Statement about PCI compliance
QMerchant 2012 is **NOT** an 'off-the-shelf'
product. It is a toolbox or a framework that allows you
to create and implement your own bridge between the
various QuickBooks versions and the different payment
gateways. The individual customization and
implementation is done in the following three steps.
First, your choice of software during the download
process. Second the setup process individualizes and
implements the software for the specific Windows
operating system, the special QuickBooks version and
your choice of the payment gateway. This is based on
your requirements and decisions. The third step is
done with the software activation.
So, QMerchant 2012 is regarding PA-DSS a custom application, designed and developed to customer provided specifications. It is part of your normal PCI DSS compliance review.
Only three of the twelve PCI requirements are touched
by the QMerchant development we made for you:
Requirement 3: Protect stored cardholder data.
QMerchant does not store any cardholder data. The log file records the gateway response only that does only contain a masked cc number.
Requirement 4: Encrypt transmission of cardholder data across open, public networks.
QMerchant transmits the data to the payment gateway encrypted based on the security measures given by the payment gateway,
usually by https: encryption.
Requirement 10: Track and monitor all access to network resources and cardholder data.
QMerchant has a log, where the usage of QMerchant is recorded. Access to cardholder data is restricted by the QuickBooks security measures, if there are any
of those data stored in QuickBooks.
addQin is a trademark and service mark of netbusiness(dot)com.
QBAutomation is a trademark and service mark of netbusiness.com, Inc. since 2002.
*QuickBooks is a registered trademark and service mark of Intuit Inc. in the United States and other countries.
Authorize.Net is a registered trademark of Lightbridge, Inc.
All other marks are the property of their respective owners.