Skip to content
SaaS Configurator

How to improve the security of my SaaS Checkout process

There are several steps you can take to enhance the security of your SaaS checkout. These measures can help prevent phishing scammers from signing up and…

6 min read1,390 words10 explained imagesUpdated Tue, 21 Jan, 2025 at 7:07 PM
View as markdownOpen in ClaudeOpen in ChatGPT
Each image has a one line explanation. Switch to full detail for the step it belongs to, the fields and buttons involved, examples and the whole procedure.
On this page
  1. Useful rules we recommend
  2. 3D Secure Authentication Rules
  3. Block Rules
  4. Review Rules
  5. Q: I followed these steps but a scammer was still able to signup. What do I do?
  6. Q: What is Funnel/Website v2 and how does it enhance security?
  7. Q: What is Custom Authorization and how does it work?
  8. Q: Why should I consider using LC Phone & LC Email over Twilio or Mailgun?
  9. Q: How can I enable Phone Number & Email Verification for my SaaS signups?
  10. Q: What is Stripe Radar and how does it help in fraud prevention?
  11. Q: How can I set up rules in Stripe Radar for handling transactions?
  12. Q: What action should I take if a flagged payment appears in Stripe Radar?

There are several steps you can take to enhance the security of your SaaS checkout. These measures can help prevent phishing scammers from signing up and misusing your SaaS sub-account.

TABLE OF CONTENTS

Step 1 - Use Funnel/Website v2

If you're currently using GHL Customer Care funnels & websites for SaaS sales, it's advisable to switch to v2 funnels & websites. The newer version supports native Stripe integration and 3D secure technology, ensuring a more secure checkout experience.

Step 1 - Use Funnel/Website v2 (image 1 of 10) What this shows If you're currently using GHL Customer Care funnels & websites for SaaS sales, it's advisable to switch to v2 funnels & websites. What this shows Illustrates the "Step 1 - Use Funnel/Website v2" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "Step 1 - Use Funnel/Website v2" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: If you're currently using GHL Customer Care funnels & websites for SaaS sales, it's advisable to switch to v2 funnels & websites. The newer version supports native Stripe integration and 3D secure technology, ensuring a more secure checkout experience. Immediately after, the guide continues: Adding an authorization amount to your SaaS products with a trial is the best way to ensure only real credit cards with enough balance are able to get through your signup process. Image 1 of 10 What this coversIf you're currently using GHL Customer Care funnels & websites for SaaS sales, it's advisable to switch to v2 funnels & websites. The newer version supports native Stripe integration and 3D secure technology, ensuring a more secure checkout experience. Next stepAdding an authorization amount to your SaaS products with a trial is the best way to ensure only real credit cards with enough balance are able to get through your signup process.

Step 2 - Add Custom Authorization to your trial

Adding an authorization amount to your SaaS products with a trial is the best way to ensure only real credit cards with enough balance are able to get through your signup process. 

You can enter an authorization amount on your sales funnel by going to funnel -> Products -> Additional Options -> Custom Authorization.

Step 2 - Add Custom Authorization to your trial (image 2 of 10) What this shows You can enter an authorization amount on your sales funnel by going to funnel -> Products -> Additional Options -> Custom Authorization. What this shows Illustrates the "Step 2 - Add Custom Authorization to your trial" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "Step 2 - Add Custom Authorization to your trial" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: You can enter an authorization amount on your sales funnel by going to funnel -> Products -> Additional Options -> Custom Authorization. Immediately after, the guide continues: A Custom Authorization is especially helpful when your SaaS product has a trial. It sim ply creates a payment intent and validates that the card is real and has sufficient balance. The customer is NOT charged and the payment is refunded…. Image 2 of 10 What to fill inYou can enter an authorization amount on your sales funnel by going to funnel -> Products -> Additional Options -> Custom Authorization. Next stepA Custom Authorization is especially helpful when your SaaS product has a trial. It sim ply creates a payment intent and validates that the card is real and has sufficient balance. The customer is NOT charged and the payment is refunded immediately.
Step 2 - Add Custom Authorization to your trial (image 3 of 10) What this shows You can enter an authorization amount on your sales funnel by going to funnel -> Products -> Additional Options -> Custom Authorization. What this shows Illustrates the "Step 2 - Add Custom Authorization to your trial" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "Step 2 - Add Custom Authorization to your trial" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: You can enter an authorization amount on your sales funnel by going to funnel -> Products -> Additional Options -> Custom Authorization. Immediately after, the guide continues: A Custom Authorization is especially helpful when your SaaS product has a trial. It sim ply creates a payment intent and validates that the card is real and has sufficient balance. The customer is NOT charged and the payment is refunded…. Image 3 of 10 What to fill inYou can enter an authorization amount on your sales funnel by going to funnel -> Products -> Additional Options -> Custom Authorization. Next stepA Custom Authorization is especially helpful when your SaaS product has a trial. It sim ply creates a payment intent and validates that the card is real and has sufficient balance. The customer is NOT charged and the payment is refunded immediately.

