Trust Starts with Security
Protecting merchant data, payment information, and business continuity through secure infrastructure, industry best practices, and compliance-focused solutions.
Layered Security for Payment Processing
ONKORE applies layered security across infrastructure, access controls, monitoring, and software practices to help protect payment data and business operations.
Secure Infrastructure
Enterprise-grade infrastructure designed to protect payment data at every layer of processing.
Continuous Monitoring
Systems are monitored around the clock to detect and respond to potential threats.
Secure Authentication
Multi-factor authentication and access controls help protect account access.
Enterprise Architecture
Layered security controls built to support high-volume payment processing.
Understanding PCI Responsibilities
We help merchants understand their PCI responsibilities. Requirements vary depending on payment acceptance methods. ONKORE does not certify compliance on behalf of merchants.
PCI DSS Overview
The Payment Card Industry Data Security Standard is a set of requirements for organizations that process, store, or transmit cardholder data.
Merchant Responsibilities
Merchants are responsible for validating their own PCI compliance based on payment acceptance methods and transaction volume.
SAQ Guidance
Self-Assessment Questionnaires help merchants validate compliance. The applicable SAQ depends on how you accept payments.
Compliance is determined by your acquirer, transaction volume, and how you capture and transmit cardholder data. Using tokenization, hosted checkout, or payment links where supported can help reduce your PCI scope. Contact ONKORE for guidance on your specific setup.
Protecting Data in Transit and at Rest
ONKORE uses industry-standard cryptography to help protect payment data throughout its lifecycle.
Encryption
Industry-standard cryptography protects sensitive payment data using strong encryption methods.
Transport Security
Data in transit is protected using TLS to help safeguard information as it moves between systems.
Secure Storage
Data at rest is encrypted to help protect stored information where applicable.
Reduce Exposure with Tokenization
Tokenization replaces sensitive card data with secure tokens, reducing the exposure of raw cardholder data across your systems.
Card Tokenization
Replace sensitive card data with tokens that have no value outside the ONKORE environment.
Reduced PCI Scope
Tokenization can help reduce the systems in scope for PCI assessment.
Secure Recurring Billing
Store tokenized payment methods for repeat and subscription billing without handling raw card data.
Responsible Data Handling
ONKORE is committed to responsible handling of merchant and customer data, with practices designed to protect privacy.
Customer Privacy
ONKORE handles customer and merchant data responsibly in accordance with its privacy practices.
Data Minimization
We collect and retain only what is necessary to provide and secure payment services.
Privacy Practices
Our privacy and terms documents explain how data is used and what rights users have.
Operational Resilience
ONKORE designs its infrastructure and processes for availability and resilience. Availability may vary depending on processor, gateway, and financial institution.
High Availability
Infrastructure is designed for availability to support payment processing continuity.
Operational Resilience
Redundant systems and processes help maintain operations during disruptions.
Backup & Redundancy
Backup strategies and redundancy are designed to support recovery objectives.
Security Event Response
When potential security events are identified, ONKORE follows defined processes for handling, investigation, communication, and recovery.
Security Event Handling
Defined processes guide how potential security events are identified and escalated.
Investigation Process
Events are investigated to understand scope, impact, and root cause.
Customer Communication
Affected merchants are notified in accordance with applicable requirements and agreements.
Recovery & Improvement
Recovery procedures are followed and lessons learned are applied to improve controls.
Responsible Disclosure Policy
ONKORE appreciates the efforts of security researchers. If you believe you have identified a potential vulnerability, please report it responsibly.
How to Report
Security researchers can report potential vulnerabilities to ONKORE's security contact with details about the issue.
Expected Information
Include a description of the issue, steps to reproduce, and potential impact so the team can assess it promptly.
Response Expectations
ONKORE reviews reports in a timely manner and works with researchers to validate and address confirmed issues.
Good-Faith Reporting
We ask researchers to act in good faith and avoid disrupting services or accessing data beyond what is necessary.
ONKORE does not currently offer a formal bug bounty program. We are committed to reviewing and addressing responsibly reported issues. Contact our security team at support@onkorepro.com.
Resources for Merchants
Explore guidance on PCI, security, fraud prevention, and chargeback management.
PCI Guidance
Resources to help you understand PCI responsibilities and reduce compliance scope.
Security Best Practices
Practical guidance for securing your payment environment and account access.
Merchant Compliance
What merchants need to know about validating and maintaining compliance.
Payment Security
How tokenization, encryption, and secure methods protect card data.
Industry Standards
Alignment with established payment security frameworks and standards.
Fraud Prevention
Tools and practices to help detect and reduce fraudulent transactions.
Chargeback Prevention
Strategies to reduce disputes and manage chargebacks effectively.
Certifications & Payment Ecosystem
ONKORE operates within the payment ecosystem through processing relationships, payment networks, and compliance frameworks. The information below is educational and does not imply official certification, endorsement, or partnership unless explicitly stated.
PCI DSS Guidance
ONKORE helps merchants understand their PCI DSS responsibilities. ONKORE does not certify merchant compliance.
Payment Networks
ONKORE processes transactions through established card networks (Visa, Mastercard, American Express, Discover) and bank networks (ACH, RTP, FedNow) where supported.
Processing Relationships
ONKORE works with acquiring banks and processing partners to facilitate payment acceptance. Specific relationships depend on your merchant setup and underwriting.
Compliance Frameworks
ONKORE aligns with established payment security frameworks and industry standards where applicable to its role as a payment services provider.
ONKORE does not display unauthorized bank names, processor names, partner logos, or certifications it does not possess. For specific partner or banking relationship inquiries, contact ONKORE directly.
Get in Touch
Have a security, compliance, or general question? Our team is here to help.
Security Questions
Questions about ONKORE security practices and infrastructure.
Email Security Team →Disclaimer: Security measures and available features may vary depending on payment processor, gateway, hardware, integration method, financial institution, and merchant configuration. ONKORE does not guarantee absolute security, zero fraud, zero breaches, or continuous uptime. No security system can eliminate all risk.
Trust & Security FAQs
Answers to common questions about ONKORE security and compliance.
Is ONKORE PCI compliant?
ONKORE helps merchants understand their PCI responsibilities. Compliance requirements vary depending on payment acceptance methods, transaction volume, and processor. ONKORE does not certify compliance on behalf of merchants — merchants are responsible for validating their own compliance using the applicable Self-Assessment Questionnaire (SAQ).
Does ONKORE guarantee zero breaches or fraud?
No security system can eliminate all risk. ONKORE applies layered security, encryption, tokenization, and monitoring to help protect payment data, but does not guarantee absolute security, zero fraud, zero breaches, or continuous uptime. Security measures may vary depending on processor, gateway, hardware, integration method, and merchant configuration.
How does tokenization reduce my PCI scope?
Tokenization replaces sensitive card data with tokens that have no value outside the ONKORE environment. By using tokens instead of storing raw card data, you can reduce the systems and processes in scope for PCI assessment. Using hosted checkout, payment links, or virtual terminal where supported can further reduce scope.
How do I report a security vulnerability?
Security researchers can report potential vulnerabilities to support@onkorepro.com with a description, steps to reproduce, and potential impact. ONKORE reviews reports in a timely manner and asks researchers to act in good faith. ONKORE does not currently offer a formal bug bounty program.
Have security questions?
Our team can help you understand PCI responsibilities and security options for your business.
