While Using Our Payment Gateway
You can integrate with the Razorpay Payment Gateway in 2 ways:- Standard Checkout
- Server To Server Checkout (PCI Compliant)
Standard Checkout
It is critical to ensure the security of your API keys and Dashboard credentials. Ensure that you store these details in safe places and only share them with trusted team members. Additionally, ensure that a customer’s payment information only reaches your servers if you are PCI DSS certified.Sensitive Data
Server To Server Checkout
Feature Request
- Be compliant with PCI DSS standards at all times.
- Share your PCI AOC (Attestation of Compliance) before every year’s expiration date for continued access to this integration method.
While Using RazorpayX
It is critical to ensure the security of your RazorpayX Dashboard credentials and API keys.Payouts
Follow the below security measures while making Payouts.- Ensure that no two fund accounts have the same
fund_account_id. - If you are not PCI-DSS compliant, you should not process your contact’s card details at your backend.
- Use the public Fund Account API to create a Fund account with type card. The public Fund Account API only needs your
. DO NOT send yourwhen making this API call, as you will expose this on your website. Know more about Payouts to Cards.