Customer Payment Methods

View and manage reusable customer payment methods within RevCent.

Customer Payment Methods represent a customer’s reusable ways to pay. The current UI replaces Customer Cards with Payment Methods, showing masked payment details, expiration, default status, and whether each method is enabled.

View Payment Methods

Open Customers > All Customers, select a customer, and scroll to Payment Methods on the customer details page. Start from Customers.

Customer Payment Methods

Payment Method Details

Click a payment method’s ID to open its details. To add a card, use Add Credit Card in the customer’s Payment Methods panel. A customer can have a default method within each payment category; the default card is separate from a default wallet or bank account.

Only display details are returned: full card numbers, security codes, complete bank-account numbers, and wallet credentials are not available through payment-method retrieval.

Payment Data Security

Our PCI DSS Level 1 certified infrastructure, enhanced monitoring and additional levels of security ensure that all data is safe.

PCI DSS Level 1

RevCent is a PCI DSS Level 1 service provider. All customer payment data is encrypted and stored in isolated air gapped networks. Human access to customer payment data is not possible, only programmatic access from specific resources. Access by RevCent employees is strictly forbidden, and in fact not possible through using identity based access.

Encryption

RevCent utilizes encryption for all communication, programmatic access and data storage. The web app, API and websocket are only accessible via HTTPS and TLS. Customer payment data is encrypted before stored and again encrypted at rest. Internal systems with separate access permissions ensure that encrypted data is never exposed when transmitted between resources, and only specific resources can decrypt the data.

Enhanced Monitoring

RevCent is hosted by AWS, which offers a suite of monitoring tools to detect and prevent malicious actors. Internal custom monitoring is also implemented.

AWS services we utilize include AWS WAF for all inbound requests, AWS Cloudtrail for logging account actions and access, AWS Shield for monitoring application traffic and AWS GuardDuty to monitor and detect threats using machine learning.

Serverless Infrastructure

RevCent’s entire infrastructure is built using serverless computing, which removes many traditional attack vectors. Security concerns associated with running servers such as IP and denial of service attacks are eliminated.

Serverless executions are also stateless, thus in-memory data is erased soon after execution. Every endpoint is protected by AWS WAF and routed via AWS API Gateway, which provides additional levels of enhanced security.