
When deciding on a provider it can be helpful to have a guideline and examples of questions to ask each company regarding safety. An online donation company's security and compliance are directly related to the safety of your organization and your donor's information.
Donation University has provided a list of topics and sample questions to help you quickly and accurately determine the level of safety offered.
- Are your forms secured by SSL Certificates?
- Who is your SSL Certificate Provider? (Ex. Verisign, Network Solutions, Thawte, GeoTrust, etc)
- Is your company PCI Compliant?
- Do you undergo quarterly scans?
- When was your last on-site audit performed?
- Who is your Independent Qualified Security Assessor?
Once you have the name of the independent assessor, you can check that company's authorization to perform PCI Audits against the official list of assessors provided by the PCI Security Standards Council. If the assessor is not on this list, they are not qualified to certify any company as PCI Compliant. Find the list by clicking here.
- Is your organization listed on the Visa Cardholder Information Security Program's (CISP) list of compliant providers?
- What about the MasterCard Site Data Program list of compliant providers?
If the online donation company is not listed with Visa's CISP program or MasterCard's Site Data Protection Program, their PCI Compliance may not be complete or may be under review. See Visa's CISP List (pdf link here) and MasterCard's Site Data Protection List.
At this time Discover and American Express do not maintain lists of certified providers.
