Laserfiche WebLink
Tulsa, OK, US <br />Part 2d. Payment Application <br />Does the organization use one or more Payment Applications? ❑ Yes ® No <br />Provide the following information regarding the Payment Applications your organization uses: <br />Payment Application <br />Name <br />Version <br />Number <br />Application <br />Vendor <br />Is application <br />PA-DSS Listed? <br />PA-DSS Listing Expiry <br />date (if applicable) <br />N/A <br />N/A <br />N/A <br />❑ Yes ®No <br />N/A <br />Part 2e. Description of Environment <br />Provide a high-level description of the environment covered <br />by this assessment. <br />For example: <br />• Connections into and out of the cardholder data <br />environment (CDE). <br />Critical system components within the CDE, such as POS <br />devices, databases, web servers, etc., and any other <br />necessary payment components, as applicable. <br />Bluefin provides (4) applications specific to the <br />storage, process, and transmit payment card <br />transactions: <br />PayConex provides stand-alone or <br />integrated payment processing with <br />P2PE for direct merchants and <br />software vendors. The P2PE <br />decryption environment is included in <br />the scope of this assessment. <br />PayConex additionally supports E2EE <br />and e-Commerce transactions <br />(hosted e-commerce), and <br />tokenization services <br />• Decryptx enables acquirers, <br />processors, and gateways to offer <br />Bluefin's P2PE solution on their <br />platform and direct to their merchants <br />through an API connection with <br />Bluefin <br />• QuickSwipe Mobile is a payment <br />application installed on mobile <br />devices <br />ShieldConex provides tokenization of <br />non -card branded data <br />For the purposes of this assessment <br />cardholder data (CHD) is stored encrypted <br />(AES-256 bit) within MySQL databases in <br />accordance with the Bluefin retention policy. <br />Bluefin maintains in -scope data centers <br />located in Atlanta, GA and Tulsa, OK. All <br />vendor, merchant, and partner connections <br />utilize TLS 1.2, IPsec VPN, and / or VPLS <br />network connections. <br />PC] DSS v3.2.1 Attestation of Compliance for Onsite Assessments — Service Providers, Rev. 1.0 June 2018 <br />© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 5 <br />