Skip to main content
Trust Center

Trust Starts with Security

Protecting merchant data, payment information, and business continuity through secure infrastructure, industry best practices, and compliance-focused solutions.

Security

Layered Security for Payment Processing

ONKORE applies layered security across infrastructure, access controls, monitoring, and software practices to help protect payment data and business operations.

Secure Infrastructure

Enterprise-grade infrastructure designed to protect payment data at every layer of processing.

Continuous Monitoring

Systems are monitored around the clock to detect and respond to potential threats.

Secure Authentication

Multi-factor authentication and access controls help protect account access.

Enterprise Architecture

Layered security controls built to support high-volume payment processing.

PCI DSS

Understanding PCI Responsibilities

We help merchants understand their PCI responsibilities. Requirements vary depending on payment acceptance methods. ONKORE does not certify compliance on behalf of merchants.

PCI DSS Overview

The Payment Card Industry Data Security Standard is a set of requirements for organizations that process, store, or transmit cardholder data.

Merchant Responsibilities

Merchants are responsible for validating their own PCI compliance based on payment acceptance methods and transaction volume.

SAQ Guidance

Self-Assessment Questionnaires help merchants validate compliance. The applicable SAQ depends on how you accept payments.

Compliance is determined by your acquirer, transaction volume, and how you capture and transmit cardholder data. Using tokenization, hosted checkout, or payment links where supported can help reduce your PCI scope. Contact ONKORE for guidance on your specific setup.

Encryption

Protecting Data in Transit and at Rest

ONKORE uses industry-standard cryptography to help protect payment data throughout its lifecycle.

Encryption

Industry-standard cryptography protects sensitive payment data using strong encryption methods.

Transport Security

Data in transit is protected using TLS to help safeguard information as it moves between systems.

Secure Storage

Data at rest is encrypted to help protect stored information where applicable.

Tokenization

Reduce Exposure with Tokenization

Tokenization replaces sensitive card data with secure tokens, reducing the exposure of raw cardholder data across your systems.

Card Tokenization

Replace sensitive card data with tokens that have no value outside the ONKORE environment.

Reduced PCI Scope

Tokenization can help reduce the systems in scope for PCI assessment.

Secure Recurring Billing

Store tokenized payment methods for repeat and subscription billing without handling raw card data.

Data Privacy

Responsible Data Handling

ONKORE is committed to responsible handling of merchant and customer data, with practices designed to protect privacy.

Customer Privacy

ONKORE handles customer and merchant data responsibly in accordance with its privacy practices.

Data Minimization

We collect and retain only what is necessary to provide and secure payment services.

Privacy Practices

Our privacy and terms documents explain how data is used and what rights users have.

Business Continuity

Operational Resilience

ONKORE designs its infrastructure and processes for availability and resilience. Availability may vary depending on processor, gateway, and financial institution.

High Availability

Infrastructure is designed for availability to support payment processing continuity.

Operational Resilience

Redundant systems and processes help maintain operations during disruptions.

Backup & Redundancy

Backup strategies and redundancy are designed to support recovery objectives.

Incident Response

Security Event Response

When potential security events are identified, ONKORE follows defined processes for handling, investigation, communication, and recovery.

Security Event Handling

Defined processes guide how potential security events are identified and escalated.

Investigation Process

Events are investigated to understand scope, impact, and root cause.

Customer Communication

Affected merchants are notified in accordance with applicable requirements and agreements.

Recovery & Improvement

Recovery procedures are followed and lessons learned are applied to improve controls.

Responsible Disclosure

Responsible Disclosure Policy

ONKORE appreciates the efforts of security researchers. If you believe you have identified a potential vulnerability, please report it responsibly.

How to Report

Security researchers can report potential vulnerabilities to ONKORE's security contact with details about the issue.

Expected Information

Include a description of the issue, steps to reproduce, and potential impact so the team can assess it promptly.

Response Expectations

ONKORE reviews reports in a timely manner and works with researchers to validate and address confirmed issues.

Good-Faith Reporting

We ask researchers to act in good faith and avoid disrupting services or accessing data beyond what is necessary.

