Security & Payment Data Policy

Last updated: September 9, 2026

This policy describes our security capabilities and how payment card details are transmitted and protected. For how we handle personal data generally, see our Privacy Policy.

1. Payment Card Data Handling

FBG Holding LLC does not collect, process, or store cardholder data on its own servers. Card payments are handled exclusively by PCI DSS compliant payment providers:

  • Bank of America Merchant Services — merchant acquiring and card processing
  • Authorize.Net — payment gateway for invoice and card-not-present transactions
  • PayPal — alternative payment channel

When you pay by card, your card details are submitted directly to the payment provider's secure environment. Full card numbers, expiration dates, and security codes (CVV/CVC) are never transmitted to, written to, or retained on FBG systems, and are not accessible to FBG personnel. We retain only the transaction reference, the last four digits, and the card brand for reconciliation and accounting purposes.

2. Transmission Security

  • All traffic to and from fbgholding.com is served over HTTPS using TLS 1.2 or higher, with modern cipher suites, and HTTP requests are automatically redirected to HTTPS.
  • Payment pages and gateway interactions are encrypted end-to-end by the payment provider.
  • Card security codes (CVV/CVC) are never stored by any party after authorization, in line with PCI DSS requirements.
  • We do not accept card details by email, chat, or any unencrypted channel. If you send card details this way, we will ask you to use a secure payment link instead.

3. PCI DSS Compliance Position

Because card data is captured entirely within our providers' PCI DSS compliant environments and never enters FBG infrastructure, FBG's own compliance scope is limited accordingly. Our payment providers maintain PCI DSS Level 1 certification, the highest level defined by the PCI Security Standards Council.

4. Infrastructure and Operational Security

  • Access control: role-based access, least-privilege provisioning, and multi-factor authentication on administrative accounts.
  • Network protection: managed firewalls, WAF and CDN filtering, and DDoS mitigation.
  • Encryption: encrypted transport for data in transit and encryption at rest for stored operational data.
  • Monitoring: continuous infrastructure monitoring, logging, and alerting for anomalous activity.
  • Patch management: proactive vulnerability and patch management across managed systems.
  • Backups: regular backups with tested restoration procedures.

5. Incident Response

We maintain documented incident response procedures covering detection, containment, remediation, and notification. Where a security incident affects client data, we notify affected clients without undue delay and cooperate with applicable regulatory reporting obligations.

6. Reporting a Security Concern

If you believe you have found a vulnerability affecting our website or services, or suspect fraudulent use of your payment details, contact us immediately at [email protected]. If you suspect your card has been compromised, also contact your card issuer directly using the number on the back of your card.

7. Contact