Every shop that accepts credit cards has a PCI compliance obligation. The good news is that Manifold is built so your shop's PCI obligation stays in the lightest bracket (called "SAQ A"), with very few questions to answer and no expensive controls to put in place.

How Manifold keeps card numbers off your systems

When a card is charged through Manifold's "Charge Card" panel on an invoice, the card number, expiration, and CVV are typed into a form provided by Authorize.net (not by Manifold). Your browser sends the card details directly to Authorize.net over an encrypted connection. Authorize.net returns a one-time token to your browser. Your browser hands that token to Manifold, and Manifold uses the token to ask Authorize.net to run the charge.

The result: Manifold's database never sees or stores the actual card number. We can't accidentally leak it, because we never have it. Authorize.net handles the heavy compliance work because the real card data lives in their vault, not ours.

What Manifold's database does store about every card payment

  • Card brand (Visa, Mastercard, etc.)
  • Last 4 digits of the card
  • Authorize.net's transaction id (so we can void or refund later)
  • For saved cards: Authorize.net's customer profile id, the card expiration month and year, and the verbatim consent the customer agreed to

What Manifold's database NEVER stores

  • The full card number
  • The CVV / CVC / security code
  • The magnetic stripe data

If a customer asks where their card is stored, the accurate answer is: "in Authorize.net's secure vault, not in our system."

What you still need to do

Even with all of the above handled by Manifold and Authorize.net, your shop is still the "merchant of record" for the card transactions, and PCI requires you to fill out a short self-assessment form once a year. It's called SAQ A. It's only a few yes/no questions. See the related article: "How to fill out your SAQ A self-assessment".

A second related article is important: if you ALSO accept cards in person at the counter with a swipe/tap terminal, that channel is separate and has its own PCI form. See "Card terminals at the counter need their own PCI form".