Skip to content

Cards

Use this section to implement the issuing and managing of debit cards for your customers.

Guides

API reference

The Solaris API offers dedicated endpoints for creating and managing debit cards.

PCI compliance and sensitive information

The Solaris API does not expose PCI-relevant information. Therefore, you are not required to be PCI compliant.

However, you must not log or store sensitive data that the customer passes to the Solaris API.

Sensitive data includes:

  • Full Primary Account Number (PAN). Note: The masked PAN is not sensitive.
  • PIN
  • CVV
  • API authentication token

If sensitive data passes through your system, ensure that you do not log or store it in any way.

Warning
  • Never include sensitive data in any form (including images) in your customer support requests.
  • Never ask your customers to include sensitive data in their support requests to you.

If you receive sensitive data from a customer:

  1. Inform the customer that they should not include sensitive data in communications with you.
  2. Instruct the customer to close the affected card. They can order a new one if they wish.
  3. Delete the sensitive data from your entire system immediately.
  4. Inform Solaris about the incident as soon as the card is closed, or if the customer does not act within five days.

What to do if sensitive data is exposed

If sensitive data is exposed or logged in your solution, you must inform Solaris about the incident immediately. Solaris will provide further instructions, which will include closing the affected cards.