How Vori handles card payments
Vori never stores, processes, or transmits cardholder data. All credit and debit card transactions are handled entirely by the payment terminal using point-to-point encryption (P2PE). Card data is encrypted at the terminal the moment a card is dipped, tapped, or swiped, and is sent directly to the payment processor — it never passes through the Vori POS software or Vori’s servers. Because Vori never touches card data, a compromise of the store’s local network would not expose any credit card information.What is PCI DSS?
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements established by the PCI Security Standards Council. Any business that stores, processes, or transmits cardholder data must comply with these standards.Who is PCI compliant in the Vori ecosystem?
Because Vori’s architecture delegates all card-data handling to a PCI-validated P2PE solution, your store qualifies for the simplest PCI Self-Assessment Questionnaire (SAQ) — significantly reducing your compliance burden.
What does this mean for your store?
- Card data is never on your network. Even if someone gains access to your store’s local network, there is no cardholder data to intercept.
- Simplified PCI compliance. Because you use a P2PE-validated payment solution, you can complete the shortest PCI self-assessment questionnaire (SAQ P2PE) rather than a full audit.
- Encryption from swipe to processor. Card data is encrypted inside the terminal hardware before it ever reaches the network.
Completing your PCI questionnaire
Your payment processor asks you to complete a PCI Self-Assessment Questionnaire (SAQ) once a year. If your processor is CardConnect, you complete it in the CardPointe PCI portal at cardpointe.managepci.com. Two answers near the start of the questionnaire determine how much work the rest of it takes:- Assessment method. The portal offers three options: Guide Me, Expert, and Upload an existing PCI compliance form or other valid forms. Select Expert.
- Assessment type. When the portal asks you to select the PCI DSS compliance assessment type that you are submitting, select SAQ P2PE. This is the shortest questionnaire, roughly 40 questions instead of the 300 or more that a store without point-to-point encryption answers.
If the questionnaire starts asking you to name an encryption vendor or a terminal model, you are on a different path through the portal. Click Previous until the Guide Me and Expert options appear again, then select Expert and continue from there.