Security on The City of Winnipeg's Payment Form.
  By Security, we mean the ways we make sure the information you send us remains secure.

Security Page Contents:

  1. Is my credit card number secure?
  2. How do I know if a Web site is secure?



Is my credit card information secure?
 

All payment applications and cardholder processing, storing and transmission is handled through Strategic Profits Inc./PayPaq Solutions Inc. a Payment Card Industry Data Security Standards (PCI DSS) validated service provider. The companies are assessed annually to the strict PCI DSS requirements for any merchant or service provider storing, processing or transmitting cardholder data today. All applications that store, process or transmit cardholder data are required to hold either a PA-DSS or PCI DSS validated Attestation of Compliance. This application is validated through PCI DSS annually. For more information see www.paypaq.com or www.pcisecuritystandards.org



How do I know if a Web site is secure?
 

When buying something on the Internet, there are three things to be sure of:

  • Data you send is encrypted.
  • The site you're doing business with is the site you think it is
  • The site you're doing business with holds a valid PCI DSS certificate of compliance covering their application or the application is PA-DSS compliant

Points 1 and 2 are taken care of by TLS (Transport Layer Security), the industry standard security protocol that this site uses to communicate with secure browsers like Chrome, Firefox and Internet Explorer. When communicating with a secure server like ours, these browsers encrypt the information you send in a way that is extremely difficult for anyone else to decode.

You can tell when you're in a secure area because the URL to the left of the colon changes from 'http' to 'https' to signify that a TLS protocol is being used to communicate with the server. (http = HyperText Transport Protocol; https = HTTP with TLS.)

Point 3
The third point is ensured if the site holds either a PA-DSS or PCI DSS validated certificate. If an application is hosted in a Valid PCI compliant network then it does not require a PA-DSS certification as the Payment Application Data Security Standards are based on the PCI DSS standards and requirements. If in doubt ask the web-master if they are PCI compliant...it is not enough for someone to tell you are secured. There is no way of knowing unless a service provider can give you a valid PCI attestion of compliance or letter from their certified QSA. (PCI SSC list of certified QSA's)

Close Window