Has anyone decided not to store credit cards? Just wondering how you would research charge backs?
Are you referring solely to storing them in Tessitura?I assume you should still be able to research this in the TPA Client given the proper credentials.
Maybe this isn't even possible in Tessie? Unless you purged the credit card data on a daily basis?
There is a t_default for it, though it sounds like you would probably start with a purge.
CC_STORE_ACCOUNT (added v7.0) If this is set to No, then credit card information will not automatically be stored in T_ACCOUNT_DATA when a new card is used for a constituent in an order or contribution. Also, entry of credit card information into the Customer Accounts window is disabled. Credit cards already in T_ACCOUNT_DATA can still be selected from the Customer Accounts window and can be added and edited in the constituent record. The default setting is ‘Yes’.
Yes, is that possible? Trying to remove any possibility of a breach.
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Ryan RowellSent: Monday, August 08, 2011 5:33 PMTo: Gloria OrmsbySubject: Re: [Tessitura Technical Forum] Anyone NOT storing credit cards?
From: Gloria Ormsby <bounce-gloriaormsby5026@tessituranetwork.com>Sent: 8/8/2011 4:25:12 PM
This message was sent automatically to you by www.tessituranetwork.com because you subscribed to the Tessitura Technical Forum. You may reply to this message to post to the Technical forum or visit the site to search, read and post to the forums. In the interest of keeping the forum posts from becoming cluttered, we encourage you to delete previous message text from your reply before sending. Thank you!
I assume those actions in Tessitura would not affect transcend and the ability to get that information out of the TPA Client, but you might want to double check with Intrix support or open a TASK ticket.
Intrix Support infoE-mail support (support@intrix.com)Telephone Support (1-800-5INTRIX, option 1)
Thanks Ryan. This is very helpful!
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Ryan RowellSent: Monday, August 08, 2011 5:39 PMTo: Gloria OrmsbySubject: Re: [Tessitura Technical Forum] Anyone NOT storing credit cards?
There is a t_default for it
From: Gloria Ormsby <bounce-gloriaormsby5026@tessituranetwork.com>Sent: 8/8/2011 4:30:11 PM
Hi Gloria,
We don't store credit cards in Tessitura at Yale, and we use Transcend to research charge backs and other questions about credit card payments.
Does removing credit cards from Tessitura change your PCI SAQ level? How is it any different to store them in TranScend? This is a very interesting topic....
I think it depends on your setup. At Yale, before we moved onto RAMP, we had our credit card server on a separate network, behind our PCI firewall. Our Tessitura database server was on our main network. So removing the credit cards from Tessitura and keeping them in Transcend had a huge impact on the results of our self-assessment.
Now that we are on RAMP, it probably doesn't really make a difference, but we have not really revisited our setup since then.
Woah... my curiousity is piqued! Before I start running some tests, how did purging credit cards affect your ability to do credit card auto billing?
We don’t do any kind of auto-billing. I don’t think it’s possible to do auto-billing without storing credit cards.
Auto-billing functionality is possible only if you store credit cards.
+Ryan Creps
+Tessitura Network
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Mara Hazzard-WallingfordSent: Thursday, August 18, 2011 3:43 PMTo: Ryan CrepsSubject: RE: [Tessitura Technical Forum] Anyone NOT storing credit cards?
I figured that was the answer, but a girl can dream...
I was just thinking about this on the drive in, oddly enough (what can I say, Chicago traffic is boring). There wouldn’t be any way to strip out credit cards of everyone EXCEPT those with active pledges or payment plan auto-billing cycles, would there?
Jeanne
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Ryan Creps Sent: Thursday, August 18, 2011 2:53 PM To: Jeanne DeVore Subject: RE: [Tessitura Technical Forum] Anyone NOT storing credit cards?
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Mara Hazzard-Wallingford Sent: Thursday, August 18, 2011 3:43 PM To: Ryan Creps Subject: RE: [Tessitura Technical Forum] Anyone NOT storing credit cards?
Sure, you can exclude those people from the cc purge utility, but even storing one encrypted cc # means the entire db needs to go behind a PCI firewall, which for us means everything is in scope.