
To "4Go" actual cardholder data is one way Shift4 is
helping merchants achieve real security and to
simplify PCI compliance.
4Go is a driver-based firewall that runs on the merchant's Point-of-Sale (POS)/Property Management System (PMS) terminal and intercepts cardholder data (CHD) as soon as it is swiped - before it ever enters the POS or PMS - and replaces it with either false cardholder data (FCHD) or a TrueToken, thereby eliminating CHD vulnerability as it travels over networks or is stored in local log files.
Shift4 believes that the best way for merchants to protect CHD data is to make it unavailable, and that means removing it from the system entirely. The first solution of its kind, 4Go collects the data and transmits it to Shift4's Universal Transaction Gateway® (UTG®), where a TrueToken or FCHD is generated and returned to the POS/PMS application. The false information subsequently enters the POS/PMS and is used to perform the transaction. The TrueToken or FCHD is sent to Shift4's secure payment gateway DOLLARS ON THE NET® where it is associated with the actual CHD and sent for authorization or used for any other purpose for which the actual CHD would be used.
4Go is a validated Payment Application Data Security Standard (PA-DSS) application. When it is installed properly at a merchant's site, it actually serves as the payment application. As a result, merchants with old, previously unsecured, and even blacklisted POS applications achieve PA-DSS compliance without having to change their existing application.
Whether used as the compliant payment application or as a layered security approach allowing merchants to reduce costs, validate, and surpass the Payment Card Industry Data Security Standard (PCI-DSS), 4Go simplifies the entire PCI process.
When 4Go is integrated with a POS application that supports TrueTokenization®, data in transit and data in long-term storage is fully protected. This combination delivers the benefits of both tokenization and end-to-end encryption, providing the highest level of security and the lowest breach profile in the payment industry. A merchant can perform all of the same transaction functions with a TrueToken as they can with real cardholder data, as well as keep up to a 24-month archive for auditing, chargeback defense, and other information requests. Essentially, anything the actual card number would be used for can be accomplished using 4Go with a TrueToken.