A Custom Authorization is especially helpful when your SaaS product has a trial. It sim ply creates a payment intent and validates that the card is real and has sufficient balance. The customer is NOT charged and the payment is refunded immediately. 

Note
- Custom Authorization does NOT charge the customer. It creates a payment intent and immediately refunds it
- It's recommended to set the authorization amount equal to the monthly fee of your most basic plan.

Step 3 - Use LC Phone & LC Email

Using Twilio or Mailgun is risky for SaaS agencies because of latency in rebilling. This allows scam artists and bad actors to rack up your Twilio & Mailgun usage before the location credits are debited. This latency is caused by delays in usage records and webhooks that we receive from Twilio or Mailgun. 

Using LC Phone & LC Email allows us to prevent that latency and also gives you access to additional security features like

  1. Ramped usage for SMS, Email, VM drops, etc. 
  2. Maximum sending limits on Sub-accounts
  3. Error rate, unsubscribe rate & complaint rate monitoring

LC Email Ramp 

LC Phone Ramp 

LC Email error thresholds & sending limit 

LC Phone error thresholds 

LC Email Verification  

All these technologies run in the background to minimize the chances of bad actors misusing your SaaS sub-account.

Migration to LC Phone & LC Email is easier than you may think. 

How do I migrate my agency and sub-account over to LC Phone?

How to Migrate My Agency Over to LC - Email

Step 4 - Enable Phone Number & Email Verification by default

Boost the security of future SaaS signups by enabling Phone Number and Email Verification. 

  • Email Verification is mandatory by default for all SaaS signups.
  • You can enable Phone Number verification for future SaaS signups by heading over to Agency Level -> Left Menu -> SaaS Configurator -> Security Settings -> Toggle : Verify Phone Number using a security code during sign-up
  • To enable email verification for all your existing sub-accounts please head over to Agency Level -> Left Menu -> Settings -> Email Services -> Sub-Account Settings -> Enable Email Verification for all sub-accounts

Step 5 - Use Stripe Radar

Stripe Radar is a fraud prevention suite integrated into the Stripe payment platform, utilizing machine learning algorithms trained on vast global data to detect and deter fraudulent transactions. It enables businesses to set custom rules to handle transactions based on specific parameters and provides detailed insights into flagged activities. Additionally, Radar offers features like adaptive acceptance, which dynamically requests added authentication for riskier payments, and a review dashboard for manual assessment. Integrated natively with Stripe, it offers a streamlined approach to online transaction security, reducing the need for third-party tools.

Stripe Radar is a paid product by Stripe but highly recommended for SaaS Agencies

Stripe Radar

Please log into your Stripe account and head over to Dasboard -> More -> Radar for Fraud Teams

Step 5 - Use Stripe Radar (image 4 of 10) What this shows Please log into your Stripe account and head over to Dasboard -> More -> Radar for Fraud Teams What this shows Illustrates the "Step 5 - Use Stripe Radar" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "Step 5 - Use Stripe Radar" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: Please log into your Stripe account and head over to Dasboard -> More -> Radar for Fraud Teams. Immediately after, the guide continues: You can add Radar rules by heading over to the rules tab. Image 4 of 10 What this coversPlease log into your Stripe account and head over to Dasboard -> More -> Radar for Fraud Teams Next stepYou can add Radar rules by heading over to the rules tab

Useful rules we recommend

You can add Radar rules by heading over to the rules tab

3D Secure Authentication Rules

These rules will allow the payment to go through if 3D Secure is authenticated

3D Secure Authentication Rules (image 5 of 10) What this shows These rules will allow the payment to go through if 3D Secure is authenticated What this shows Illustrates the "3D Secure Authentication Rules" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "3D Secure Authentication Rules" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: These rules will allow the payment to go through if 3D Secure is authenticated. Immediately after, the guide continues: These rules will allow the payment to occur but they will be successful only if a human reviews and approves them. Image 5 of 10 What this coversThese rules will allow the payment to go through if 3D Secure is authenticated
Buttons and menus referenced Block Rules
Next stepThese rules will allow the payment to occur but they will be successful only if a human reviews and approves them

