Safari Portal's Credit Card Authorization feature is designed to securely collect and store client payment details while minimizing your PCI compliance burden. Below are answers to some of the most common questions about how card data is handled.
Where is card data stored?
When a client enters their credit card details into a Safari Portal form, the information is never stored in Safari Portal's database.
Instead, card details are securely captured and stored by PCI Vault (pcivault.io), a PCI DSS Level 1 certified provider specializing in secure card tokenization and encrypted payment data storage.
Safari Portal stores only:
- A secure token referencing the card
- Cardholder name
- Card expiry date
- Last four digits of the card number
The full card number is never written to Safari Portal's database.
How are card numbers displayed?
Throughout Safari Portal, card numbers are displayed in truncated format, showing only the last four digits.
This means Safari Portal is not storing the full card number locally and simply masking a portion of it. The full card number is stored securely within PCI Vault's PCI DSS Level 1 certified environment.
For cases whose workflow requires manually entering the card into a host agency system or supplier portal, authorized users can securely retrieve the full card number from PCI Vault when needed.
Is card data encrypted?
Yes. Cardholder data is encrypted at rest within PCI Vault's PCI DSS Level 1 certified environment.
Because Safari Portal stores only a secure token rather than the full card number:
- Full card numbers do not exist within Safari Portal's database.
- Safari Portal engineers cannot retrieve full card numbers from Safari Portal's database.
- Full card details remain within PCI Vault's secure cardholder data environment.
- Access to card details is controlled through PCI Vault's secure infrastructure and Safari Portal's authorization controls.
Is Safari Portal PCI compliant?
Safari Portal relies on PCI Vault's PCI DSS Level 1 certified environment for the capture, tokenization, and storage of cardholder data.
PCI Vault maintains the secure cardholder data environment and provides the applicable Attestation of Compliance (AOC) covering card storage and tokenization.
Is card data encrypted at rest, and who can access it?
Yes. All full cardholder data is encrypted at rest within PCI Vault's PCI DSS Level 1 certified environment.
Safari Portal does not store full card numbers in its own database. Safari Portal stores only the tokenized and truncated card information described above.
Access to individual account encryption keys is strictly limited to a small number of senior technical leaders within Safari Portal and is governed by strict internal security controls.
Authorized Safari Portal users may retrieve card details through the application when required for legitimate business purposes, subject to the permissions and security controls associated with their account.
What PCI requirements apply to my company?
The PCI obligations that apply to your company depend on your own payment workflow.
Factors such as:
- How payment information is collected
- How card details are used
- Where payment is ultimately processed
- Your acquiring bank's requirements
all influence which PCI Self-Assessment Questionnaire (SAQ) or other compliance requirements may apply.
Because every business operates differently, Safari Portal cannot determine which SAQ is appropriate for your organization.
However, we can provide the technical details your acquirer or compliance advisor may require, including:
- Where card details are captured
- Where card data is stored
- Who is responsible for securing the cardholder data environment
- What information is stored and visible within Safari Portal
- How authorized users retrieve card details when required
If your compliance provider has additional technical questions, our team is happy to assist.
Keywords: Credit Card Authorization, Credit Card Forms, Card on File, PCI Compliance, PCI DSS, PCI Vault, PCI Level 1, Tokenization, Credit Card Security, Payment Security, Card Data Protection, Encrypted Card Storage, CVV, Attestation of Compliance, AOC, PCI SAQ, Payment Processing, Secure Payment Collection, Travel Agency Payments, Safari Portal Payments
