> ## Documentation Index
> Fetch the complete documentation index at: https://doc-test-my.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Shared Responsibility Model

> Know about the security responsibilities shared between businesses and Razorpay.

Razorpay is a shared payment service provider. You bear some responsibility for the security of your payment ecosystem.

Razorpay is responsible for all the backend systems and payment data we process and share with banks. Our security and compliance programme ensures that we are always compliant against PCI-DSS, ISO 27001 and SOC 2 global compliance standards.

We also provide you with a facility to [generate API keys](/docs/api/authentication#generate-api-keys) and connect to our systems via automated computer programmes.

## While Using Our Payment Gateway

### Standard Checkout

It is critical to ensure the security of your **API keys** and **Dashboard credentials**. Ensure that you store these details in safe places and only share them with trusted team members.

Additionally, ensure that a customer's payment information only reaches your servers if you are [PCI DSS](https://www.pcisecuritystandards.org/about_us/) certified.

<Info>
  **Sensitive Data**

  On the Razorpay Payment Gateway, all the details entered by a user, like their name, address, and credit/debit card information, are used only to process and complete the order. Razorpay never stores sensitive information like CVV numbers, PINs and so on.
</Info>

### Related Information

* [Razorpay Security](/docs/security)
* [Security Checklist](/docs/security/checklist)
