PCI-Aligned Payment Security
A security layer around Booking Ninjas payment workflows that helps keep access, payment records, permissions, and audit activity controlled.
Security Built Around the Payment Workflow
This is not a separate PCI compliance product. It is part of how Booking Ninjas helps structure and protect payment operations.
Access Control
Use Salesforce permissions and roles to control who can access payment-related records and actions.
Payment Record Control
Keep payment activity connected to the booking, invoice, customer, and configured processor.
Audit Trail
Use available Salesforce and Booking Ninjas record history to support operational review.
Processor Boundaries
Keep authorization and sensitive payment handling with the configured payment provider where applicable.
Keep Sensitive Payment Work Structured
The goal is to reduce unnecessary exposure and keep payment responsibilities clear.
Limit Access
Give payment-related access only to the users and roles that need it.
Keep Context Together
Keep payment status close to the related invoice, reservation, and customer record.
Use Supported Providers
Use the configured payment processor for the payment functions it is responsible for.
Review Changes
Use available history and audit information to review important record or configuration changes.
PCI Responsibility Is Shared
Booking Ninjas can support a PCI-aligned payment workflow, but PCI compliance depends on the full environment.
Booking Ninjas
Provides the operational layer, permissions, billing records, workflows, and supported payment integrations used in the setup.
Payment Provider
Handles the payment-processing and card-security responsibilities defined by the provider and integration.
Client Organization
Remains responsible for its own policies, users, devices, procedures, vendors, and compliance obligations.
Implementation
Defines how permissions, payment flows, integrations, and operational controls are configured for the organization.
Salesforce Adds the Control Layer
Booking Ninjas is Salesforce-native, so payment operations can use the same permission and record-control model.
- Role and permission-based access
- Payment records linked to customers and operational records
- Record history and audit information where available
- Configured approval or review workflows where needed
- Centralized reporting on payment-related records
- Supported integrations with payment providers
Works With the Payment Stack
The security layer supports the same payment, authorization, and audit workflows already used in Booking Ninjas.
Payment Processing
Connect payment activity to the configured processor while keeping operational context in Booking Ninjas.
View Payment Processing →Payment Authorization
Keep the processor's authorization result connected to the payment record.
View Payment Authorization →Audit Trail
Review changes and user activity where the Salesforce data model and configuration support it.
View Audit Trail →Pricing
The payment security layer is part of the Core product and configured payment setup — not a separate software subscription.
Core Package
Starts with 1–50 Active Bookable Units.
- Booking Engine + Reservation System
- Invoicing and Billing
- Role and permission controls
- Standard reports and dashboards
- Supported payment integrations where relevant
Provider & Compliance Scope
Depends on setupPayment-provider fees, security responsibilities, compliance work, and any client-specific integration requirements remain separate where applicable.
- No separate PCI security-layer subscription
- Payment provider fees remain separate
- Client compliance obligations remain with the client
- Implementation is scoped separately
Separate Compliance Tool vs Booking Ninjas Security Layer
Booking Ninjas is not replacing a PCI compliance program. It helps keep payment operations structured inside the product.
| Capability | Manual Controls | Booking Ninjas | Dedicated Compliance Tool |
|---|---|---|---|
| Payment workflow context | Separate documentation | Connected to operations | Usually external |
| Access control | Manual policies | Salesforce permissions | Depends on tool |
| Payment-provider connection | Managed separately | Supported integration | Usually separate |
| Operational audit context | Manual logs | Record history where available | Compliance-focused logs |
| PCI certification | Client responsibility | Not provided by Booking Ninjas | May support compliance work |
| Separate BN subscription | Not applicable | No | Usually yes |
Frequently Asked Questions
Keep Payment Security Built Into the Workflow
Use permissions, supported payment providers, and connected records to keep payment operations controlled inside Booking Ninjas.