Show HN: Your personal payment processing server
medium.com
medium.com
It means the credit card details are never sent to your server, so you are not required to meet the full terms of PCI Compliance on your server
You also need to consider things such as: if the process crashes, does it produce an error log or exception trace with the request information?
Given that Payum is written in PHP and uses the Symphony HTTP Request class, let's consider that in 5.6+, fopen('php://input') (i.e. read the request body) can cause a temp file to be created with the contents of the request body stored in it.
So even if you don't intend to store the request, the underlying technologies often store data transparently (albeit temporarily).
It is not end solution. It does not provide API, backend UI, integration with a storage. It takes a bit more time to setup it. Plus, you have to be a developer (preferably Ruby one) to use it.
PayumServer requires as few programming knowledge as possible. You can use it with any of your app, written on whatever language you like.
It is already used in many projects, in production, well tested. The 1.0.0 version was released not long ago.