCraft’s security team for monitoring review.
System updates
The servers and networks appliances are regularly updated to ensure all software is up to date. If a major vulnerability is discovered, patches are applied immediately by PointCraft's system and security team. Per our compliance, all updates are logged as part of our change-control policies.
Authentication & access controls.
To safeguard pointcraft data and systems, we enforce strict access controls, such as VPN requirements, defined user roles, multi-factor authentication, and comprehensive logging for network access and activity. Our internal office networks are isolated from platform environments and have restrict wireless access. Internal systems are only accessible by employees who are locally and physically connected to the network.
Encryption.
PointCraft employs AES-256 encryption for all sensitive merchant and cardholder data, such as name, card numbers, expiry dates and cardholder address in order to meet PCI compliance. We do not store CVV, PIN, EMV, or mag data.
Information in transit
PointCraft safeguards data in transit with TLSv1.2 and strong cyphers, excluding outdated SSLv3, TLSv1.0, and TLSv1.1 from our systems. This ensures that data is encrypted in transit and maintains integrity.
Compliance.
PointCraft is a Level 1 PCI-DSS compliant service provider, by undergoing rigorous on-site audits, vulnerability scanning, penetration testing, and adherence to NIST security practices, all aimed at ensuring the highest level of data security compliance with the Payment Card Industry Data Security Standard.
Service uptime.
PointCraft devotes significant resources to ensure the most uptime possible for our networks and merchants. These safeguards include redundant virtual environments across cloud-based data centers, using service providers that utilize best industry practices including backup power generation and dual-path power distribution systems.
Saas development.
PointCraft's in-house programmers develop all our systems and applications. This ensures they meet our strict security standards, and enables close collaboration with QAs and security staff to identify potential issues before they become a problem.
Secure coding practices
All in-house applications adhere to the most current secure coding guidelines, including OWASP, through our ongoing developer training. This approach gives us full control over coding standards, source code, and deployment cycles.
Penetration testing
PointCraft completes regular penetration tests to identify network, system, and application vulnerabilities for potential malicious activities. These tests are done by both our in-house security team and third party professionals. Any vulnerabilities are addressed immediately by our teams.
Vulnerability scanning
Routine vulnerability scanning of PointCraft's networks and applications help find potential security concerns. We adhere to compliance requirements with internal and ASV-performed external network scans.
FAQs
-
To safeguard against data loss, corruption, theft, or destruction, PointCraft automatically performs daily database backups. These backups are carried out between data centers and off-site locations, demonstrating our commitment to maintaining business continuity for our merchants.
-
To ensure the utmost security of PointCraft's data and systems, we enforce rigorous access controls, including VPN requirements, well-defined user roles, multi-factor authentication, and comprehensive logging for network access and activity. Our internal office networks are isolated from platform environments and have restricted wireless access. Internal systems can only be accessed by employees who are physically connected to the network on-site.
-
PointCraft invests significant resources to ensure maximum uptime for our networks and merchants. We utilize redundant virtual environments across cloud-based data centers and partner with service providers that employ industry best practices, including backup power generation and dual-path power distribution systems.
-
As a Level 1 PCI-DSS compliant service provider, PointCraft undergoes stringent on-site audits, vulnerability scanning, penetration testing, and adheres to NIST security practices. Our unwavering commitment to meeting the highest level of data security compliance with the Payment Card Industry Data Security Standard ensures the protection of our merchants' and their customers' sensitive information.
Get Started with PointCraft Today
Take the first step towards streamlining your retail or restaurant management. Fill out our waitlist form and experience the power of PointCraft firsthand.