Compliance
Compliance
PCI, HIPAA, NACHA, and ACH authorization requirements for Cresora integrations.
Cresora is designed for compliance-first integrations. This section covers your obligations as a Partner integrating the platform.
Standards covered
| Standard | Cresora posture |
|---|---|
| PCI DSS | Cresora is PCI DSS validated as a service provider; the Attestation of Compliance (AoC) is available on request. Card data is entered on Cresora-served pages, never on yours. Which SAQ applies to your business is your QSA's call. |
| HIPAA | Cresora is HIPAA-aware for healthcare ISVs. See HIPAA guide →. |
| NACHA | ACH processing follows NACHA operating rules. See NACHA guide →. |
Where card data lives
Cresora exposes two integration surfaces, and neither puts a card number on your systems:
- Hosted page — the payer types card or bank details into a page Cresora serves (redirect or iframe). Nothing cardholder-related transits your server, logs or database. This is commonly the SAQ A shape.
- Saved-card charge — your server charges a card that is already saved with Cresora, by its
cvt_vault token, viaPOST /transactions. A raw card number posted to the API is rejected with400.
Which PCI validation requirement applies to your business is a question for your QSA or compliance advisor — these pages do not determine your SAQ eligibility.
🔒Compliance requirement
You must complete the PCI SAQ your QSA determines for your environment before going live. Provide your SAQ completion evidence during Cresora certification.