Block Rules

These rules will block they payment altogether

Block Rules (image 6 of 10) What this shows Block Rules These rules will block they payment altogether What this shows Illustrates the "Block Rules" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "Block Rules" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: Block Rules These rules will block they payment altogether. Immediately after, the guide continues: These rules will allow the payment to occur but they will be successful only if a human reviews and approves them. Image 6 of 10 What this coversBlock Rules These rules will block they payment altogether
Buttons and menus referenced Block Rules
Next stepThese rules will allow the payment to occur but they will be successful only if a human reviews and approves them

Review Rules

These rules will allow the payment to occur but they will be successful only if a human reviews and approves them

Review Rules (image 7 of 10) What this shows These rules will allow the payment to occur but they will be successful only if a human reviews and approves them What this shows Illustrates the "Review Rules" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "Review Rules" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: These rules will allow the payment to occur but they will be successful only if a human reviews and approves them. Immediately after, the guide continues: You can see all your pending reviews by heading over to the reviews tab in Radar. It looks like this. Image 7 of 10 What this coversThese rules will allow the payment to occur but they will be successful only if a human reviews and approves them Next stepYou can see all your pending reviews by heading over to the reviews tab in Radar. It looks like this

You can see all your pending reviews by heading over to the reviews tab in Radar. It looks like this

Review Rules (image 8 of 10) What this shows You can see all your pending reviews by heading over to the reviews tab in Radar. What this shows Illustrates the "Review Rules" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "Review Rules" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: You can see all your pending reviews by heading over to the reviews tab in Radar. It looks like this. Immediately after, the guide continues: As an agency admin or owner you can approve or refund these payments manually. Image 8 of 10 What this coversYou can see all your pending reviews by heading over to the reviews tab in Radar. It looks like this Next stepAs an agency admin or owner you can approve or refund these payments manually.

As an agency admin or owner you can approve or refund these payments manually. 


FAQ:

Q: I followed these steps but a scammer was still able to signup. What do I do?

A: All the rules mentioned above are best practices and they will prevent your SaaS sub-accounts from being misused in most cases. However, some bad actors might still be able to get through in rare instances. 

In such cases the best thing is to refund all fraudulent payments and specifically mark them as fraudulent. 

Q: I followed these steps but a scammer was still able to signup. What do I do? (image 9 of 10) What this shows In such cases the best thing is to refund all fraudulent payments and specifically mark them as fraudulent. What this shows Illustrates the "Q: I followed these steps but a scammer was still able to signup. What do I do?" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "Q: I followed these steps but a scammer was still able to signup. What do I do?" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: In such cases the best thing is to refund all fraudulent payments and specifically mark them as fraudulent. This part of the guide covers 2 fields, listed below. Immediately after, the guide continues: When refunding the payment please select it as "Fraudulent". This is VERY IMPORTANT. Image 9 of 10 What this coversIn such cases the best thing is to refund all fraudulent payments and specifically mark them as fraudulent.
Fields in this part of the guide Adds the card fingerprint to your blocklistAdds the email ID to your blocklist
Next stepWhen refunding the payment please select it as "Fraudulent". This is VERY IMPORTANT.
All 3 steps in this procedure
  1. Adds the card fingerprint to your blocklist
  2. Adds the email ID to your blocklist
  3. Sends various signals like IP, email, card number, etc to Stripe which makes it more accurate over time
Q: I followed these steps but a scammer was still able to signup. What do I do? (image 10 of 10) What this shows In such cases the best thing is to refund all fraudulent payments and specifically mark them as fraudulent. What this shows Illustrates the "Q: I followed these steps but a scammer was still able to signup. What do I do?" section of "How to improve the security of my SaaS Checkout process". This screenshot appears in the "Q: I followed these steps but a scammer was still able to signup. What do I do?" section of "How to improve the security of my SaaS Checkout process". The text alongside this image reads: In such cases the best thing is to refund all fraudulent payments and specifically mark them as fraudulent. This part of the guide covers 2 fields, listed below. Immediately after, the guide continues: When refunding the payment please select it as "Fraudulent". This is VERY IMPORTANT. Image 10 of 10 What this coversIn such cases the best thing is to refund all fraudulent payments and specifically mark them as fraudulent.
Fields in this part of the guide Adds the card fingerprint to your blocklistAdds the email ID to your blocklist
Next stepWhen refunding the payment please select it as "Fraudulent". This is VERY IMPORTANT.
All 3 steps in this procedure
  1. Adds the card fingerprint to your blocklist
  2. Adds the email ID to your blocklist
  3. Sends various signals like IP, email, card number, etc to Stripe which makes it more accurate over time
When refunding the payment please select it as "Fraudulent". This is VERY IMPORTANT. 

