The short answer
The most secure way to handle credit card data is not to have it, and that is the approach we take. Your card details are never entered on our systems, never pass through them, and are never stored by us, because every card payment happens inside the payment gateway's own environment, not ours.
Where your card details actually go
When you pay by card, instant EFT, or PayPal, you are handed to PayFast, Paystack, or PayPal to complete the payment. Those are specialist payment providers whose entire business is processing payments securely and who carry the certifications that go with it. They confirm back to us that a payment succeeded, and that is all we receive.
This has a practical consequence worth stating plainly: we are not PCI compliant, and we do not need to be, because we never capture card data. There is no stored card number on our servers to protect, no card database to breach, and nothing for us to accidentally expose. A provider claiming to store your cards safely is making a promise; we are simply not in a position to break one.
What we do hold
Your client portal holds your account information: your name and contact details, your services and domains, your invoice history, and your support tickets. It is protected by your password, it runs over an encrypted connection, and access to it is controlled by you, including any additional users and contacts you have added, as covered in our article on adding extra contacts and users.
Our own banking details appear on unpaid invoices and nowhere else, which is deliberate, and the reasoning behind it is in our article on how to pay your invoice.
How your account itself is protected
- A verified email address. Your registered address must be confirmed when you first register, when your password changes, and whenever the address itself changes. An unverified address cannot be used to reset a password.
- A security question on password resets. Reaching your inbox is not enough on its own, as explained in our article on why we ask a security question.
- Manual review of every order. Every order, new, upgrade, or downgrade, is checked and accepted by a person before anything is provisioned. It is a deliberate speed bump, and it is one of the reasons fraudulent accounts rarely get far with us.
- Payment only on confirmed funds. We process a payment when it genuinely reflects in our account, not when someone tells us it has been sent. Proof of payment speeds up the check, it does not replace it.
The part that depends on you
Most account compromises anywhere start with the account holder, not the provider. Three things do most of the work:
- A strong, unique password on your client portal, not reused from anywhere else.
- An email address you actually control and read, since it is the recovery path for everything. An account still registered to a former employee's address is a problem waiting for its moment.
- Scepticism about anything asking for credentials or payment. We never ask for your password or your security question answer, in a ticket, on WhatsApp, or by email. Any message claiming our banking details have changed should be treated as fraud until you have verified it with us directly, using contact details you already have rather than ones the message supplies.
Good to know
If you would rather not have card details stored anywhere at all, including with a gateway, bank transfer remains available and is how the majority of our clients pay us. It costs you a manual allocation step on our side, described in our article on how to pay your invoice, and gains you a payment method that involves no third party holding anything on your behalf. Both approaches are legitimate, and the choice is yours.