Skip to content
Ready to get started, Let's Go! Talk to Sales

Security

QorPay operates its own processing platform, so security is not a vendor questionnaire we forward; it is infrastructure we run. This page describes how QorCommerce handles cardholder data, who can touch what, and what happens when something breaks.

How is cardholder data handled?

Card numbers are tokenized at the point of capture. The raw primary account number (PAN) is exchanged for a token, and the PAN itself lives encrypted in the QorCommerce vault, a segmented environment inside our PCI DSS Level 1 boundary. Downstream systems, reports, and API responses carry the token, not the card.

For integrators, this is the point: if you use hosted checkout or secure embedded forms, card data goes from the customer's browser to our vault without transiting your servers. That keeps your PCI scope at the SAQ A end of the spectrum instead of a full assessment. Stored credentials for recurring billing use card tokens and ACH tokens, so repeat charges never require re-handling the PAN.

What infrastructure does QorCommerce run on?

QorCommerce runs on [TODO: cloud provider/regions], with the cardholder data environment segmented from general-purpose workloads. Data is encrypted in transit (TLS) and at rest. Production, test, and development environments are separated; the public sandbox never touches live card data.

[TODO: confirm redundancy/failover architecture, backup cadence, and DR objectives before publishing specifics.] We would rather leave a placeholder here than publish an invented number.

How is access controlled?

Access to production systems follows least privilege: role-based permissions, granted per function, reviewed on a recurring schedule as required by PCI DSS. Administrative access to the cardholder data environment requires multi-factor authentication and is logged. Customer access to the QorCommerce portal is scoped the same way: users see the merchants, transactions, and reports their role allows, and nothing else.

API authentication uses per-application key pairs, so a compromised key can be revoked and rotated without touching other integrations.

How do you handle incidents?

In public. Platform availability and incident history are published at status.qorcommerce.io. When an incident occurs, the status page carries the timeline: detection, impact, mitigation, resolution. Because QorPay operates the full stack, the engineers responding are the ones who built the affected system; there is no upstream processor to wait on.

Security incidents involving cardholder data follow the response procedures required by PCI DSS and our sponsor bank agreements, including notification obligations. [TODO: confirm published notification commitments.]

Frequently Asked Questions (FAQs)

Does QorPay store raw card numbers?

Primary account numbers are tokenized at capture and stored in the QorCommerce vault. Applications integrating through hosted checkout or embedded forms never touch the raw PAN, which keeps most of their systems out of PCI scope.

Is QorCommerce PCI DSS Level 1?

Yes. QorPay is validated as a PCI DSS Level 1 service provider through an annual on-site audit by a Qualified Security Assessor, not a self-assessment questionnaire. Details are on the compliance page.

Where can I check platform status?

status.qorcommerce.io publishes real-time and historical availability for the QorCommerce API and portal, plus incident reports when something goes wrong.

How do I report a security issue?

Email [TODO: security email] with details. We acknowledge reports and keep you informed through remediation. (TODO: confirm disclosure policy and response SLA.)

Need security documentation for a vendor review?

Ask us for the current PCI Attestation of Compliance and the answers your security team actually needs.