But its representatives also take pride in offering a package that goes well beyond the standard to ensure that merchants are carefully safeguarded from cyber criminals nearby and the world over.
The company, headquartered in Houston, Texas, was founded in 1989 by two brothers, Mark and Brad Cyprus. Today, Brad is the company's Senior Security Architect; Mark is the Chief Technology Officer.
Both are exceptionally smart "in different ways," according to Bill Pickard, Vendor Safe's Chief Operating Officer. Mark, who sits on several industry oversight bodies, including the PCI committee of the Retail Solutions Providers Association, is the "world's expert on Level 4 merchant PCI compliance," Pickard said. "He's unbelievable.
"I worked for Sprint, which is a Fortune 100 company, and he is as smart, if not smarter, than the smartest guy we had at Sprint."
Pickard joined Vendor Safe in 2007, around the same time the company hired its current Chief Executive Officer, Chris Melson. Both were recruited to help the company develop and market what has become its signature technology - what Vendor Safe calls its "self-configuring firewall architecture," a remotely configured and operated firewall for POS environments.
The technology, the brainchild of Mark Cyprus, is patent pending. Pickard noted that Vendor Safe is the only company that has it. POS firewall implementation normally entails an extensive on-site installation process. Vendor Safe's firewall, and the PCI Managed Security Suite package within which it's contained, can be installed in minutes, Melson said.
"When we send out the firewall we tell the customer to go to a location on our website and click a link," Melson said. "That's all they have to do is click this link, some software gets installed on their system that allows us to understand their network topology, and then it sends them a firewall.
Then we can talk them through installing the Ethernet cable on the fire-wall: they just have to plug in the cable; then they walk away, and we do everything remotely."
The package is aimed primarily at Level 4 merchants (those processing fewer than 1 million transactions per year), who are most in need of a relatively cheap solution that's automated and doesn't demand technological savvy from its user.
"The systems are very automated, which allows us to keep our cost down, which we pass on to them in the form of a low monthly fee to keep them PCI compliant," Melson said. "The guy that has a sandwich shop can't afford $25,000 to do a gap analysis or even $10,000 a year for security. But he can afford $50, $60 or $70 a month."
Pickard said merchants of all sizes subscribe to the service, but that its biggest customers are Level 4 merchants with "geographically distributed offices and small IT staffs." He added that Vendor Safe's products are sold almost entirely through reseller channels.
Vendor Safe's self-configuring security network automatically tailors itself to fit the differently configured environments of multilocation merchants, Pickard said. That ensures that networks are fully segmented, with the POS system sealed off from all proximate digital entryways.
"You have a market that is huge and underserved and has a need for security measures that are mandated not only by the Payment Card Industry, but also by a number of state governments that have passed the PCI DSS or some separate standard to protect credit card data," Melson said. "We have a solution that meets that need."
Pickard said the PCI management system allows merchants to skip over about two-thirds of the questions on the PCI compliance questionnaire, which contains 225 questions for merchants who store card information. "Think of those questions as requirements," Pickard said. "We're providing a service that allows you to answer positively that 'we are fulfilling these following requirements.'"
Melson added that merchants whose networks run over a dedicated phone line use Vendor Safe's PCI Compliance Reporting Suite, a less expensive option.
But those who process transactions over public data networks using, for example, a DSL or cable modem to route transactions over the Internet use the company's PCI Compliance Managed Security Suite, a more tightly controlled and monitored option.
"It's much more difficult to hack into a traditional phone line that's a dedicated point to point connection," Melson said.
Pickard said that when the company applied for insurance on its patent, the insurer couldn't find a single company that had patented anything remotely similar (patent insurance rates are based largely on the insurer's assessment of the probability of litigation by companies that have patented similar products). To the company's knowledge, its self-configuring firewall is unique and novel.
Pickard said Vendor Safe's firewall and accompanying PCI program can be installed with a simple plug-in and a few clicks of the mouse. The bulk of the installation and operation is performed remotely by Vendor Safe - although the package is, as advertised, largely "self-configuring," meaning it largely installs itself by forming around the existing contours of a given merchant's digital layout.
"The differentiator for us is we do compliance for a fixed monthly fee," Pickard said. "Other companies bring out security analyzers and tell merchants exactly how to build a specific solution. ... We have a standard solution delivered via managed service.
"All our customers look the same to us: they all get a firewall; we manage that firewall 24/7 without sending somebody on site, and we don't make them change their IP address at the local land level."
Melson said the company's firewall automatically segments a merchant's POS system to keep it separated from other media channels that can function as gateways for hackers.
"Part of our service is to set the firewall up so [different networks] are zoned off," Melson said. He noted that typically, digital video recorders (DVRs), for example, have to be open to the Internet so they can be accessed remotely by managers monitoring stores from off premise locations.
"We don't want that Internet opening to migrate its way over to your point of sale network," he said. "Otherwise, the hole you might leave that allows you to access the DVR remotely might be accessed by a hacker to get into your point of sale system.
"If he's only accessing the DVR that's not a big deal, but if he found his way into your point of sale system and could access your credit card data, that's a serious problem. If you have a sophisticated firewall in place, you can fix it so that those are on completely separate networks.
So even though he's [hacked into] the DVR he still can't get into the point of sale system."
In addition to the firewall, the company's PCI compliance package comes with a rogue device detector meant to monitor on-site criminals who try to siphon card numbers with malware that's injected using a laptop or skimmer.
"People in Russia and China are really good at accessing networks from afar, but there is also the threat that someone could walk into your restaurant and get into your system internally, whether through your wireless network or even walking up and maybe plugging an Ethernet cable into your switch," Melson said.
"Our system protects against that as well. If somebody plugs a rogue device into the network, we can detect it and block it. We have a 24-hour monitoring system. If we detect suspicious behavior, we'll alert the merchant."
Pickard added that somebody trying to gain external access could try to log on to the network 50 times in 20 minutes. "That's a machine trying to log on, not a person," he said. "And we would detect that something was wrong. Or there are man-in-the-middle attacks. ... All the ways that hackers try to penetrate a system we are on the lookout for."
Pickard said the company's PCI compliance programs also include mechanisms for encrypting data and regulating its transmission. When a merchant registers with Vendor Safe, it is required to list the parties that it communicates with - such as vendors, processors and other business partners.
The IP addresses of those workplaces are then noted by Vendor Safe, and any attempts at digitally communicating with IP addresses outside of those listed are blocked. That prevents hackers from sending card information to external sources.
Vendor Safe services over 20,000 store locations in every state but Hawaii, as well as in Canada and Mexico. Pickard said the company tends to tackle client problems as if they were its own, adding that the company insures merchants for breach costs up to $50,000. "This company was built around designing and managing data networks, and it's still that way today," Pickard said. "When you manage data networks, security is the major focus. ... If you want to be PCI compliant, first and foremost you need to worry about security.
So that's what we do every day - 24 hours a day, eight days a week. You worry about security and PCI tends to fall into place."
Notice to readers: These are archived articles. Contact names or information may be out of date. We regret any inconvenience.
ISO/MLS contact:
Chris Melson
President and Chief Executive Officer
Phone: 713-929-0201
E-mail: cmelson@vendorsafe.com
Company address:
7324 Southwest Freeway
Houston, TX 77074
Phone: 713-929-0200
Fax: 713-773-2669
Website: www.netsurion.com
Web site: www.netsurion.com
ISO/MLS benefits:
Company Profile originally appeared in
The Green Sheet Issue 100601
231102 - Merchant Advisory Services Inc
231002 - Wellesley Hills Financial
181201 - Network Merchants LLC
180902 - MainStream Merchant Services Inc.
180801 - Century Business Solutions
180502 - Priority Payment Systems Northeast
180501 - Merchant e-Solutions Inc.
180301 - Wirecard North America
171202 - Secure Cryptopayments
171002 - National Benefit Programs LLC
170902 - Frates Insurance & Risk Management
170901 - DCS Holdings Group LLC
170802 - Apogee Payment Systems LLC
170702 - Active Software & Hardware Systems
170701 - Veratad Technologies LLC
170502 - Frontline Processing Corp.
170501 - Platinum Choice Bancard LLC
161202 - International Bancard Corp.
161201 - CSR Professional Services Inc
161102 - Digitzs Solutions Inc.
161101 - Residual Sheriff LLC.
160801 - DigiPay: Solutions Inc
160702 - CreditCardProcessing.com
151202 - Benseron Information Technologies Inc.
151201 - CardWare International Inc
151101 - Lion Capital Group LLC
150801 - Topcreditcardprocessors.com
150702 - Vision Payment Solutions LLC
150601 - Conformance Technologies
150502 - Global Processing Systems
150402 - Mercantile Processing Inc.
