Blog Feed Post

Porticor Helps Organizations Meet PCI DSS Compliance and Secure Credit Card Information Stored in the Cloud

Porticor’s Cloud Key Management and Data Encryption Solution Protects Cloud-based Cardholder and Financial Information from Holiday Hackers and Threats at Organizations such as Payze

CAMPBELL, Calif. – Dec. 2, 2014 – Porticor®, a leading cloud data security company delivering the only cloud-based key management and data encryption  solution that infuses trust into the cloud and keeps cloud data confidential, today announced growing customer traction due to its innovative solution enabling organizations to secure cloud-based credit card and financial information, helping them meet Payment Card Industry Data Security Standard (PCI DSS) compliance.  Customer privacy is of particular concern for financial organizations during the holiday season due to the increase in threats and hacker activity.

The Porticor Virtual Private Data (VPD) platform is a cloud key management and encryption solution that delivers the industry’s most secure cloud encryption key management by enabling organizations to securely maintain control of their own encryption keys.  Unlike traditional data encryption solutions, which are complicated and expensive to deploy and manage, Porticor’s split-key encryption and homomorphic key management system is offered as the industry’s first cloud data protection service of its kind, delivering true confidentiality of credit card and financial data in cloud, virtual and hybrid environments by ensuring encryption keys are never exposed.

“At Payze we’ve setup a credit card processing system within AWS, and as part of our PCI requirements we needed a separate key management system in order to comply with PCI policies,” said Joel Paulin, Founder and Chairman of Payze.  “We’ve integrated Porticor into our encryption key setup to provide seamless additional encryption on top of our existing encryption infrastructure.  This additional level of encryption, with keys isolated from our normal system, and using Porticor’s permissions and controls enables us to have a more secure key management posture going for PCI compliance.  What differentiates Porticor is the product: It is polished, easy to configure, easy to integrate, more reliable, and has greater security than the other options we had seen.”

The main focus of PCI DSS is protecting cardholder data in systems and applications, including data in storage, transmission, and in use.  These requirements are more critical when data is stored and processed in the cloud, an activity escalated during holiday shopping.  Porticor VPD is a complete solution that combines patented key management with state-of-the-art encryption to enable organizations to effectively comply with PCI DSS in the cloud.  Porticor encrypts the entire data layer, including virtual disks, databases, files, and object storage.  It also addresses the processes necessary for managing encryption environments and encryption keys, and provides the security needed for compliance in a convenient, cost-effective, fully cloud-based solution.

“We were impressed with the ease of setting up the Porticor appliance,” added Paulin.  “Compared to the other options we considered, we were more confident in the security of Porticor’s solution, and we appreciate the turnkey nature of it.  Also, because the Porticor systems provide automation of key management, we didn’t need to worry about a server crashing and losing our keys since the automated system would correctly provision our instances, which was a risk for other systems.  Finally, the use of a master key on the appliance kept by us helped give us assurance that Porticor did not know our keys and we had the benefit of dual control, which helped us meet our dual control needs for PCI compliance.”

The PCI Council defined 12 high-level security requirements.  Six of the requirements define the need for both encryption and key management in the cloud to protect credit card information from both inside and outside threats, and are addressed by Porticor.  Porticor gives organizations the ability to meet these requirements by requiring two keys to encrypt or decrypt an object.  In addition, each key is encrypted – to protect it while it is resident in a cloud account – using patent-pending homomorphic key management technology.  In addition, Porticor helps address some of the general PCI DSS requirements beyond encryption and key management.  For more information on how Porticor addressed PCI DSS compliance, see: http://www.porticor.com/pci-white-paper-download/

“Financial organizations are under threat at all times, but especially during this time of year with the increased consumer buying activity,” said Ariel Dan, Porticor Co-Founder and Executive VP.  “Porticor’s VPD is uniquely built to address PCI DSS compliance requirements, and the PCI DSS requirements validate the need for Porticor’s unique approach of combining patented split-key encryption and homomorphic key management with encryption technologies.  Key management is an ongoing challenge for organizations, and Porticor’s homomorphic key management solves this problem and enables companies to achieve compliance.  With Porticor, organizations are assured that credit card information and confidential data are kept safe from outside and internal threats.”

Integrating with major players such as HP, AWS and VMware, Porticor provides the industry’s only software-defined, automated solution that uniquely eliminates the need for cumbersome, non-scalable, and expensive hardware security modules for the cloud.  Uniquely combining data encryption with patented split-key encryption and homomorphic key management technologies, Porticor protects critical data in public, private and hybrid cloud environments.  It provides the strong security needed for compliance in a convenient, cost-effective, fully cloud-based solution.

About Porticor

Porticor is the leading cloud security company delivering easy-to-use and scalable security solutions for cloud data encryption and key management.  The Porticor Virtual Private Data (VPD) system is the industry’s first solution combining data encryption with patented split-key encryption and homomorphic key management to protect critical data in public, private and hybrid cloud environments.  Using breakthrough split-key encryption and homomorphic key management, the Porticor VPD is the only system available that offers the ease-of-use of cloud-based key management without sacrificing trust.  Porticor is an Amazon Web Services Technology Partner, a VMware Technology Alliance Partner, an HP technology partner, and supports other clouds.  The company is headquartered in Tel Aviv, Israel, with offices in Silicon Valley, and is venture backed.  For more information, visit: http://www.porticor.com/.



