Security & trust
Where your card data, your documents and your money go.
Plain statements, each tagged with who is responsible for it. Where something is provided through our processing partner we say so, and we do not dress it up as ours.
How to read the tags
- OursA statement about Dash Process, which we are accountable for.
- Processing partnerProvided by the gateway or the acquiring bank. Attributed, not claimed.
Reviewed
Card data
Your server only ever sees a token.
With hosted checkout, a plugin or hosted fields, the card number is captured in a field we serve and exchanged for a token before your code runs.
Cardholder's browser
Types the card number
Hosted field
Served by us, inside your page
Token
Stands in for the card
Your server
Never holds the card number
Dash platform
Authorizes, captures, settles
PCI scope
By integration path.
Which self-assessment questionnaire applies depends on whether card data ever touches your systems. Three of the four paths keep it away entirely.
- Hosted checkout
- SAQ ACard data is entered on a page we serve and never reaches your systems.
- Cart plugin
- SAQ AThe plugin uses hosted fields; card data bypasses your server.
- API with hosted fields
- SAQ AFields we host inside your page tokenize the card before your code sees it.
- API with raw card data
- SAQ DYour server touches card numbers. Larger scope, longer questionnaire. We would rather you did not.
Statements
Where things go, and who is responsible.
- Card data
- Tokenized in the browser by our gateway partner's hosted fields or the hosted checkout page. Card numbers are not stored on Dash Process systems or yours.
- Bank or gateway
- Merchant funds
- Held and settled by the acquiring bank that provides your merchant account, not by Dash Process. We do not take deposits.
- Bank or gateway
- Reserves
- Set and held by the acquiring bank against the account's chargeback exposure. Balance and release dates are visible in your dashboard; releases post as line items.
- Bank or gateway
- Application documents
- Collected over a secured channel after a person has confirmed your category fits — never through a marketing form. Kept for as long as the acquiring bank, card-network rules and regulation require.
- Ours
- Inquiry data
- Forms on this site collect name, contact details, company and what you sell. Kept for the period stated in the privacy policy unless you become a customer.
- Ours
- Transport
- HTTPS everywhere, with HSTS. The site sends no card data anywhere; it collects inquiries only.
- Ours
- Abuse controls
- Lead endpoints are rate limited and size capped, with a honeypot and timing check. Best-effort against floods; not a substitute for the controls on the gateway and at the bank.
- Ours
- Analytics
- Google Analytics runs in production and is disclosed in the privacy policy. No advertising pixels.
- Ours
Report a security issue
Report a security issue
If you have found something, tell us directly. We would rather hear it from you than read about it.
support@dashprocess.com(347) 594-9686
We acknowledge reports, we do not pursue good-faith researchers, and we say what we changed in the changelog.
Ask the question you would ask a bank.
Where the money sits, who holds the reserve, what happens to your documents. If the answer is not on this page, a person will give it to you.