Alpha Software Mobile Development Tools:   Alpha Anywhere    |   Alpha TransForm subscribe to our YouTube Channel  Follow Us on LinkedIn  Follow Us on Twitter  Follow Us on Facebook

Announcement

Collapse

The Alpha Software Forum Participation Guidelines

The Alpha Software Forum is a free forum created for Alpha Software Developer Community to ask for help, exchange ideas, and share solutions. Alpha Software strives to create an environment where all members of the community can feel safe to participate. In order to ensure the Alpha Software Forum is a place where all feel welcome, forum participants are expected to behave as follows:
  • Be professional in your conduct
  • Be kind to others
  • Be constructive when giving feedback
  • Be open to new ideas and suggestions
  • Stay on topic


Be sure all comments and threads you post are respectful. Posts that contain any of the following content will be considered a violation of your agreement as a member of the Alpha Software Forum Community and will be moderated:
  • Spam.
  • Vulgar language.
  • Quotes from private conversations without permission, including pricing and other sales related discussions.
  • Personal attacks, insults, or subtle put-downs.
  • Harassment, bullying, threatening, mocking, shaming, or deriding anyone.
  • Sexist, racist, homophobic, transphobic, ableist, or otherwise discriminatory jokes and language.
  • Sexually explicit or violent material, links, or language.
  • Pirated, hacked, or copyright-infringing material.
  • Encouraging of others to engage in the above behaviors.


If a thread or post is found to contain any of the content outlined above, a moderator may choose to take one of the following actions:
  • Remove the Post or Thread - the content is removed from the forum.
  • Place the User in Moderation - all posts and new threads must be approved by a moderator before they are posted.
  • Temporarily Ban the User - user is banned from forum for a period of time.
  • Permanently Ban the User - user is permanently banned from the forum.


Moderators may also rename posts and threads if they are too generic or do not property reflect the content.

Moderators may move threads if they have been posted in the incorrect forum.

Threads/Posts questioning specific moderator decisions or actions (such as "why was a user banned?") are not allowed and will be removed.

The owners of Alpha Software Corporation (Forum Owner) reserve the right to remove, edit, move, or close any thread for any reason; or ban any forum member without notice, reason, or explanation.

Community members are encouraged to click the "Report Post" icon in the lower left of a given post if they feel the post is in violation of the rules. This will alert the Moderators to take a look.

Alpha Software Corporation may amend the guidelines from time to time and may also vary the procedures it sets out where appropriate in a particular case. Your agreement to comply with the guidelines will be deemed agreement to any changes to it.



Bonus TIPS for Successful Posting

Try a Search First
It is highly recommended that a Search be done on your topic before posting, as many questions have been answered in prior posts. As with any search engine, the shorter the search term, the more "hits" will be returned, but the more specific the search term is, the greater the relevance of those "hits". Searching for "table" might well return every message on the board while "tablesum" would greatly restrict the number of messages returned.

When you do post
First, make sure you are posting your question in the correct forum. For example, if you post an issue regarding Desktop applications on the Mobile & Browser Applications board , not only will your question not be seen by the appropriate audience, it may also be removed or relocated.

The more detail you provide about your problem or question, the more likely someone is to understand your request and be able to help. A sample database with a minimum of records (and its support files, zipped together) will make it much easier to diagnose issues with your application. Screen shots of error messages are especially helpful.

When explaining how to reproduce your problem, please be as detailed as possible. Describe every step, click-by-click and keypress-by-keypress. Otherwise when others try to duplicate your problem, they may do something slightly different and end up with different results.

A note about attachments
You may only attach one file to each message. Attachment file size is limited to 2MB. If you need to include several files, you may do so by zipping them into a single archive.

If you forgot to attach your files to your post, please do NOT create a new thread. Instead, reply to your original message and attach the file there.

When attaching screen shots, it is best to attach an image file (.BMP, .JPG, .GIF, .PNG, etc.) or a zip file of several images, as opposed to a Word document containing the screen shots. Because Word documents are prone to viruses, many message board users will not open your Word file, therefore limiting their ability to help you.

Similarly, if you are uploading a zipped archive, you should simply create a .ZIP file and not a self-extracting .EXE as many users will not run your EXE file.
See more
See less

payment gateway help needed

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    payment gateway help needed

    Hi,
    I'm trying to move away from paypal to another company; anyone have any suggestions on what company is easy (and cheap) to integrate with Alpha5?

    Ideally I want to process an entire order on one grid... i.e. user enters their information, items, credit card details. Does anyone have any idea/sample to show how to do this, and what credit card company you are using...?

    Thanks
    Lee

    #2
    Re: payment gateway help needed

    Lee:

    Are you wanting to have the customers enter their credit card info on your site (A5) or on a gateway providers site (like PayPal does)? I highly suggest the later for web based sales to reduce your PCI compliance requirements considerably. If your website NEVER has the credit card information and it is only on a PCI certified gateway then your compliance requirements are nominal. On the other hand if you intend to capture the credit card data on your own site then you need a different PCI SAQ including network scans, access logs, at rest encryption etc.

    Depending on your location there are numerous gateways which are certified and will work with a merchant account of your choosing. You can simply Google for gateway providers and find one which fits your specific needs and budget. You will need both types of accounts regardless if the transactions are entered on your site on on the gateway providers site. I use a local gateway provider in the Chicago, IL area as well as a merchant ISO which is also local. My configuration does not process payments on a website as most of our transactions occur face to face and are swiped into an encrypted swiping device (manually keyed transactions are also encrypted at the hardware device) for which we do not have the decryption keys. This removes the majority of the PCI compliance issues since we do not have "sensitive card data" on our servers. Although I have debated allowing customers to pay online I have not implemented the simple link to our gateway provider yet due to security concerns and the integration with our A5 accounting system.

