Protecting your business.
Supporting secure payments.
At Zivora Merchant Services, security is a fundamental part of our approach to merchant services and payment operations. We work to maintain appropriate administrative, technical, and operational safeguards for the information and payment environments entrusted to us.
Responsible information handling, appropriate verification, fraud prevention, and secure payment practices are built into our approach.
Our security approach
Security is a combination of processes, controls, technology, and responsible business practices. Our framework focuses on data protection, secure communications, access control, identity verification, fraud prevention, payment security, PCI DSS considerations, infrastructure security, monitoring, incident response, and third-party risk management.
PCI DSS and payment card security
The Payment Card Industry Data Security Standard supports secure payment-processing environments through protection of cardholder data, secure transmission, access control, authentication, vulnerability management, monitoring, testing, and information-security policies. Responsibilities depend on each merchant’s processing environment, payment methods, integrations, and service providers. Payment security is shared between merchants, processors, acquiring institutions, gateways, technology providers, and other parties.
Secure payment processing
Payment transactions may involve specialized processors, acquiring institutions, gateways, and technology providers. Depending on the approved configuration, payment-card information may be entered directly into a secure payment-processing environment rather than ordinary email or unsecured communication channels.
Encryption and data protection
We use secure communication practices designed to protect information transmitted between users and our online services. We take reasonable measures to protect business, contact, ownership, application, account, processing, and supporting information, and limit access according to legitimate business requirements.
Access control and identity verification
Access is restricted to authorized personnel based on business responsibilities. Practices may include role-based access, authentication controls, restricted administrative permissions, secure credentials, access monitoring, and periodic permission reviews. During onboarding, we may verify applicant, business, ownership, and other relevant information.
Fraud prevention
We may review application and account information for identity discrepancies, inconsistent information, suspicious activity, unusual transaction patterns, potential account misuse, and chargeback-related risk indicators. Additional review or verification may be required before processing is approved.
Website and infrastructure security
Our website and online systems are maintained with secure connections, authentication controls, administrative restrictions, software maintenance, security updates, monitoring, vulnerability management, backup, recovery, and controlled access to sensitive systems.
Third-party service providers
Payment operations may involve processors, acquiring institutions, gateways, banks, cloud infrastructure, identity-verification providers, fraud-prevention services, communication providers, and software providers. These providers maintain their own security programs, policies, and contractual responsibilities.
Merchant responsibilities
Security is shared. Merchants should use strong unique passwords, keep credentials confidential, enable available security features, restrict employee access, remove former-employee access, update systems, avoid sending sensitive information through email, never share authentication codes, use approved payment methods, and understand applicable PCI DSS obligations.
Security monitoring and incident response
If a potential incident is identified, appropriate procedures may include identification, containment, investigation, remediation, partner coordination, legally required notification, and prevention improvements. Security processes evolve as threats, technologies, and business requirements change.
Protecting sensitive information
Never send passwords, online-banking credentials, authentication codes, payment PINs, complete card numbers, CVV/CVC codes, or account security answers through ordinary email. If you receive a suspicious communication claiming to represent Zivora, contact us through official website information.
Report a security concern
If you believe your account, business information, or interaction with Zivora may have been compromised, contact us promptly. Do not include highly sensitive credentials in your email.
Our security commitment
Trust is fundamental to payment services. We continuously review our technology infrastructure, access controls, onboarding procedures, payment-processing relationships, information-handling practices, and fraud-prevention measures to support a secure and responsible environment.