Security
Security designed into the payment flow.
Secure architecture
Payment data handling
API authentication
Encrypted transport
Access controls
Monitoring
Secure development
Vulnerability management
PCI DSS and your integration
The PCI DSS requirements applicable to a merchant depend on how payment data is collected, processed, stored and transmitted and on the merchant's integration architecture.
Hosted payment architectures may reduce the amount of payment data handled directly by a merchant. The merchant remains responsible for determining and validating its applicable PCI DSS obligations. A server-to-server integration that sends card data from your systems brings those systems into scope and requires Rainbow Pay's approval.
Responsible disclosure
If you believe you have found a security vulnerability in a Rainbow Pay service, please report it privately to security@rainbowpay.hk. Read our Responsible Security Disclosure policy before testing.
Never send card numbers, CVV codes, passwords or API keys by email or through any form on this website.
Ready to discuss your payment setup?
Tell us how your business accepts payments today and what you need from your next payment integration.