Hi
By way of introduction, I work for a company called Callpay. We launched an instant EFT gateway in South Africa last year. You can read all about it here -
http://ventureburn.com/2017/02/eftsecure-allows-merchants-to-accept-more-payments-faster-than-ever
To give you some deeper insight. We act as a proxy between the customer and their bank. Normal settlement periods always apply and we provide the instant payment notification to the Merchant. This has benefits for both the Merchant and customer. From a Merchant perspective, it allows millions more South Africans to pay them online whilst lowering their very expensive credit card processing fees. For the customer, it is a simple 3 step payment process allowing them to pay using any of their online account - cheque, savings and even credit card accounts to pay in less than 15 seconds.
From a security point of view. Whilst the payment is in process, partial sensitive data comes into contact with our environment. At Callpay, we are subjected to some of the most toughest security measures out there. The environment goes through multiple penetration testers, including external, internal and web application penetration testing. We have vulnerability scans that run daily and are further subject to Payment Card Industry Data Security Standards. We have an appointed firm, Sysnet Global Solutions in Ireland that audits our entire environment and report back to the various banks and card brands. We go through physical audits, with our QSA from Mauritius being down every 6 months for an onsite audit aswell. PCI is required as PAN is in the clear with some banks as they themselves have not yet been able to validate against the stringent measures of PCI DSS. Apart, we have various other scans, compliances and certificates in place. Lastly, data is NEVER stored, we provide the Merchant with a guarantee that the payment was done. We also have a buyers protection program that protects a customer up to R100 000 that is underwritten with an insurer. I cannot vouch for I-Pay security measures, I also know that SID is not PCI compliant and this compliance must be done by each Merchant themselves to become compliant as per their Merchant Agreement. We are a full Level 1 PCI DSS v3.2 compliant Service Provider and descope our Merchants 100% from the stringent PCI DSS compliance measures.
2015 -
https://sysnetgs.com/2015/07/callpay-certifies-to-pci-dss-v3-1/
2016 -
http://www.itweb.co.za/index.php?option=com_content&view=article&id=159696
In many ways it is even more safe than a card payment. For me, online banking was designed to be online whereas card payments was adapted by the massive card brands to work online. It works well in a physical store with chip and pass pin. The reason is that a Card Not Present (CNP) transaction can be done in two ways - either Mail Order Telephone Order (MOTO) and 3D Secure. This means when your sensitive card credentials is compromised, it can be used anywhere in the world without your consent. With banking, not a single bank will do a once off payment with the customer authorizing that payment. It is basically 3D Secure build into the solution already. Now, it could be possible to charge back a card payment. This in itself can be a very tedious process. As it took many years for consumers to trust entering their credit card payments, people are becoming use to instant EFT's. The eCommerce shop is also very important - the customer place a huge amount of trust in the brand - for payment security aswell. For this reason, it is very important also for Merchants to only work with reputable companies that has the measures in place to keep their customers safe whilst shopping online.
And for some marketing, EFTsecure is the most advanced instant EFT payment gateway in South Africa. We allow customers to pay online from any of the major 4 banks including Capitec and Investec. We are the only EFT solution that can process refunds, an industry first. Our Merchants can "self-host" the payment solution on their site, in a PCI compliant manner. We complete EFT payments, in real-time, at a fraction of the speed compared to competitors. We offer the lowest processing rates in the industry with a free trial to get you going. Integration is a breeze with our various eCommerce Plugins and we have a full suite of API's for Enterprise Integration. We acquire local and can settle also settle funds in other 170 countries. We have recently partnered with various other service providers, to allow a Merchant to accept bank transfer payments from customers in over 40 countries. We are also busy integrating directly into two banks via API's, also an industry first.
For local payments, EFT payments will be a big part of the future. Our Merchants are already processing between 25%-35% of online payments via instant EFT compared to card and other alternative methods. It is simple for me, we are all South Africans - this includes customers and Merchants. We do not need an international MC or VISA rail to manage our local payments. Think about it.
If you have any questions, feel free to PM me. Also, have a look at
www.eftsecure.co.za for your online payments. Let me know, I will personally hook you up with the best deal - promise.
Hope my post give some clarification around instant EFT as a payment method and security behind atleast
OUR solution. You can demo the solution here:
https://eftsecure.callpay.com/eft/demo?organisation_id=219