Orbit & PAR Pay/PCI
13. Orbit and Local Store Communications
Orbit and local store services coordinate store-side communications for supported PAR deployments. These services should remain on approved POS or local services segments and should communicate outbound to approved PAR destinations.
Figure 3. Conceptual Orbit, MQTT/HTTPS, PAR cloud, and PAR Pay communication flow.
| Component | Network expectation | Evidence |
|---|---|---|
| Orbit/local service | Stable LAN address and outbound access to approved PAR endpoints | Endpoint inventory and firewall log |
| MQTT/HTTPS path | Outbound only unless a site-specific design says otherwise | Successful connection test |
| Store POS endpoints | Can reach local service and required cloud endpoints | POS health check |
14. PAR Pay and PCI Considerations
Payment connectivity must be reviewed with the merchant's compliance owner, payment processor, and QSA where applicable. Network design should reduce PCI scope through segmentation, least privilege, and documented control ownership.
| Area | Customer-facing expectation | Compliance owner check |
|---|---|---|
| Segmentation | Payment-adjacent systems are isolated from guest and office traffic. | Confirm scope boundary. |
| Firewall | Only approved payment and PAR Pay destinations are allowed. | Review rulebase and logs. |
| TLS | Avoid breaking certificate validation or payment service trust chains. | Confirm inspection exemptions. |
| Logging | Retain relevant firewall and endpoint logs. | Define retention period. |
| Evidence | Keep change tickets, rule exports, and validation samples. | Attach to compliance package. |