I know Authorize.Net was ruled out, but couldn't you just use the Authorize.net CIM to avoid storing credit card data? We've been using Authorize.Net and the CIM and it's been great - and they are professional.
Yes, this was my thought too. Through their API can't you essentially mimic the same functionality as if cards were stored on your servers without having to deal with PCI compliance?
Comments
I know Authorize.Net was ruled out, but couldn't you just use the Authorize.net CIM to avoid storing credit card data? We've been using Authorize.Net and the CIM and it's been great - and they are professional.
Yes, this was my thought too. Through their API can't you essentially mimic the same functionality as if cards were stored on your servers without having to deal with PCI compliance?