Skip to main content
NewChargeback Protection + Fee Intelligence for high-volume merchants. Get a savings analysis and a review of your dispute handling.See how it works
Details

Chargeback Protection + Fee Optimization

See how it works: high-volume merchants get automated dispute evidence, interchange optimization, and real-time savings visibility.

See how it works

Enterprise payment infrastructure with due diligence support

An enterprise payment decision is made in security review, procurement and legal rather than at the counter. RapidCents publishes the material those reviewers need — a security statement, the PCI DSS scope and SAQ mapping, a data processing addendum and the subprocessor categories — and holds PCI DSS Level 1 service provider status covering its own environment. Commercial terms can be negotiated as a custom master agreement, and migration runs in waves with a parallel period and a reconciliation checkpoint before each next wave.

  • Canadian specialists
  • Interchange-plus available
  • Guided migration
  • Post-launch support

Who this solution is for

  • Security and vendor risk reviewers

    Reviewers work through where cardholder data goes, who else touches it and what governs its processing. Those answers are published rather than emailed on request.

  • Procurement and legal

    Commercial terms, the subprocessor list and the split of responsibility between platform and customer are contractual questions, not sales questions.

  • The team that will run the migration

    Whoever owns the cutover needs a sequence, a rollback position and a parallel period before a contract is signed, not after.

Common challenges

  • Diligence answered piecemeal

    A questionnaire answered over several weeks by several people produces inconsistencies that reviewers then have to chase.

  • An estate nobody documented

    Terminals nobody can account for, a gateway integration written by someone who left, stored credentials whose portability was never tested.

  • Cutover with no rollback

    A migration planned as a single switch has nowhere to retreat to. The plan needs a parallel period in which both routes work.

The RapidCents approach

  1. Start at the Trust Centre so security review can read the material directly instead of waiting on a response.

  2. Document the current estate: acceptance channels, devices, integrations, stored credentials and every contract end date.

  3. Run commercial and contractual review alongside technical planning rather than after it.

  4. Build the migration sequence around a parallel period, with defined criteria for proceeding to the next wave.

  5. Cut over in waves with a single implementation contact, keeping the previous route available until each wave reconciles.

Recommended capabilities

  • Trust Centre documentation

    The Security Statement, the PCI DSS scope and SAQ mapping, the data processing addendum, the privacy policy, the accessibility statement, the vulnerability disclosure route and the subprocessor categories with what each is engaged to do and what it can reach — published for a reviewer to work through directly. The subprocessors page also publishes the register naming the individual providers it evidences. The Attestation of Compliance, and the current full list of providers, are provided on request by the routes those pages set out.

  • PCI DSS Level 1 service provider status

    Maintained through on-site audit, vulnerability scanning and penetration testing. It covers the RapidCents environment; your own validation remains yours.

  • Documented data handling

    Card numbers are replaced with tokens at capture. Card verification values, PINs, EMV chip data and magnetic-stripe data are not stored at all. AES-256 at rest, TLS 1.2 in transit, with older protocol versions deactivated.

  • Custom master agreement

    Commercial terms negotiated rather than accepted as posted, for organizations whose legal review requires it.

  • Dedicated implementation

    A single implementation contact through discovery, parallel running and each cutover wave.

Implementation approach

  • Discovery and estate audit

    Every device, integration and stored credential documented, including the ones nobody has touched in years. This is where a migration gets its real timeline.

  • Security and procurement review

    Diligence runs in parallel with technical planning, so neither becomes the other’s blocker.

  • Parallel processing period

    Both routes live at once. New volume moves to RapidCents while the previous route stays available and reconcilable.

  • Waved cutover and post-launch review

    Sites or channels move in defined waves, each with a reconciliation checkpoint before the next begins.

What does not change

  • Your own PCI validation

    The RapidCents status covers the RapidCents environment. Your networks, staff, devices and integration stay in your scope, and your annual validation stays your obligation.

  • Your ERP and general ledger

    Settlement detail exports into the accounting structure you already run. Migration does not require a chart of accounts change.

  • Existing certified integrations

    Where your POS or ERP already holds a certification, the integration is a configuration exercise rather than a rebuild.

Frequently asked questions

What can a security reviewer read before we sign anything?

The Trust Centre gathers the published material in one place: the Security Statement, the PCI DSS scope and SAQ mapping, the data processing addendum, the privacy policy, the accessibility statement, the vulnerability disclosure route, and the subprocessor categories with what each can reach. Section 9 of the subprocessors page publishes the register naming the individual providers it evidences, and says in terms that the register is not the whole supply chain. Two things are provided on request rather than published — the Attestation of Compliance, and the current full list of providers — and the PCI compliance page and the subprocessors page each set out how to ask. The security page states the encryption in use, the retention position and the boundary between RapidCents controls and yours.

Does the RapidCents compliance status cover us?

No, and a provider claiming otherwise is worth a second look. RapidCents is a PCI DSS Level 1 service provider, which covers its own environment. Your validation depends on how you accept payments and remains your obligation.

What happens to stored cards when we migrate?

Portability depends on the outgoing provider and the networks involved. Some token sets can be migrated and some cannot, and the customers behind the second group have to be re-collected. Establishing which case applies is the first task in discovery, because it changes the plan more than anything else does.

How long is the parallel period?

Long enough for each wave to produce a full settlement cycle that reconciles. It is defined by reconciliation checkpoints rather than by a date, because the point is the evidence rather than the calendar.

Can the agreement be negotiated?

A custom master agreement is available where legal review requires it. In practice the clauses most often negotiated are liability, term length, and the notice and transition provisions that apply at exit.

How is cardholder data retained?

Cardholder data is retained for up to 24 months of inactivity, encrypted where held. Card verification values, PINs, EMV chip data and magnetic-stripe data are not stored at all, in any form.

Who is accountable for the cutover on the RapidCents side?

A single implementation contact carries it through discovery, the parallel period and each cutover wave, rather than a support queue picking up whatever arrives. That contact also defines the reconciliation checkpoint each wave has to clear before the next one starts.

What does the estate audit have to cover before a timeline exists?

Every acceptance channel, device, integration and stored credential, plus every contract end date — including the terminals nobody can account for and the gateway integration written by someone who left. A timeline built before that documentation exists is an estimate of an unknown estate.

Take the next step

Talk to a RapidCents specialist

RapidCents Fee Check reads a processing statement and shows interchange separately from the markup. Upload a statement for an instant breakdown, or open a merchant account and start accepting payments on one account.

  • No obligation
  • Canadian payment specialists
  • Secure statement upload