To protect your business and your customers from data fraud, Tyro complies with Visa and MasterCard Payment Card Industry Data Security Standards (PCI DSS). Do you?
To avoid large fines or the loss of your credit card acceptance capability, self-assess your compliance and act! Learn about the Top Three POS System Vulnerabilities.
Visa has issued a global mandate requiring PCI DSS compliance by 30 September 2009. Will you be ready? Have you considered the costs of non-compliance as well as the benefits of meeting the requirements?
View Tyro's PCI DSS Certification
Other banks send part or all of the data in the clear, however, the card schemes are starting to require the Tyro level of encryption and it is expected that this will be accomplished in a few years. At a technical level, we use SSL (Secure Sockets Layer) with 3DES (Triple Data Encryption Standard, pronounced "Triple DES"), with positive terminal authentication. This is important to the merchant because all customer cardholder data and his own business volumes are secured and there is no risk to his reputation or liability from disclosure of this data.
The merchant requires a secure login and critical changes to his account information (eg bank account info, email addresses) are notified to the merchant via email. This means that the merchant can detect any unauthorised changes in a timely manner.
Our terminals are encrypted to ensure all transaction data is secure. To further secure your wireless network, our recommended best practice for WiFi terminal security settings is:
1. Enable WPA-2
2. Enable MAC address filtering
3. Hide SSID Broadcasting
4. Review firewall logs regularly
This is aimed at merchant cashier fraud and will detect unusual patterns of activity and refunds before these cause loss to the merchant (or loss to Tyro).
The PIN is encrypted securely in the terminal and then encrypted a second time for transfer to the authorisation switch. The merchant likes this because the cardholders can be assured that their critical personal information is treated securely at all times.