Skip to main content

Security

Security designed into the payment flow.

Rainbow Pay designs its payment infrastructure and merchant integrations with payment security requirements in mind. Specific PCI DSS responsibilities depend on the service and integration architecture.

Secure architecture

Payment services are separated into environments, with sandbox and production isolated from each other and credentials issued per environment.

Payment data handling

Hosted payment flows let customers enter card details on a Rainbow Pay-hosted page rather than on the merchant's site, and callbacks carry masked card information only.

API authentication

Every API request is authenticated with a private key sent as a bearer token. Keys are issued per merchant and per environment and are meant for server-side use only.

Encrypted transport

The API accepts requests over HTTPS only; calls over plain HTTP fail. This website is served over HTTPS with strict transport security.

Access controls

Access to systems and data is limited to people who need it for their role.

Monitoring

Platform activity is monitored for operational and security events.

Secure development

Changes are reviewed before release, and secrets are kept out of source code.

Vulnerability management

Reported and discovered vulnerabilities are assessed and remediated according to their risk.

PCI DSS and your integration

The PCI DSS requirements applicable to a merchant depend on how payment data is collected, processed, stored and transmitted and on the merchant's integration architecture.

Hosted payment architectures may reduce the amount of payment data handled directly by a merchant. The merchant remains responsible for determining and validating its applicable PCI DSS obligations. A server-to-server integration that sends card data from your systems brings those systems into scope and requires Rainbow Pay's approval.

Responsible disclosure

If you believe you have found a security vulnerability in a Rainbow Pay service, please report it privately to security@rainbowpay.hk. Read our Responsible Security Disclosure policy before testing.

Never send card numbers, CVV codes, passwords or API keys by email or through any form on this website.

Ready to discuss your payment setup?

Tell us how your business accepts payments today and what you need from your next payment integration.

Cookie preferences

Choose which optional cookies we may use. Strictly necessary cookies are always active because the website cannot work without them.

  • Strictly necessary

    Security, load balancing, form protection and remembering your cookie choice.

    Always active

Read the Cookie Policy