Payment Solution Overview
Payment Solution Overview

Enactor Payment Solution
PCI P2PE Compliant
- Card data is encrypted at the PED - never exposed in clear text
- Point-to-Point Encryption from PED to payment gateway
Supported Verifone PEDs
- P400 - fixed countertop
- v240m - mobile
- e285 - compact mobile
- e355 - companion device
- Vx820 - legacy countertop
- Vx680 - legacy mobile
Payment Gateways
- Gateway cluster processes transactions between POS estate and acquirers
Payment Portal
- Token store for secure card-on-file and e-commerce transactions
Fixed POS Payment Flow
Architecture
- POS + PED initiates the transaction
- Encrypted card data transmitted over IPSec VPN to the payment gateway cluster
- Gateway forwards to Acquirer for authorisation
Encryption
- DUKPT (Derived Unique Key Per Transaction) encryption at the PED
- TLS 1.1+ and IPSec for transport security
High Availability
- 3 geographically separated gateways for resilience
- 2 providers for redundancy
- Automatic failover between gateways
Mobile POS Payment Flow
Mobile POS Variant
- Mobile POS + PED connects to the store's PDP Server and PDC (Payment Device Controller)
- PDC routes encrypted data over IPSec VPN to the payment gateway cluster
- Gateways forward to the Acquirer via BT Cardway VPN
Key Difference
- Mobile devices connect through an intermediate PDP Server and PDC layer rather than directly to the VPN
- Same gateway infrastructure and failover as fixed POS
Further Reading
For additional information and further reading on Payment Solutions, please see the following guides: