Skip to content

    Do I buy or build a PCI compliant payment vault?

    Do I buy or build a PCI compliant payment vault?

    Managing the costs and risks associated with personally identifiable information (PII) is a fundamental challenge for merchants building and maintaining the payment systems they need to operate their businesses. For many, delivering that information to a PCI Level One vault is the most effective approach. The core payments system stays out of PCI scope, and provides clear security benefits for customers.

    The challenge is working out whether to build or buy the technology to make this a PCI compliant payment vault a reality. Software supply chain security can make the choice to outsource PCI compliance feel risky. Fears of undue influence by vendors are real, and need to be considered as part of the bigger picture to buy or build this technology.

    Why does PCI compliance loom so large? 

    PCI-DSS is the industry standard for storing and protecting consumer payment data.

    In order to transact business through credit cards, and many other payment methods, all merchants are required to commit to the PCI standard. This sets strong standards for merchants, as data leaks and hacks can have immediate economic and long-term reputational consequences.

    However, the cost to maintain a PCI-compliant payment system can be substantial, in terms of both investment dollars and time. This is because every part of a payment system that has access to customer data in plain text must be verified according to the standard.

    Anything from web pages to the data storage, and even the security of rooms where customer service reps access computers that can display customer information. Even your chatbot.

    As the volume of transactions increases for a merchant, so too does the level of scrutiny, and the cost of maintaining compliance.

    Return to Top

    How does a payment vault help merchants maintain PCI compliance? 

    Because the PCI-DSS standard covers all the elements of the payments system that access customer data in plain text, a critical option to reduce the cost and resource drain of compliance is to limit the places where that data is stored and accessed. A payment vault, used particularly to limit PCI costs and overhead, can divert plain text customer data away from the core payments system.

    Instead of receiving the customer’s credit card number and submitting it to a payment service provider (PSP) or payment orchestrator for processing, the data is delivered to a vault.

    The vault passes the payment system a token, which cannot be decrypted or in any other way reverse-engineered to reveal the actual underlying data; then passes the token back to the vault with instructions on where to send the actual data for processing. In this way, the vault must, of course, be fully PCI-compliant but the payment system stays out of scope because it never actually touches the customer’s data.

    Consider the decision Felix made to move from payment orchestration to token ownership. By removing the payment orchestrator from the transaction process, payment latency was cut in half. Existing payment tokens were migrated from the orchestrator and into Basis Theory’s payment vault.

    “We own the tokens, so we can just go ahead and integrate directly with a PSP API,” says Emilio Muñoz, Software Engineering Manager at Felix. “We don’t have to rely on the orchestrator.”

    Return to Top

    What is the difference between buying and building a PCI payment vault? 

    Broadly speaking, ‘buying’ a PCI vault means contracting with a token vault provider, who operates an online system that can collect and store customer information, and supplies programmatic interfaces to use that information without ever bringing it inside the core payment system.

    Because the data never enters the merchant’s systems in plain text, the PCI benefits are instantly recognized, although there is naturally a cost to the vault service provider.

    By contrast, ‘building’ a PCI vault means exactly what it says: the merchant will own, and maintain the payment vault. While this eliminates the cost of paying a third-party, it brings its own challenges from the technical (infrastructure must be carefully planned and executed to ensure plain text data is fully segregated) to the financial (although no fees are paid to a provider, the system must be monitored, updated, and maintained).

    Building a payment vault takes time and expertise, as well as an ongoing commitment to administration. The long-term cost savings for large merchants are certainly present, offset by longer implementation cycles and trickier maintenance requirements.

    Return to Top

    What should I consider when choosing between building and buying a payment vault? 

    Similar principles apply when choosing to build or buy a PCI payment vault, as would be in play for any software system:

    • Speed to market. Building generally takes longer than buying, so if time to market is a significant concern, lean toward buying.
    • In-house skills. With an already skilled team that knows how to build and maintain complex infrastructure, it can make sense to build. If these folks are missing or already stretched thin, buying becomes more realistic
    • Balance fixed versus variable costs. If the preference is a fixed, well-articulated cost basis, a third-party can make it easier to model their budget to be more predictable. By contrast, those who prefer to continue seeking future tweaks that can produce cost savings (at the risk of periodic unexpected costs due to unforeseen maintenance/upgrade needs) may opt to build internally.
    • Infrastructure flexibility. Because the vault must be kept entirely separate from the underlying payments system (to minimize PCI scope), choosing to build it means having the flexibility to fully segregate the two systems. Those without that sort of flexibility may be better off buying their own vault solution.

    Choose your own adventure. The shortest path is to contract with a payment vault provider like Basis Theory. A vault can be live in days, with the Basis Theory team responsible for migrations, vault maintenance, security, and feature development. By contrast, those who build should set aside a number of months for the initial creation process, and assign personnel on an ongoing basis to maintain and develop the system, and retain the potential financial and reputational risks of security breaches.

    Get started in the Basis Theory Portal to find out what adventure is best for you.

    Return to Top

    Stay Connected

    Receive the latest updates straight to your inbox