CyberSource

CyberSource

CyberSource scripts embed hosted payment form components within PCI-compliant iframes on checkout pages. Device fingerprinting scripts run fraud screening by collecting browser characteristics and behavioral signals. Transaction data is processed through Visa's payment management infrastructure.

Overview

CyberSource, a Visa subsidiary, is one of the world's largest payment management platforms, processing transactions for businesses of every size across virtually every payment method and geography. When CyberSource's scripts appear on merchant websites, they serve two critical functions: rendering secure payment forms that keep card data off the merchant's servers, and running device fingerprinting for fraud detection.

The dual nature of CyberSource's scripts — essential payment processing combined with sophisticated fraud screening — makes it a foundational component of enterprise e-commerce infrastructure.

What This Script Does

CyberSource's scripts handle payment processing and fraud prevention on checkout pages:

  • Hosted payment form components: Renders card input fields (card number, expiry, CVV) within PCI-compliant iframes, ensuring sensitive payment data is captured directly by CyberSource's servers and never touches the merchant's infrastructure
  • Card tokenization: Converts entered payment credentials into secure tokens that merchants can use for processing without handling raw card data
  • Device fingerprinting: Collects browser characteristics, device attributes, and behavioral signals — including screen resolution, installed plugins, timezone, language settings, and mouse/keyboard interaction patterns — to build a device profile for fraud risk assessment
  • 3D Secure authentication: Manages Strong Customer Authentication flows (3DS2) required by PSD2 for European transactions, presenting bank verification screens within the checkout experience
  • Transaction risk scoring: Feeds collected device and behavioral data into CyberSource's Decision Manager fraud screening engine, which returns risk scores and recommended actions
  • Session management: Sets cookies to maintain payment session state and link fraud screening data to the active transaction

Consent & Compliance

CyberSource operates within a well-defined compliance framework:

  • GDPR: Payment processing falls under "performance of a contract" (Article 6(1)(b)). Fraud prevention has additional lawful bases including legitimate interest and legal obligation. CyberSource/Visa acts as both a data processor and, for fraud prevention, a data controller.
  • ePrivacy Directive: Payment session cookies and fraud detection mechanisms are strictly necessary for the service the customer requested (completing a purchase) and for preventing fraud, exempting them from consent requirements.
  • PCI DSS: CyberSource is PCI DSS Level 1 certified. The hosted payment fields are specifically engineered to keep merchants out of PCI scope.
  • PSD2/SCA: CyberSource handles Strong Customer Authentication requirements and manages transaction risk analysis for exemption processing.

Should You Block This Without Consent?

CyberSource's scripts are essential payment infrastructure. The hosted payment forms process transactions that customers explicitly initiated, and the fraud screening protects both the merchant and the customer from fraudulent activity. Both functions fall under the strictly necessary exemption — blocking these scripts would prevent customers from completing purchases and remove fraud protection from the checkout process.

No.

Is CyberSource GDPR compliant?

CyberSource typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So CyberSource can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads CyberSource, not on CyberSource itself.

Visit website

Consent Categories

Also Known As

cybersourcecybersource paymentscybersource fraudcybersource device fingerprintvisa cybersourcecybersource checkout

Industries

Computers Electronics and Technology

Tracked Domains (1)

cybersource.comEssential

cybersource.com is an essential domain operated by CyberSource, used to keep the site working, including security, load balancing, and sessions.

Frequently Asked Questions

Related Vendors

Rollbar
Rollbar
Error tracking and monitoring platform that captures JavaScript exceptions and logs them with full context for debugging. The Rollbar SDK sends error payloads including stack traces, request data, and custom metadata. Does not engage in advertising or behavioral tracking.
Vonage
Vonage
Vonage client SDKs may embed voice and video calling interfaces in web applications. Scripts manage WebRTC sessions, handle call routing, and may collect call metadata. Primarily a backend telecom platform; web embedding is limited to specific communication feature integrations.
Auth0
Auth0
Auth0 is an identity-as-a-service platform providing authentication, authorization, and SSO for web and mobile applications. Scripts handle login flows, token management, and session persistence using Auth0's Universal Login. Integrates with social providers, enterprise IdPs, and MFA to secure application access.
Elavon
Elavon
Elavon scripts embed hosted payment forms for processing card transactions on merchant websites. Scripts handle card data within Elavon's PCI-compliant hosted environment, preventing direct handling of sensitive card data by the merchant. Session data is used for fraud prevention.
Jscrambler
Jscrambler
Jscrambler scripts protect JavaScript application code running in the browser through obfuscation, tampering detection, and runtime integrity monitoring. Scripts may also detect and block unauthorized third-party script injections and report client-side security events.
Square
Square
Square scripts embed hosted payment forms and checkout components for processing card transactions on merchant websites. Scripts handle card tokenization within Square's PCI-compliant iframe environment. Session data is used for fraud prevention and transaction processing.

Manage consent for CyberSource

ConsentStack automatically detects and manages CyberSource trackers so your site stays compliant with global privacy regulations.