Skip to content

    How do credit card vaulting services work?

    Credit Card Vaulting Service

     

    Today’s consumer demands an easy, frictionless checkout process. To achieve this, platforms need not only to accept a broad array of payment methods, including digital wallets, but also provide a way for customers to store and reuse their credit card information.

    Holding that information within their own systems, however, creates a serious risk. Hackers stealing payment data can have long-term ramifications. As a result, merchants are turning to credit card vaults to provide the perfect blend of convenience and security.

    What is a credit card vault? 

    A credit card vault, also called a payment vault or token vault, is a compliant system that stores customer payment information on a merchant's behalf and issues a token in its place so merchants can offer fast, repeat checkout without ever holding raw card data themselves.

    The token itself is a random string with no intrinsic value. A token won’t be reverse-engineered back into the original card number. Using a credit card vault ensures that:

    • All payment data is securely protected in a dedicated, PCI Level One store to thwart hacking attempts and data leaks.
    • Only the merchant for whom the data is stored can access it, using a combination of security protocols.
    • The merchant does not bring unencrypted, or plain text, payment information into their own payment system, allowing them to reduce the resource requirements to maintain PCI-DSS compliance.
    • The merchant can provide a smooth purchase process, particularly for repeat customers and subscription holders, that optimizes revenue flows.

    There are two types of credit card vaulting services:

    • Payment service provider (PSP) vaults are provided for the convenience and security of an individual PSP’s customer. They are secure, and often quick and easy to establish, but are inherently tied to the PSP: the merchant can generally use the stored data only to transact sales through that one provider.
    • Third-party programmable payment vaults are provided by independent companies, like Basis Theory. These vaults offer the same high level of security and may take a little more setup in the early going, but they are not associated with any particular PSP: the merchant can direct the vault provider to submit deals to any downstream processor they choose.

    Many, if not most, online merchants elect to contract with a full-service PSP when they start their business, in order to get started as rapidly and with as predictable a fee schedule as possible. However, all the credit card data they place into that PSP’s vault is effectively marooned there - which is why, as merchants expand and look to contract with a stable of PSPs, specializing in particular geographies or market segments, they tend to migrate to a third-party vault.

    Return to Top

    Why would I use a credit card vaulting service? 

    Credit card vaulting with a third-party provider is one of the few strategic moves a merchant can make that brings both risk reduction and the chance for revenue growth. That’s because it enables

    • Data protection, both in motion and at rest. Credit card details are collected, and stored, in a vault that is wholly separate to the merchant’s underlying payment system. The details cannot, therefore, be hacked or leaked. The worst case scenario in a system penetration event is that the attacker collects tokens that they cannot use
    • Reduced investment in PCI-DSS compliance. Because sensitive data is kept externally, the core system remains out of scope, reducing the strain of maintaining strict regulatory compliance
    • Smoother transactions. Customers can reliably store their credit card data for future use, and for automatic subscription payments, making it quicker and easier to transact business with the merchant. In addition, when using a third-party vault, the merchant can direct all transactions to the processor most likely to be able to complete the deal, eliminating the risk of soft declines

    Customers can confidently build a long-term relationship with the merchant, with satisfyingly reliable and rapid purchase processes.

    Return to Top

    What are the risks of credit card vaulting? 

    The risks vary depending on the model selected by the merchant. When using a PSP’s dedicated vaulting service, the primary risk is vendor lock-in: because it is the PSP that holds the underlying data, it can be difficult, if not impossible, to persuade them to allow the merchant to transfer that information elsewhere in the event of a provider change. Indeed, the proprietary nature of the PSP vault also means that all payment transactions must run through that provider, eliminating the option of executing a comprehensive multi-processor strategy.

    When using a third-party credit card vaulting service, the risks are somewhat different. Certainly, there is the risk of vendor lock-in if the merchant opts to move to a different provider: this is why it is important to ensure that the service guarantees a smooth transition should you decide to take your business elsewhere.

    So long as the lock-in issue is resolved, the greatest challenge may be the initial setup (though experience suggests this may not be a significant hurdle to clear), and the maintenance, as the merchant expands their stable of downstream payment providers.

    Return to Top

    How do credit card vaulting services help with PCI compliance? 

    Any business that wants to accept credit cards must comply with PCI-DSS, an industry standard that ensures customer information is safely and securely collected, stored, and used. Merchants who want to retain customer information, therefore, must ensure their system is aligned to the PCI requirements, which can be an expensive and time-consuming task.

    By using a third-party vaulting service, the merchant can limit the data that enters their system, reducing the weight of maintaining PCI compliance. Because that information cannot be stolen from them, merchants can reduce resource intensity and the cost burden by a significant margin, freeing up time and money to focus on their core business.

    A credit card vault does not eliminate PCI compliance requirements, but it significantly reduces PCI scope. Since raw card data never enters the merchant's or platform’s systems, the compliance burden and audit costs both shrink.

    Merchants and platforms working with multiple PSPs should consider third-party credit card vaulting services.

    Return to Top

    Stay Connected

    Receive the latest updates straight to your inbox