The post Porticor Helps Organizations Meet PCI DSS Compliance and Secure Credit Card Information Stored in the Cloud appeared first on Porticor Cloud Security.

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

Latest Stories
Due of the rise of Hadoop, many enterprises are now deploying their first small clusters of 10 to 20 servers. At this small scale, the complexity of operating the cluster looks and feels like general data center servers. It is not until the clusters scale, as they inevitably do, when the pain caused by the exponential complexity becomes apparent. We've seen this problem occur time and time again. In his session at Big Data Expo, Greg Bruno, Vice President of Engineering and co-founder of StackIQ...
The security needs of IoT environments require a strong, proven approach to maintain security, trust and privacy in their ecosystem. Assurance and protection of device identity, secure data encryption and authentication are the key security challenges organizations are trying to address when integrating IoT devices. This holds true for IoT applications in a wide range of industries, for example, healthcare, consumer devices, and manufacturing. In his session at @ThingsExpo, Lancen LaChance, vic...
"Plutora provides release and testing environment capabilities to the enterprise," explained Dalibor Siroky, Director and Co-founder of Plutora, in this SYS-CON.tv interview at @DevOpsSummit, held June 9-11, 2015, at the Javits Center in New York City.
FinTech is the sum of financial and technology, and it’s one of the fastest growing tech industries. Total global investments in FinTech almost reached $50 billion last year, but there is still a great deal of confusion over what it is and what it means – especially as it applies to retirement. Building financial startups is not simple, but with the right team, technology and an innovative approach it can be an extremely interesting domain to disrupt. FinTech heralds a financial revolution that...
In his session at DevOps Summit, Tapabrata Pal, Director of Enterprise Architecture at Capital One, will tell a story about how Capital One has embraced Agile and DevOps Security practices across the Enterprise – driven by Enterprise Architecture; bringing in Development, Operations and Information Security organizations together. Capital Ones DevOpsSec practice is based upon three "pillars" – Shift-Left, Automate Everything, Dashboard Everything. Within about three years, from 100% waterfall, C...
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo 2016 in New York. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place June 6-8, 2017, at the Javits Center in New York City, New York, is co-located with 20th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry p...
SYS-CON Media announced today that @WebRTCSummit Blog, the largest WebRTC resource in the world, has been launched. @WebRTCSummit Blog offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. @WebRTCSummit Blog can be bookmarked ▸ Here @WebRTCSummit conference site can be bookmarked ▸ Here
SYS-CON Events announced today that Addteq will exhibit at SYS-CON's @DevOpsSummit at Cloud Expo New York, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Addteq is one of the top 10 Platinum Atlassian Experts who specialize in DevOps, custom and continuous integration, automation, plugin development, and consulting for midsize and global firms. Addteq firmly believes that automation is essential for successful software releases. Addteq centers its products an...
In his keynote at @ThingsExpo, Chris Matthieu, Director of IoT Engineering at Citrix and co-founder and CTO of Octoblu, focused on building an IoT platform and company. He provided a behind-the-scenes look at Octoblu’s platform, business, and pivots along the way (including the Citrix acquisition of Octoblu).
SYS-CON Events announced today that IoT Now has been named “Media Sponsor” of SYS-CON's 20th International Cloud Expo, which will take place on June 6–8, 2017, at the Javits Center in New York City, NY. IoT Now explores the evolving opportunities and challenges facing CSPs, and it passes on some lessons learned from those who have taken the first steps in next-gen IoT services.
You think you know what’s in your data. But do you? Most organizations are now aware of the business intelligence represented by their data. Data science stands to take this to a level you never thought of – literally. The techniques of data science, when used with the capabilities of Big Data technologies, can make connections you had not yet imagined, helping you discover new insights and ask new questions of your data. In his session at @ThingsExpo, Sarbjit Sarkaria, data science team lead ...
SYS-CON Events announced today that WineSOFT will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Based in Seoul and Irvine, WineSOFT is an innovative software house focusing on internet infrastructure solutions. The venture started as a bootstrap start-up in 2010 by focusing on making the internet faster and more powerful. WineSOFT’s knowledge is based on the expertise of TCP/IP, VPN, SSL, peer-to-peer, mob...
The Internet of Things can drive efficiency for airlines and airports. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Sudip Majumder, senior director of development at Oracle, discussed the technical details of the connected airline baggage and related social media solutions. These IoT applications will enhance travelers' journey experience and drive efficiency for the airlines and the airports.
For organizations that have amassed large sums of software complexity, taking a microservices approach is the first step toward DevOps and continuous improvement / development. Integrating system-level analysis with microservices makes it easier to change and add functionality to applications at any time without the increase of risk. Before you start big transformation projects or a cloud migration, make sure these changes won’t take down your entire organization.
Big Data, cloud, analytics, contextual information, wearable tech, sensors, mobility, and WebRTC: together, these advances have created a perfect storm of technologies that are disrupting and transforming classic communications models and ecosystems. In his session at @ThingsExpo, Erik Perotti, Senior Manager of New Ventures on Plantronics’ Innovation team, provided an overview of this technological shift, including associated business and consumer communications impacts, and opportunities it m...