    Hope this helps

    Brad

    Comment


      #3
      Re: payment gateway help needed

      Brad thanks a ton for this information. If the credit card gateway is in a DIV with a link to the gateways site, does this PCI compliant... this is all new to me and really appreciate your advice.
      thanks
      Lee

      Comment


        #4
        Re: payment gateway help needed

        Lee:

        You will want to check the different certification requirements https://www.pcisecuritystandards.org for the different SAQ types. If your lucky you will be able to use SAQ A which is pretty simple. However if any credit card data is stored (this means card number aka PAN, expiration date, etc) you will require a minimum of SAQ C with vulnerability scans. If your gateway is certified PCI compliant and on the list at the above link then you will want to construct your A5 pages to not store credit card information - you can store last 4 digits & card type with auth # / transaction #. You should use the interface provided by the gateway to research payments and to perform any recurring transactions if you have them.

        The less you keep in your system the better and easier compliance will be. It should be noted that you are still required to complete the appropriate SAQ even if your card processing is fully outsourced.

        Brad

        Comment


          #5
          Re: payment gateway help needed

          This is a good and relevant issue. We have a site that accepts credit card payments and it uses the authorize.net process that ships with Alpha Five. We do not store any cardholder information and the site is SSL encrypted. In reviewing the security requirements for PCIsecuritystandards, the question I have is whether or not the authorize.net process within Alpha Five is PCI DSS certified.
          Can anyone answer that?

          Mike
          Mike Reed
          Phoenix, AZ

          Comment


            #6
            Re: payment gateway help needed

            Hi Lee,

            We have just got our site up and running and are using Sage Pay. There is no need for PCI compliance as they are already covered and no credit card details are stored in the application. Their set up fee is very reasonable as are the transaction costs.

            They also supply kits to enable you to link to the gateway with the required data.
            Regards
            Keith Hubert
            Alpha Guild Member
            London.
            KHDB Management Systems
            Skype = keith.hubert


            For your day-to-day Needs, you Need an Alpha Database!

            Comment


              #7
              Re: payment gateway help needed

              Mike:

              Below is my understanding -

              If your customer logs into authorize.net directly and no credit card data ever resides on your network (even in RAM memory) then SAQ A is appropriate but still required. If at any time the data is on your computer (or network) then I believe you require SAQ C with scans. This is true even though authorize.net is PCI compliant as a gateway.

              You may want to check http://www.authorize.net/resources/pcicompliance/ for helpful information.

              If you are formatting the data to perform an http post to authorize.net using A5 or any other software I believe that would require SAQ C.

              Brad

              Comment


                #8
                Re: payment gateway help needed

                Keith:

                Are you formatting the "data" for Sage Pay? If yes then my reading of the PCI says you need to answer the PCI SAQ and scans as appropriate even though you are not storing the card information. If on the other hand all processing/formatting is 3rd party then as I indicated above you should be able to use SAQ A. Ultimately it is your merchant account with a third party gateway - you must be PCI compliant in addition to the third party. The requirements under SAQ A are pretty easy to fulfill.

                See also my response to Mike above.

                Brad

                Comment


                  #9
                  Re: payment gateway help needed

                  Thanks I really appreciate all the help and guidance... What would I do without this forum? (probably fall flat on my face..).
                  @Keith... how easy was it to setup sage pay? are you able to show me and example of how you did it? I'm trying to avoid having the user go to too many different pages, but stay on the same site...
                  do you know if Sage payments can integrate via a DIV or does it go directly to their site?

                  Comment


                    #10
                    Re: payment gateway help needed

                    Lee,

                    Our site requires data input first from the user, they are then taken to a cart page for confirmation of the T & Cs and amount. They then are directed to Sage for the actual payment.

                    Sage is a little tricky to set up but as I got some great help from this forum when you are ready let me know.
                    Regards
                    Keith Hubert
                    Alpha Guild Member
                    London.
                    KHDB Management Systems
                    Skype = keith.hubert


                    For your day-to-day Needs, you Need an Alpha Database!

                    Comment


                      #11
                      Re: payment gateway help needed

                      Keith:

                      Thought you might want to check http://www.sagepay.com/pci-dss-compliance. Even when using Sage Pay you must be PCI compliant yourself (at least SAQ A) as they describe.

                      Brad

                      Comment


                        #12
                        Re: payment gateway help needed

                        Hi Keith:
                        I'm ready to learn more about this. I called SagePay and they went over an application with me... the claim it is easy to integrate with A5; although i got the feeling he may have been 'blowing smoke' to get me to signup!.
                        Before I do signup I wanted to get an idea of how the integration is. Do you have any examples that i could take a quick peek at? (fee free to PM me if you want to send links/urls etc). Ideally, i'd like to use sage pay as an InFrame sort of an payment solution, but trying to find out if possible/more information.

                        Brad thanks for the help/info on PCI compliance--definitely a new topic for me.

                        Lee

                        Comment


                          #13
                          Re: payment gateway help needed

                          Hi Keith
                          I guess 4 years on you are perhaps well versed in sage pay, I have signed up but am somewhat bewildered.
                          My uX gathers all the relevant information for sage (no card details), but do not know the code for the button to redirect to the sage pay url i.e. The encrypted data and the actual url string format.
                          I am sure I will be able to build the return success & failure landing pages on return.
                          Perhaps you would be kind enough to let me see your code for this.
                          Thanks
                          Terry

                          Comment

                          Working...
                          X