Durable logo
Durable logo

All articles

Learn about security measures Durable uses for payment processingUpdated 7 months ago

Durable uses Stripe for all payment processing, and at no point do we store or access any sensitive financial information on our own database.
Stripe has been audited by a PCI-certified auditor and is certified to PCI Service Provider Level 1. This is the most stringent level of certification available in the payments industry. 
All card numbers are encrypted at rest with AES-256. Decryption keys are stored on separate machines. None of Stripe’s internal servers and daemons can obtain plaintext card numbers but can request that cards be sent to a service provider on a static allowlist. Stripe’s infrastructure for storing, decrypting, and transmitting card numbers runs in a separate hosting environment, and doesn’t share any credentials with Stripe’s primary services (API, website, and so on). 
Read more about Stripe security.
Was this article helpful?
Yes
No