Loading
Salesforce Payments
Payment Page Tamper Detection

Payment Page Tamper Detection

To make sure customer payment data is secure, Salesforce Payments complies with the latest PCI standard for detecting changes to Content Security Policy (CSP) headers and scripts. The PCI standard applies to any payment form where customers enter their information, including the checkout page, Pay Now payment pages, and mini carts that include express checkout.

Required Editions

View supported editions.

If Salesforce Payments detects changes to a payment web page header or the insertion of javascript, it triggers a Content Security Policy (CSP) platform event with these fields:

  • Context––URL of the payment page where the change occurred.
  • Notification Type–Header or script change.
  • Notification Message–Tells the admin what change was detected.

To secure customer payment information, subscribe to these events, and, if necessary, take corrective action. To receive these events, create an Apex trigger or a platform event-triggered flow. For more information, see Subscribing to Platform Events.

Note
Note Payment pages that use the Salesforce Payments, Payment, or Dual Payment Experience Builder components are compliant by default. If you use a third-party payment provider with a custom payment component, verify whether change detection is implemented.
 
Laddar
Salesforce Help | Article