150401 - Field Guide Enterprises
150302 - Signature Card Services
150301 - Premier Payment Systems Inc.
150201 - Humboldt Merchant Services
141102 - National Merchants Association
141001 - Instant Credit Manager
140902 - Merchant Cash and Capital LLC
140701 - National Transaction Corporation (NTC)
140601 - Total Merchant Services
140501 - Nationwide Payment Solutions
140501 - BPC Banking Technologies
140301 - Meritus Payment Solutions
131202 - First American Payment Systems L.P.
131102 - Evo Payments International LLC
131001 - Live Reps Call Center
130901 - Regal Payment Systems LLC
130901 - The Merchant Solutions
130802 - North American Bancard LLC
130801 - Payment Logistics LLC
130702 - Plug n Pay Technologies Inc.
130601 - U.S. Merchant Systems LLC
130402 - National Processing Co.
130202 - Charge Card Systems Inc.
130202 - Layered Technologies Inc.
121202 - American Microloan LLC
121102 - Keep in Touch Systems Inc.
121102 - Merchants Choice Payment Solutions
121002 - Washington Bancard Merchant Services LLC
120902 - Central Payment Co. LLC
120802 - Royal Merchant Holdings LLC
120801 - National Benefit Programs LLC
120602 - Cardinal Commerce Corp.
120601 - Veritrans Merchant Services LLC
120502 - ExecuTech Lease Group
120502 - The Small Business Authority
120402 - Chargeback Guardian Inc.
120401 - Electronic Payment Exchange
120301 - Complete Merchant Solutions LLC
120201 - CSR - Compliance Solutions and Resources
111002 - Lead Source Call Center
111001 - First Annapolis Consulting Inc.
110902 - Point of Sale System Services Inc.
110901 - Sage Payment Solutions
110801 - Century Payments Inc.
110702 - Creative Vision Studio LLC
110702 - Network Merchants Inc.
110701 - Capital Access Network Inc.
110602 - eProcessing Network LLC
110602 - Moneris Solutions Inc.
110502 - Paragon Application Systems Inc.
110401 - Merchant Implementation Services
101202 - CheckAlt Payment Solutions
101102 - Impact Payments Recruiting
101101 - Global Electronic Technology Inc.
101002 - TriSource Solutions LLC
100802 - Federated Payment Systems LLC
100801 - Voltage Security Inc.
100601 - NETSURION (formerly Vendor Safe Technologies)
100502 - Transaction Network Services Inc.
100402 - Secure Payment Systems Inc.
100401 - Elite Merchant Solutions
100302 - Retail Decisions Inc.
091201 - Performance Training Systems Bankcard Boot Camp
091101 - Merchant e-Solutions Inc.
091002 - Whitehall Capital Advisors LLC
090901 - CoCard Marketing Group LLC
090801 - First National Merchant Solutions
090701 - checXchange Money Transfer Systems Inc.
090601 - Sterling Payment Technologies
090502 - Infinity Payment Systems
090501 - Merchant Cash and Capital
090401 - UseMyBank Services Inc.
090401 - Data Delivery Services Inc.
090302 - Velocity Merchant Services
090302 - Metro Merchant Services
090301 - Smart Transaction Systems Inc.
090301 - DCC Merchant Services USA LLC
090202 - TransFirst Holdings Inc.
081202 - Affirmative Technologies Inc.
081201 - On-line Strategies Inc.
081101 - Vision Payment Solutions LLC
081002 - Veratad Technologies LLC
081001 - International Merchant Solutions LLC
080801 - GreenSoft Solutions Inc.
080702 - Smart Circle International
080601 - International Bancard Corp.
080502 - DRG Telemarketing Inc.
080501 - BCC Merchant Solutions
080402 - U.S. Merchant Systems
080401 - Greystone Business Resources Corp.
080302 - Transmedia Payment Services Ltd.
071202 - Barclay Square Leasing Inc.
071102 - FirstView Financial LLC
071001 - Sage Payment Solutions
070902 - YourTownMall Business
070901 - Nxgen Payment Services
070802 - All card Processing-AAMonte-USA
070801 - Money Movers of America Inc.
070602 - Central Point Resources Inc.
070601 - Positive Feedback Software LLC
070502 - Premier Payment Systems
070501 - Amacai Information Corp.