Skip to main content
Cresora Commerce
Compliance

Compliance

PCI, HIPAA, NACHA, and ACH authorization requirements for Cresora integrations.

Cresora is designed for compliance-first integrations. This section covers your obligations as a Partner integrating the platform.

Standards covered

StandardCresora posture
PCI DSSCresora is PCI DSS validated as a service provider; the Attestation of Compliance (AoC) is available on request. Card data is entered on Cresora-served pages, never on yours. Which SAQ applies to your business is your QSA's call.
HIPAACresora is HIPAA-aware for healthcare ISVs. See HIPAA guide →.
NACHAACH processing follows NACHA operating rules. See NACHA guide →.

Where card data lives

Cresora exposes two integration surfaces, and neither puts a card number on your systems:

  • Hosted page — the payer types card or bank details into a page Cresora serves (redirect or iframe). Nothing cardholder-related transits your server, logs or database. This is commonly the SAQ A shape.
  • Saved-card charge — your server charges a card that is already saved with Cresora, by its cvt_ vault token, via POST /transactions. A raw card number posted to the API is rejected with 400.

Which PCI validation requirement applies to your business is a question for your QSA or compliance advisor — these pages do not determine your SAQ eligibility.

🔒Compliance requirement

You must complete the PCI SAQ your QSA determines for your environment before going live. Provide your SAQ completion evidence during Cresora certification.

Topics in this section