This might not be the right channel for this... I have a question about SSP app security. We had a vendor build an SSP app for us where a customer can essentially order an item from our store on one page. They select the amount, type in their name and credit card details, hit submit and a sales order is created in NetSuite. I am pretty new to SSP apps and I am not a web developer by any means.
My question is this, if a customer accesses the page through http and not https are their credit card details (and other form data) still transferred to NetSuite in a secure way? In other words do SSP apps always work securely with NetSuite just based off of how they communicate with the system, or is it critical the customer also accesses the page via https?