By refunding the payment and marking it as fraudulent Stripe Radar automatically gets smarter over time and prevents more scams from happening. 

It automatically 

  • Adds the card fingerprint to your blocklist
  • Adds the email ID to your blocklist
  • Sends various signals like IP, email, card number, etc to Stripe which makes it more accurate over time

Q: What is Funnel/Website v2 and how does it enhance security?

A: Funnel/Website v2 is an upgraded version of GHL Customer Care funnels & websites. It supports native Stripe integration and 3D secure technology, which significantly improves the security of your SaaS checkout.

Q: What is Custom Authorization and how does it work?

A: Custom Authorization is a feature that allows you to add an authorization amount to your SaaS products with a trial. It ensures that only real credit cards with sufficient balance can sign up. The customer is not charged; instead, a payment intent is created to validate the card's authenticity and immediately refunded.

Q: Why should I consider using LC Phone & LC Email over Twilio or Mailgun?

A: Using Twilio or Mailgun can be risky due to latency in rebilling, which can be exploited by scammers. LC Phone & LC Email prevent this latency and offer additional security features like ramped usage, sending limits, and error rate monitoring.

Q: How can I enable Phone Number & Email Verification for my SaaS signups?

A: You can enable these verifications through the Agency Level settings. For phone number verification, navigate to Settings -> Phone Integration. For email verification, go to Settings -> Email Services.

Q: What is Stripe Radar and how does it help in fraud prevention?

A: Stripe Radar is a fraud prevention suite integrated into the Stripe payment platform. It uses machine learning algorithms to detect and deter fraudulent transactions. It allows businesses to set custom rules for transactions and provides insights into flagged activities.

Q: How can I set up rules in Stripe Radar for handling transactions?

A: You can add Radar rules by heading over to the rules tab in your Stripe account. There are different types of rules, such as 3D Secure Authentication Rules, Block Rules, and Review Rules, to customize how transactions are handled.

Q: What action should I take if a flagged payment appears in Stripe Radar?

A: If a payment is flagged in Stripe Radar, you can review it manually. As an agency admin or owner, you have the option to approve or refund these payments based on your assessment.

Frequently asked questions

Q: I followed these steps but a scammer was still able to signup. What do I do?
A: All the rules mentioned above are best practices and they will prevent your SaaS sub-accounts from being misused in most cases. However, some bad actors might still be able to get through in rare instances. In such cases the best thing is to refund all fraudulent payments and specifically mark them as fraudulent. When refunding the payment please select it as "Fraudulent". This is VERY IMPORTANT. By refunding the payment and marking it as fraudulent Stripe Radar automatically gets smarter over time and prevents more scams from happening. It automatically Adds the card fingerprint to your blocklist Adds the email ID to your blocklist Sends various signals like IP, email, card number, etc to Stripe which makes it more accurate over time
Q: What is Funnel/Website v2 and how does it enhance security?
A: Funnel/Website v2 is an upgraded version of GHL Customer Care funnels & websites. It supports native Stripe integration and 3D secure technology, which significantly improves the security of your SaaS checkout.
Q: What is Custom Authorization and how does it work?
A: Custom Authorization is a feature that allows you to add an authorization amount to your SaaS products with a trial. It ensures that only real credit cards with sufficient balance can sign up. The customer is not charged; instead, a payment intent is created to validate the card's authenticity and immediately refunded.
Q: Why should I consider using LC Phone & LC Email over Twilio or Mailgun?
A: Using Twilio or Mailgun can be risky due to latency in rebilling, which can be exploited by scammers. LC Phone & LC Email prevent this latency and offer additional security features like ramped usage, sending limits, and error rate monitoring.
Q: How can I enable Phone Number & Email Verification for my SaaS signups?
A: You can enable these verifications through the Agency Level settings. For phone number verification, navigate to Settings -> Phone Integration. For email verification, go to Settings -> Email Services.
Q: What is Stripe Radar and how does it help in fraud prevention?
A: Stripe Radar is a fraud prevention suite integrated into the Stripe payment platform. It uses machine learning algorithms to detect and deter fraudulent transactions. It allows businesses to set custom rules for transactions and provides insights into flagged activities.
Q: How can I set up rules in Stripe Radar for handling transactions?
A: You can add Radar rules by heading over to the rules tab in your Stripe account. There are different types of rules, such as 3D Secure Authentication Rules, Block Rules, and Review Rules, to customize how transactions are handled.
Q: What action should I take if a flagged payment appears in Stripe Radar?
A: If a payment is flagged in Stripe Radar, you can review it manually. As an agency admin or owner, you have the option to approve or refund these payments based on your assessment.

Was this guide helpful?

Related guides