Terms

247Debit.com performed the required policies and procedures to validate compliance with the Payment Card Industry (PCI) Data Security Standard supported by all the major credit card associations including: American Express, Diners Club, Discover, JCB, MasterCard International, Visa International and Visa USA.  All data transmitted and/or processed through 247Debit is done so in accordance with the Payment Card Industry (PCI) Data Security Standard and best practices. Trustwave's Trusted CommerceSM service designation indicates that 247Debit protects credit card and order information in accordance with payment card industry best practices.

SECURITY MEASURES & PREVENTIONS

Payment Card Industry EPP Security Requirements

The miniTeller® uses tamper detection and response mechanisms which cause the miniTeller® to become immediately inoperable and results in the automatic and immediate erasure of any secret information which may be stored in the miniTeller®. These mechanisms protect against physical penetration of the device by means of (but not limited to) drills, lasers, chemical solvents, opening covers, splitting the casing (seams) and using ventilation openings and there is not any demonstrable way to disable or defeat the mechanism and insert a pin disclosing bug or gain access to secret information.

PIN entry is accompanied by audible tones, then the tone for each entered PIN digit is indistinguishable from the tone for any other entered PIN digit.

There is no feasible way to determine any entered PIN digit by monitoring sound, electro-magnetic emissions, power consumption or any other external characteristic available for monitoring

The miniTeller® performs a self-test upon start up and at least once per day to check firmware, security mechanisms for signs of tampering, and whether the miniTeller® is in a compromised state. In the event of a failure, the miniTeller® and it functionality fails in a secure manner.

Sensitive information shall not be present any longer or used more often than strictly necessary. The miniTeller® must automatically clear its internal buffers when either:

The PIN is encrypted within the miniTeller® immediately after PIN entry is complete and has been signified as such by the cardholder. The clear text PIN must then be immediately erased after encryption is complete.

The PIN encryption technique implemented in the miniTeller® is a technique Included in ISO 9564.

The key-management techniques implemented in the miniTeller® conform to ISO 11568 and/or ANSI X9.24.

It is not possible to encrypt or decrypt any arbitrary data using any PIN encrypting key or key encrypting key contained in the miniTeller®.

DEVICE MANAGEMENT DURING MANUFACTURING

Payment Card Industry EPP Security Requirements

The miniTeller® manufacturer, subject to Association site inspections, confirms the following: