Skip to main content
NewChargeback Protection + Fee Intelligence for high-volume merchants. Get a savings analysis and a review of your dispute handling.See how it works
Details

Chargeback Protection + Fee Optimization

See how it works: high-volume merchants get automated dispute evidence, interchange optimization, and real-time savings visibility.

See how it works

COMPANY

Trust Centre

The Trust Centre publishes what a security or procurement review works through, rather than emailing it case by case. A review runs along four lines: evidence about the PCI DSS Level 1 processing environment, validated annually; the data flow, since hosted checkout and Rapid.js keep full card numbers out of merchant systems and that decides everything else; the supply chain, meaning the subprocessor categories, the published register naming each provider and the data processing terms; and the response path, a published vulnerability disclosure programme with a security contact.

  • Evidence about the processing environment
  • Data flow before anything else
  • Subprocessors and where data sits
  • Data processing terms

Watch how it works…Try it, edit values and click buttons

Edit amount and click Send requestSending request to /v1/payments…201 Created, payment approved for 24900 cents

API request

POST /v1/payments
{
  "amount": 24900,
  "currency": "USD",
  "capture": true,
  "metadata": { "order_id": "4821" }
}

Response

Click "Send request" to see the API response

Processing payment…

201 Created
{ "id": "pay_7xK2m", "status": "approved", "amount": 24900 }

Demonstration data only

In detail

  • Evidence about the processing environment

    PCI DSS Level 1 validation covers the systems that touch cardholder data and is renewed annually. A reviewer should be reading evidence about that environment, not a marketing claim about it.

  • Data flow before anything else

    Hosted checkout and Rapid.js keep full card numbers out of merchant systems. Establish that first, because it decides the scope of every other question in the review.

  • Subprocessors and where data sits

    The subprocessors page sets out the categories that support the infrastructure, what each is engaged to do and what it can reach; section 9 of that page publishes the register naming the individual providers, and sets out the route for obtaining the current full list. It is the question most vendor questionnaires ask twice in different words.

  • Data processing terms

    The data processing addendum is the processing terms in writing, and it divides the work activity by activity: what RapidCents does on a merchant’s instruction as its processor, and what it does on its own account as a controller. It is written to the privacy legislation that binds RapidCents rather than to the GDPR, so it offers no standard contractual clauses. The privacy policy covers how personal information is collected, used and protected for merchants and site visitors.

  • Vulnerability disclosure

    A published responsible disclosure programme and a security contact, so a researcher or a customer’s security team has a route that does not depend on finding the right inbox.

  • Accessibility and commercial terms

    Reviews routinely cover accessibility conformance on public surfaces and the terms governing the merchant relationship. Both are published rather than produced on request.

Questions about Trust Centre

What will you provide for our vendor questionnaire?

Evidence about the processing environment in the form of the Attestation of Compliance for the PCI DSS Level 1 validation, the security statement describing the controls in force, the subprocessor register naming each provider with what it is engaged to do, together with the current full list, the data processing addendum, the privacy policy, the accessibility statement and the vulnerability disclosure route. Most of that is published, so a reviewer can start reading before anyone is on a call.

Where does the platform run, and what happens to backups?

On redundant virtual environments across cloud data centres, whose providers operate backup power generation and dual-path power distribution, run continuous on-site surveillance and restrict physical access to key personnel through multi-factor controls including biometrics. Databases are backed up daily, both between data centres and offsite. The subprocessors page sets out the infrastructure and hosting category and what it can reach, and section 9 of that page publishes the register naming the providers it evidences, states in terms that the cloud data centre providers behind the platform are not among them, and sets out the route for obtaining the current full list.

What monitoring and network controls are in place?

Intrusion detection and intrusion prevention run at the firewall and locally on every server, screening traffic for suspicious behaviour, abnormal volumes and malicious code, with the prevention layer acting rather than only recording. Server firewalls default to deny-all, so a connection is refused unless a reviewed rule permits it. Servers are hardened and patched, major vulnerabilities are addressed without delay under change control, and there is no wireless access to the platform environment.

What governs personal information, and how long is it kept?

The privacy policy covers collection, use and protection under PIPEDA, and the data processing addendum is the processing terms in writing, which clause 19 of that addendum records as applying to every merchant and binding RapidCents without a separate signature. A designated Privacy Officer is accountable for compliance with the policy and for answering requests and complaints, reachable at the North York address or on +1 (844) 957-2743. Cardholder data is retained for up to 24 months of inactivity; identity and onboarding records are held for the period anti-money-laundering legislation requires.

Do you meet an accessibility standard?

Public marketing surfaces target WCAG 2.2 AA conformance, and the accessibility statement is published with the rest of the legal set. A document in an alternate format, or feedback about a barrier, can be requested through the contact page, by telephone on +1 (844) 957-2743, by mail, or in person at the North York address. Feedback can be left anonymously, though a reply needs a way to reach you.

Take the next step

Talk to a RapidCents specialist

RapidCents Fee Check reads a processing statement and shows interchange separately from the markup. Upload a statement for an instant breakdown, or open a merchant account and start accepting payments on one account.

  • No obligation
  • Payment specialists, not a call centre
  • Secure statement upload