ONKORE does not currently offer a formal bug bounty program. We are committed to reviewing and addressing responsibly reported issues. Contact our security team at support@onkorepro.com.

Compliance Resources

Resources for Merchants

Explore guidance on PCI, security, fraud prevention, and chargeback management.

PCI Guidance

Resources to help you understand PCI responsibilities and reduce compliance scope.

Security Best Practices

Practical guidance for securing your payment environment and account access.

Merchant Compliance

What merchants need to know about validating and maintaining compliance.

Payment Security

How tokenization, encryption, and secure methods protect card data.

Industry Standards

Alignment with established payment security frameworks and standards.

Fraud Prevention

Tools and practices to help detect and reduce fraudulent transactions.

Chargeback Prevention

Strategies to reduce disputes and manage chargebacks effectively.

Certifications & Payment Ecosystem

Certifications & Payment Ecosystem

ONKORE operates within the payment ecosystem through processing relationships, payment networks, and compliance frameworks. The information below is educational and does not imply official certification, endorsement, or partnership unless explicitly stated.

PCI DSS Guidance

ONKORE helps merchants understand their PCI DSS responsibilities. ONKORE does not certify merchant compliance.

Payment Networks

ONKORE processes transactions through established card networks (Visa, Mastercard, American Express, Discover) and bank networks (ACH, RTP, FedNow) where supported.

Processing Relationships

ONKORE works with acquiring banks and processing partners to facilitate payment acceptance. Specific relationships depend on your merchant setup and underwriting.

Compliance Frameworks

ONKORE aligns with established payment security frameworks and industry standards where applicable to its role as a payment services provider.

ONKORE does not display unauthorized bank names, processor names, partner logos, or certifications it does not possess. For specific partner or banking relationship inquiries, contact ONKORE directly.

Security Contact

Get in Touch

Have a security, compliance, or general question? Our team is here to help.

Security Questions

Questions about ONKORE security practices and infrastructure.

Email Security Team →

Compliance Questions

Guidance on PCI responsibilities and compliance scope.

Email Compliance Team →

Merchant Support

Help with your account, processing, or integrations.

Contact Support →

Sales

Speak with our team about pricing and solutions.

Contact Sales →

General Contact

Any other questions about ONKORE services.

Get in Touch →

Disclaimer: Security measures and available features may vary depending on payment processor, gateway, hardware, integration method, financial institution, and merchant configuration. ONKORE does not guarantee absolute security, zero fraud, zero breaches, or continuous uptime. No security system can eliminate all risk.

FAQs

Trust & Security FAQs

Answers to common questions about ONKORE security and compliance.

Is ONKORE PCI compliant?

ONKORE helps merchants understand their PCI responsibilities. Compliance requirements vary depending on payment acceptance methods, transaction volume, and processor. ONKORE does not certify compliance on behalf of merchants — merchants are responsible for validating their own compliance using the applicable Self-Assessment Questionnaire (SAQ).

Does ONKORE guarantee zero breaches or fraud?

No security system can eliminate all risk. ONKORE applies layered security, encryption, tokenization, and monitoring to help protect payment data, but does not guarantee absolute security, zero fraud, zero breaches, or continuous uptime. Security measures may vary depending on processor, gateway, hardware, integration method, and merchant configuration.

How does tokenization reduce my PCI scope?

Tokenization replaces sensitive card data with tokens that have no value outside the ONKORE environment. By using tokens instead of storing raw card data, you can reduce the systems and processes in scope for PCI assessment. Using hosted checkout, payment links, or virtual terminal where supported can further reduce scope.

How do I report a security vulnerability?

Security researchers can report potential vulnerabilities to support@onkorepro.com with a description, steps to reproduce, and potential impact. ONKORE reviews reports in a timely manner and asks researchers to act in good faith. ONKORE does not currently offer a formal bug bounty program.

Have security questions?

Our team can help you understand PCI responsibilities and security options for your business.

Expert guidance
Compliance support
No long-term contracts
PCI Compliant Guided onboarding No long-term contracts