Card data is entered on the bank's secure page, not on the SDT site. SDT does not receive or store card numbers, CVV or expiry. HTTPS with a valid SSL certificate is used in production; card processing follows the payment systems' requirements (PCI DSS on the bank/provider side). Card logos and the pay button appear only after the method is connected.