Security Policy
Thousands of charities outsource their transaction security to us. It is our top priority to ensure that transaction data is kept secure at all times. We take an active role in the overall reduction of identity theft and fraud on the internet by ensuring the security of our IT systems, personnel and infrastructure. Our staff are trained in all aspects of web application security, including infrastructure vulnerabilities, cross-site scripting, secure data storage, and using the software development life cycle to maintain and improve security. Justgiving has been certified PCI compliant by Trustwave, an official Visa Qualified Security Assessor. This means our systems and services comply with the Payment Card Industry Data Security Standard and that we actively protect our customers' identities, personal information and financial details. Our security efforts are focused on the following areas: MasterCard Secure Code Justgiving has implemented the industry standard card verification scheme MasterCard Secure Code (MCSC™). Created by MasterCard, this scheme has helped create a higher standard of security for online card transactions. This new process is the online equivalent of the now familiar “Chip and PIN” process used in shops and restaurants. Justgiving has no knowledge of, or access to your MasterCard SecureCode™ password at any time. This is why you are asked to submit your password to your card issuer directly, over a secure link. Our system does not see or store your password.
Transaction security All transaction and credit card information entering Justgiving systems is encrypted using 128-bit SSL certificates from Verisign. No cardholder information is ever passed unencrypted in a web browser to Justgiving. You can be completely secure in the knowledge that nothing you enter as part of a secure Justgiving transaction can be examined, used or modified by any third parties attempting to gain access to sensitive information.
Encryption and data storage At our Data Centre rigorous physical, electronic, and personnel security measures protect your data. Those measures are regularly assessed by One-Sec Ltd, an official Visa Qualified Security Assessor. Once on our systems, credit card data is encrypted and securely stored in our dedicated hosting facilities at our Data Centre. Our servers and network infrastructure are owned and used by Justgiving for the provision of fundraising services, and not shared with any other company or industry. Card Security Code (CSC) and Card Verification Value or Code (CVV or CVC) Justgiving do not store the 3-digit Card Security Code (CSC), sometimes called Card Verification Value or Code (CVV or CVC).
Links to banks Justgiving authorises credit card transactions in partnership with Barclaycard Business. Any cardholder information sent to the banks and any authorisation message coming back is secure and cannot be tampered with.
Employee access Our systems only allow access to authorised staff. Your transaction information and customer card information is secure even from our own employees because our systems never display the full card numbers, even on administration screens.
Payment Card Industry (PCI) Data Security Standard compliance The PCI DSS is a set of security standards that apply across the card payment industry worldwide that help safeguard cardholder information and improve consumer confidence. The PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organisations proactively protect customer account data. Justgiving is PCI compliant. For more information on our status please click here. There are six categories of PCI compliance security standards: (1) Building and maintaining a secure network (2) Protecting cardholder data (3) Maintaining a vulnerability management program (4) Implementing strong access control measures (5) Regular monitoring and testing of networks (6) Maintaining an information security policy If you have questions regarding security or privacy on this site please get in touch via email at . |
Close window |