Billing walkthrough
Billing & subscription — Activate a tier. See the secure Stripe-hosted checkout, receipt, and billing portal. Subscription selection → Stripe-hosted checkout → receipt → billing portal. PCI-DSS SAQ-A posture. XOLVARA never sees or stores card data. Billing is handled by Stripe under our PCI-DSS SAQ-A posture. We never see or store card numbers. Every Stripe webhook is signature-verified before any subscription row is written. If your organization has been issued a validation code, it can be entered during checkout. Lifecycle events (renewal, payment failure, cancellation) all append immutable audit rows. What XOLVARA does not do here: We don't bill insurance. We don't run claims through clearinghouses (in our public roadmap). We don't touch your patients' card data — Stripe handles every payment. We don't store, log, or transmit card numbers, CVV, or expiration on XOLVARA infrastructure.