Website Security Explained
Salem Essentials Website Security
Our site is built with Shopify, which is certified Level 1 PCI DSS compliant and meets all PCI DDS standards. What is PCI DDS?
PCI DDS stands for "Payment Card Industry Data Security Standard", which ensures that making online payments is safe.
Why we use Stripe Payments Gateway
Our website platform's security is extremely important to us. Your privacy, your information, and ESPECIALLY how your payments are processed. For this reason, we use Stripe as our primary means for processing credit card payments.
When you make a one-time order on www.salemessentials.com, for your convenience, we give you several options
Stripe has been audited by a PCI-certified auditor, and is certified to PCI Service Provider Level 1. This is the most stringent level of certification available.
Stripe forces HTTPS for all services, including our public website. We regularly audit the details of our implementation: the certificates we serve, the certificate authorities we use, and the ciphers we support. We use HSTS to ensure browsers interact with Stripe only over HTTPS. Stripe is also on the HSTS preloaded lists for both Chrome and Firefox.
For more about implementing SSL on your own website, read our SSL guide.
All card numbers are encrypted on disk with AES-256. Decryption keys are stored on separate machines. None of Stripe's internal servers and daemons are able to obtain plaintext card numbers; instead, they can just request that cards be sent to a service provider on a static whitelist. Stripe's infrastructure for storing, decrypting, and transmitting card numbers runs in separate hosting infrastructure, and doesn't share any credentials with Stripe's primary services (API, website, etc.).