PCI DSS L1 Strong authentication, in each buyer's language

A checkout built to be trusted — and to clear the rules.

Orbipay is PCI DSS Level 1, tokenizes card data so it never touches your servers, and runs SCA / 3-D Secure exactly where the rules require — presented in the shopper's own language so strong authentication never feels like a foreign roadblock.

PCI DSS Level 1 SCA under PSD2 GDPR-aligned
3-D Secure stepshown in French
Card never storedtokenized in the sheet
CHECKOUT · PARIS Total € 248,00 Numéro de carte •••• •••• •••• 4242 token Chiffré dans la fenêtre · jamais stocké chez vous Payer 248,00 € Vérification 3-D Secure Demandée par votre banque Code envoyé au •• 67 4 1 7 9 Authentifié uniquement quand la règle l'exige Confirmer PSD2 · SCA satisfaite
Certified by default

The hard parts are handled before you start

Compliance and data protection are not add-ons you switch on. They are how the checkout is built, so the burden stays off your servers and out of your roadmap.

PCI DSS Level 1

Orbipay operates at the highest PCI DSS tier and is assessed every year. Card data is captured inside our hosted fields, so your systems stay out of scope.

Audited yearly

Network tokenization

Card numbers are replaced with network tokens, so a stored credential is useless if exposed and a saved card keeps working when the physical card is reissued.

No raw PAN

SCA / 3-D Secure

Strong Customer Authentication under PSD2 runs through 3-D Secure where it is required, and is skipped where an exemption applies — so security never adds a needless step.

PSD2 ready

GDPR data handling

Personal data is collected only where it is needed, processed under clear consent and handled in line with GDPR — including data-subject requests and retention limits.

Privacy by design
How a payment is protected

From keystroke to authorization, locked down

Every payment passes through the same four stages. Card details never sit on your infrastructure at any point along the way.

Encrypted in the sheet

Card data is entered into Orbipay's hosted fields and encrypted in the shopper's browser. It is never exposed to your page or sent to your servers.

Out of your scope

Tokenized

The card number is swapped for a network token. From this point on, nothing downstream ever handles the real number — only a token that is safe to store.

PAN replaced

Authenticated where required

If the rules call for it, a 3-D Secure challenge runs in the shopper's language. Where an exemption applies, the step is skipped to keep the flow short.

Only when needed

Routed to authorize

The tokenized, authenticated payment is routed to your processor for authorization. You receive the result and the token — never the underlying card data.

Token, not card
SCA without the friction

Strong auth only where the rules demand it

A challenge on every payment costs you sales; no challenge where one is required costs you compliance. Orbipay applies Strong Customer Authentication precisely — requesting 3-D Secure when the rules say so, claiming exemptions when they apply, and always in the shopper's language.

  • Exemption logic claims low-risk and low-value exemptions so most payments pass without a challenge.
  • Challenge in their language — when 3-D Secure does run, it reads as native, not as a foreign warning.
  • Liability shift on authenticated payments moves chargeback risk where it belongs.
EXEMPTION APPLIES No challenge Low-risk payment authorized straight through RULE REQUIRES SCA 3-D Secure, in their language Código de verificación 5 2 0 8 authenticated · liability shifted
Data residency & privacy

Customer data, kept where it should be

Selling across borders means handling personal data under more than one rulebook. Orbipay keeps the footprint small: minimal collection, clear retention, regional storage where it is required, and the controls you need to answer a data request quickly.

  • EU data residency for European shoppers, with storage that stays in-region.
  • Data minimization — only the fields a payment needs are collected and retained.
  • Subject requests for access and erasure are supported and logged for your records.
  • Encryption at rest and in transit, with access scoped and audited end to end.
DATA RESIDENCY EU shopper Stored in the EU Collected only what the payment needs Retention bounded and documented Encryption at rest and in transit GDPR-aligned handling
99.99%
checkout uptime, trailing 12 months
1
PCI DSS level — the highest
100%
card data tokenized before storage
SCA
applied only where rules require

Uptime is illustrative of the platform's operating target. Certifications are maintained through annual assessment.

Sell abroad on a checkout that clears the rules

Get PCI DSS Level 1, network tokenization and precise SCA out of the box — protecting shopper data and your conversion rate at the same time.