Skip to main content
Version: 0.0.1

Security

Best Practices​

For our recommended security best practices, see our Best Practices guide

PCI DSS​

Every organisation that handles card payments must comply with the Payment Card Industry Data Security Standard (PCI DSS). Annual compliance is mandated by the payment card schemes and banks.

What is PCI DSS?​

PCI DSS is a global standard, helping to protect cardholder data and tackle the growing threat of security breaches. It sets the operational and technical requirements for organisations handling card payments, and for software developers and manufacturers of payment applications and devices.

Zenith Payment's entire infrastructure is fully compliant with PCI DSS - we are certified at Level 1, which is the highest level of compliance. We are independently audited annually for compliance by qualified security assessors.

Please find our PCI DSS certificate here: PCI Certificate

What this means for you?​

Whilst Zenith Payments is a PCI DSS compliant organisation, if your organisation does accept card payments then it must also be fully compliant, though not to the same level. Non-compliance with PCI DSS could make you responsible for any losses through fraud, and you may also face considerable fines from the card schemes and banks.

There are four levels of compliance, dependent on how many transactions are processed by your organisation in a year. Find out how your organisation can reach compliance at the PCI Security Standards Council Website

More specific information can be found at the PCI Security Standards Documentation site, searching for "SAQ". For most merchants, the "SAQ Instructions and Guidelines" and "SAQ-A" are the appropriate documents. Please refer to this site for the most up to date standards.

3DS​

3D Secure (3DS), often recognised by brand names like Visa Secure or Mastercard Identity Check, is a security protocol designed to provide an additional layer of authentication for online credit and debit card transactions. The "three domains" refer to the Acquirer (the merchant's bank), the Issuer (the customer's bank), and the Interoperability Domain (the infrastructure supporting the protocol). When a transaction is processed via 3DS, the customer is typically prompted by their bank to verify their identity using a one-time passcode, a mobile app notification, or biometric authentication. This process is handled upstream of Zenith Payments and no action is needed from developers when using our payment plugin.

Data Protection and Tokenisation​

Tokenisation substitutes card details with unique token values that are usable only in permitted payment contexts. This lowers direct handling of raw card data and supports safer recurring or repeat-payment experiences.

Why Tokenisation Matters​

  • Improves security by limiting exposure of sensitive card details.
  • Supports payment-data protection practices used across modern payment systems.
  • Enables convenient returning-customer payment flows without re-entering full card details.

Shared Responsibility​

ZenPay provides hosted payment controls and platform-level protections, but merchants still play an important role in maintaining a secure payment operation.

Merchants should:

  • protect internal access to payment-related systems and reports
  • review payment outcomes and investigate unusual activity
  • train teams to recognise phishing and social-engineering risks
  • use secure internal processes when handling customer and payment data