Overview
This article explains how Authorize.net protects your customer data and combats fraud through a combination of strong infrastructure, strict internal security policies, and adherence to industry-recognized security initiatives. It describes the government and industry compliance frameworks that Authorize.net follows, so you can be confident your customers' payment data is handled securely. This information applies to all merchants using Authorize.net payment solutions.
Authorize.net's Commitment to Security
Authorize.net is committed to safeguarding customer information and combating fraud. Our mission is to provide the most secure and reliable payment solutions for you and your customers. To accomplish this, Authorize.net dedicates significant resources toward a strong infrastructure and adheres to both strict internal security policies and industry security initiatives.
With Authorize.net, your customers can be confident their data is secure. We utilize industry-leading technologies and protocols, and we comply with a number of government and industry security initiatives.
Payment Card Industry Data Security Standard (PCI DSS)
The Payment Card Industry Data Security Standard (PCI DSS) is a set of comprehensive requirements developed by the major card brands to facilitate the adoption of consistent data security measures. Authorize.net renews its PCI DSS compliance annually.
For more information, see: Is Authorize.net PCI DSS compliant?
PCI compliance for merchants is separate from Authorize.net platform compliance. Some merchants are contacted by SecurityMetrics regarding PCI validation processes. Completion requirements vary depending on merchant setup, processor, and card brand obligations.
For more information, see: What is PCI compliance, and how do I find out if I am compliant?
Sarbanes-Oxley Act (SOX)
The Sarbanes-Oxley Act (SOX) is a set of federally mandated accounting standards for all U.S. public company boards, management, and public accounting firms. Authorize.net is validated annually by external auditors for the current, relevant portions of the Sarbanes-Oxley Act.
Statement on Standards for Attestation Engagements No. 18 (SSAE-18)
Statement on Standards for Attestation Engagements (SSAE) No. 18, commonly known as SSAE-18, defines the professional standards used to assess the internal controls for organizations that provide outsourcing services that impact the control environment of their customers. Authorize.net is validated annually by external auditors for SSAE-18.
SSAE-18 may also be referred to as:
- SOC 1 (Service Organization Controls Report 1)
- SOC 2 (Service Organization Controls Report 2)
- SAS70 (legacy reference)
For more information, see: Requesting SSAE-18 SOC Reports
Health Insurance Portability and Accountability Act (HIPAA)
Authorize.net does not handle HIPAA information in the provision of its services. We do not use or collect ancillary information about the health transaction being processed, nor do we use it for fraud analysis. Even if we did handle HIPAA information, Section 1179 of HIPAA exempts certain activities from the HIPAA rules, to the extent that these activities constitute authorizing, processing, clearing, settling, billing, transferring, reconciling, or collecting payments for health care. Authorize.net services fall squarely within these functions specifically identified by the U.S. Department of Health and Human Services as exempt.
Vendor Questionnaire
Businesses may require Authorize.net to participate in:
- Vendor risk assessments
- Security questionnaires
- Due diligence reviews
- Supplier evaluations
- Audit surveys
- Third-party risk assessments
For more information, see: Vendor Questionnaire and Due Diligence Requests.
Common Questions
- Is Authorize.net PCI DSS compliant?
- Yes. Authorize.net renews its Payment Card Industry Data Security Standard (PCI DSS) compliance every year.
- How do I know if my business is PCI compliant?
- PCI compliance depends on how your business processes, stores, and transmits cardholder data. For guidance on determining your compliance status, refer to the related support article What is PCI compliance, and how do I find out if I am compliant?
- Is Authorize.net audited for Sarbanes-Oxley (SOX) compliance?
- Yes. Authorize.net is validated annually by external auditors for the current, relevant portions of the Sarbanes-Oxley Act.
- What is SSAE-18, and is Authorize.net compliant?
- SSAE-18 defines professional standards used to assess internal controls for outsourcing service providers. Authorize.net is validated annually by external auditors for SSAE-18, which is also known as SOC 1.
- Does Authorize.net handle HIPAA-protected information?
- No. Authorize.net does not handle HIPAA information in the provision of its services and does not collect or use ancillary information about health transactions. Payment processing activities are also exempt under Section 1179 of HIPAA.
- How can my organization request an SSAE-18, SOC 1, SOC 2, or Bridge/Gap Letter from Authorize.net?
- For instructions on how to submit these report requests, refer to the related support article: Requesting SSAE-18 SOC Reports.
- How does my organization submit a vendor questionnaire or due diligence request to Authorize.net?
- Authorize.net participates in vendor risk assessments, security questionnaires, supplier reviews, due diligence packages, and audit surveys. For submission instructions, refer to the related support article Vendor Questionnaire and Due Diligence Requests.
Glossary
- PCI DSS – Payment Card Industry Data Security Standard
- SOX – Sarbanes-Oxley Act
- SSAE – Statement on Standards for Attestation Engagements
- SOC – Service Organization Controls
- SAS – Statement on Auditing Standards
- HIPAA – Health Insurance Portability and Accountability Act
Additional Resources
- Is Authorize.net PCI DSS compliant?
- What is PCI compliance, and how do I find out if I am compliant?
- Requesting SSAE-18 SOC Reports
- Vendor Questionnaire and Due Diligence Requests
