Skip to main content

Payment Processing Models

This article outlines the architectural methods OPSCOM uses to handle financial transactions. Its primary purpose is to help administrators understand the differences between integrated gateways and hosted payment pages, ensuring secure and compliant transaction routing. This guide is intended for OPSCOM administrators.

Setup and Configuration

Selecting and configuring a payment processing model is a foundational step in your system setup. Because the configuration steps vary significantly by provider, you must configure your specific merchant account settings within the system.

For detailed setup instructions regarding your specific provider, please refer to the dedicated wiki articles for your processor (e.g., TouchNet (uPay) Hosted Payments, Moneris Hosted Paypage, or Bambora Checkout).

Understanding the Processing Models

OPSCOM supports different architectures for processing user payments, though the industry standard heavily favors hosted solutions for security reasons.

G8Yimage.png

Using Hosted Payments

This is the preferred and industry-standard method for handling payments within the OPSCOM platform.

Key Information Displayed / Process Flow:

  1. The user confirms their cart items and initiates the checkout process in OPSCOM.

  2. The system directs the user away from OPSCOM to the payment provider's secure hosted payment page.

  3. The user supplies their sensitive payment details directly to the payment provider. No payment details are exposed to or captured by OPSCOM.

  4. The payment provider processes the transaction and sends a secure notification back to OPSCOM.

  5. OPSCOM receives the notification, marks the transaction as complete, and updates the user's profile accordingly.

Using a Gateway

This legacy method involves handling the payment data flow more directly through the application.

The Gateway model is actively being phased out as a method for handling payments. Organizations still using a direct gateway should plan to migrate to a hosted payment solution to maintain security standards.


Best Practices and Considerations

  • Prioritize Hosted Payments: Organizations should always utilize Hosted Payments for new setups. This model drastically reduces your organization's PCI compliance scope because sensitive credit card data never touches your local network or the OPSCOM servers.

  • Audit Legacy Systems: If your organization has been using OPSCOM for many years, review your current payment configuration to ensure you are not relying on a deprecated gateway model.

Need help migrating from a legacy gateway to a modern hosted payment provider? Contact the OPSCOM support team to discuss your transition plan and ensure uninterrupted payment processing.