Card data never reaches our servers
Card data handled by a PCI DSS Level 1 processor — it never touches our servers. Card details are captured in the processor's hosted fields; Umbra receives a token, never a card number.
The controls should reflect that. Here is what protects your data and your clients' payment details.
Card data handled by a PCI DSS Level 1 processor — it never touches our servers. Card details are captured in the processor's hosted fields; Umbra receives a token, never a card number.
TLS 1.2+ in transit, encrypted at rest on AWS, with sensitive credentials held in AWS KMS.
Owner and employee roles for each business, and nothing from another business on the platform.
Activity history on every invoice and payment, plus an audit-trail report.
Reconciliation runs continuously against the processor and against QuickBooks. Divergence is surfaced in a queue rather than discovered at month end.
Found something? Write to support@umbrapay.com and we will respond directly.
Reduce cost, remove the tedious parts, and get the insight you need to grow — without adding another tool to the stack.