High-risk payment security, built for founders who have been burned before
You have probably had an account frozen, a processor go quiet, or a customer database you were never sure was safe. Here is how Resub is built to handle your payments and customer data.
Book a callSecurity you can actually check before you sign
High-risk merchants in nutra, supplements, beauty, health, CBD, coaching and subscription DTC carry more scrutiny than almost anyone else in payments. Card networks watch your ratios more closely, banks ask harder questions, and one bad decision on data handling can cost you an account you spent months getting approved. That means high-risk payment security is not a checkbox at the end of onboarding for us. It is the foundation the platform is designed around, because your ability to keep processing depends on it.
We keep this page honest on purpose. Instead of flashing badges we cannot let you verify, we describe the standards and practices Resub is built to follow, how card data is scoped and protected, how customer data is handled, and how reserves and payouts work so there are no surprises. If you want the specifics for your setup, your volume, or your compliance team, we would rather walk you through them on a call than make a claim here we cannot stand behind for your exact account.
How we protect payments & data
PCI DSS scope for card data
Resub is designed around PCI DSS practices for handling cardholder data, with the goal of keeping raw card details out of your systems and minimizing the scope that ever touches sensitive card data in the first place. Less exposure for you means fewer things that can go wrong.
Tokenization, no raw card storage
Card numbers are designed to be replaced with tokens, so your CRM, dashboards and integrations work with a safe reference instead of a real PAN. The intent is simple: you should be able to bill, retry and manage subscriptions without ever storing raw card numbers yourself.
3-D Secure 2 & SCA
The platform supports 3-D Secure 2 and Strong Customer Authentication flows so eligible transactions can shift liability and satisfy regional requirements. It is built to apply authentication where it protects you, while keeping friction off the checkouts that do not need it.
Encryption in transit & at rest
Sensitive data is designed to be encrypted in transit using modern TLS and encrypted at rest in storage. The aim is that data moving between your customers, Resub and the processors, and data sitting in our systems, is protected by strong, current cryptography end to end.
Access controls
Access to systems and customer data is built around least-privilege principles, role-based permissions and authentication safeguards, so people and services only reach what they need. The goal is that no single account is a skeleton key to your customers or your payments.
Fraud & chargeback safeguards
Resub is designed to plug into chargeback and fraud alert networks in the Ethoca and Verifi style, so disputes can be caught and resolved before they post. Monitoring is built to be VAMP-aware, watching the ratios the networks watch so you can act early instead of reacting to a threshold letter.
Your customer data, handled with care
Your customer list is one of the most valuable things you own, and in high-risk it is also one of the most sensitive. Resub is designed for GDPR-aware handling of personal data: collecting what is needed to run payments and the CRM, keeping it protected, and supporting the kinds of access, correction and deletion requests your customers and regulators can make. Data handling is built to respect data-processing responsibilities between you as the merchant and Resub as the platform, so roles and obligations are clear rather than assumed. We are deliberately not naming specific sub-processors, certificate numbers or audit dates on this page, because we will not publish a claim we cannot guarantee holds for your exact configuration. If your compliance team needs that level of detail, including how data is segregated and where it is processed, we will cover it directly on a call.
Security & compliance at a glance
| Area | Industry norm | Resub |
|---|---|---|
| Card data handling | Scope often left vague | Built around PCI DSS practices, scope kept minimal |
| Card storage | Raw card data stored in merchant systems | Designed for tokenization, no raw card storage on your side |
| Authentication | 3DS bolted on, if at all | Supports 3-D Secure 2 & SCA where it protects you |
| Encryption | Inconsistent coverage | Designed for encryption in transit and at rest |
| Access control | Shared logins, broad access | Built around least-privilege, role-based access |
| Chargeback alerts | Found out after it posts | Designed to use Ethoca/Verifi-style alerts to catch disputes early |
| Ratio monitoring | React to threshold letters | VAMP-aware monitoring built to flag risk early |
| Reserves & payouts | Opaque holds, slow payouts | Transparent reserve terms with 2-day payouts |
Reserves, payouts and staying online
Trust is not only about how data is encrypted. For a high-risk founder it is also about whether the money moves, whether you can see what is happening, and whether the platform is there when your traffic spikes. We treat reserves and payouts as a trust point, not fine print, and we build operations to keep your revenue flowing:
- Rolling reserves are explained up front, with the percentage and release schedule stated plainly, so you always know what is held and when it comes back.
- Payouts are designed to reach you on a 2-day cycle, so your cash is not sitting in limbo while you wait to reinvest in growth.
- Smart routing across multiple dedicated MIDs is built to keep you processing even if one account has a bad day, instead of leaving you with a single point of failure.
- Operational monitoring and alerting are designed to watch availability, transaction health and dispute ratios continuously, so issues are caught early rather than discovered by your customers.
The goal is a payments setup that is not just secure on paper, but dependable in the moments that actually cost you money.
Frequently asked questions
Do you store my customers' raw card numbers?
The platform is designed so you do not have to. Card details are meant to be tokenized, so your CRM and billing work with a safe reference instead of a real card number, keeping raw card data out of your systems.
Is Resub PCI compliant, and what is the scope?
Resub is built around PCI DSS practices for handling cardholder data, with the aim of minimizing the scope that touches sensitive card data. We would rather walk your team through exactly how that applies to your setup on a call than post a claim here we cannot guarantee for your account.
How do you help with chargebacks and VAMP?
The platform is designed to connect to Ethoca and Verifi-style alert networks so disputes can be resolved before they post, and monitoring is built to be VAMP-aware, tracking the ratios the card networks watch so you can act early.
How is my customer data handled under GDPR?
Data handling is designed to be GDPR-aware: collecting what is needed, protecting it with encryption and access controls, and supporting access, correction and deletion requests. We keep the roles between you as merchant and Resub as platform clear rather than assumed.
Why should I trust your reserves and payouts?
Because we state them plainly. Rolling reserve terms and release schedules are explained up front, and payouts are designed to reach you on a 2-day cycle. If you want the specifics for your volume and risk profile, ask us on a call and we will lay it out.
One good month shouldn't end your business
- Account frozen after a volume spike
- Payout held for 90–120 days
- MID terminated with no appeal
- One shared pool, one point of failure
- Dedicated MIDs underwritten for you
- Smart routing keeps you processing
- Fair, disclosed reserves
- Decline & dispute recovery built in
Every payment routed to the MID most likely to approve
Resub scores each transaction and sends it down the healthiest path across your dedicated MIDs, in milliseconds.
Ready to stop getting frozen?
Book 20 minutes with us. We’ll map dedicated, stable MIDs to your store and give you your exact rate — no obligation.