![]() |
|
|||||||
|
Web sites which handle their own credit card processing will generally have their own SSL certificates. This allows SiteTruth to directly validate the site ownership. Smaller merchants tend to use off-site credit card processing systems, where, when payment is to be made, the customer is sent to an off-site link. This can make it difficult for SiteTruth to validate the ownership of the merchant's site. As a convenience for smaller merchants, SiteTruth will, when appropriate, accept the payment site's verification of the merchant's identity. This increases the merchant's legitimacy rating and allows them to receive the SiteTruth checkmark. Payment site requirementsTechnical requirements - payment site
Technical requirements - merchant site
Contractual requirementsWhen SiteTruth accepts a payment site's verification of a merchant site's identity, the payment site is acting as an issuer of credentials. We therefore require that the payment site stand behind its verification of the merchant's identity. Before accepting a payment site as a source of merchant credentials, SiteTruth requires that the payment site warrant its identity verification in terms no less comprehensive than the "EV Certificate Warranties and Representations" defined by the CA Browser Forum EV Certificate Guidelines. These are standardized terms developed in conjunction with the Information Security Committee of the American Bar Association Section of Science & Technology Law and the Canadian Institute of Chartered Accountants, agreed to by all major certificate issuers (Comodo, Verisign, CyberTrust, RSA, Wells Fargo, etc.) and all major web browser developers (Microsoft, Mozilla, Opera, KDE). The payment site must accept the limited financial liability required by the "CA Liability" section of the Guidelines. Compliance by a payment site can be demonstrated by publishing, on the payment site's web site, a suitable "Relying Party Agreement" similar to that required of certification authorities. SiteTruth will publish a list of the payment sites which, in our opinion, meet these criteria. |
||||||||
SiteTruth. Know who you're dealing with. Another service from the publishers of Downside |
||||||||