What is a data tokenization platform? More than a vault.
Data tokenization is the process of generating a digital identifier—called a token—to reference an original value. If we tokenized an original value like a credit card number, we’d create a token that might look like bb8b7ed0-fee5-11ec-9686-ff66557783a8.
Data tokenization allows developers to safely use sensitive data within their applications, databases, or devices without exposing the system to the risks and requirements of holding it—unlike encryption, which is designed to be reversed once the original data reaches its intended destination.
Data tokenization vendors offer the complete infrastructure a merchant needs to replace their sensitive payment data with tokens. A data tokenization vendor enables a merchant to actually use tokens across processors, partners, and internal systems, not just be a place to store credit card numbers.
Tokenization solutions can be built in-house or purchased but typically contain some variation of the following:
- Compliant infrastructure: Auditors and regulators require that companies secure and manage sensitive data in a compliant location. These requirements can vary by country or region, data type, etc. Tokenization platforms may offer managed hosted environments that comply with these specialized requirements or accommodate a customer's existing infrastructure.
- Access controls and permissions: Sensitive data should only be accessible and editable to those with the proper access and permissions to do so. Tokenization platforms allow developers to quickly assign NIST impact levels and classifications to their applications and their data, as well as offer or connect to existing tools to manage these controls at scale better.
- Developer services, tools, and documentation: Being able to tokenize and store sensitive data is only part of the equation. Developers require tools, such as APIs, services, and compute capabilities, to embed, build, and support tokenization within their systems or those of third parties.
Governments, like India and the European Union, are driving new and clarifying old data and residency requirements at a dizzying pace. These laws mandate companies to accommodate varying levels of access, localization, and rules across multiple countries, depending on where the underlying data is stored and how it is used.
This has added significant complexity and compliance risk to merchants, especially high-risk merchants, creating opportunities for data tokenization vendors to offer a solution.
What services does a data tokenization vendor offer?
Until recently, most companies have been unable to build the supporting systems, culture, and functionality needed to deliver the gains Big Tech enjoys from tokenization.
Data tokenization vendors, however, bridge that gap by providing a solution to secure the data, and the tools, experiences, and documentation to use it.
Whether it’s a zero-day exploit or encryption-busting quantum computer, the security needs of tomorrow require a level of expertise and posture that few companies are willing to invest in today. While that leaves a significant gap that no one solution will bridge by itself, tokenization platforms offer various enduring benefits to protect your data.
- Mitigates the fragmentation and proliferation of sensitive data as system scale.
- Centralizes the complexities of encryption and key management.
- Upgrades encryption algorithms without loss of business functionality.
- Offers distributed systems for global redundancy.
- Provides dedicated tenant environments .
- Certified and attested controls and environments.
- Manages infrastructure as code.
To create a token within Basis Theory, an application sends the original value, like a credit card number, to a specialized environment called a token vault or data tokenization system. This triggers two events:
- The original value is encrypted and stored for safekeeping.
- A token is generated and sent to an application or database for future use.
To do this, the actor (i.e., a system or a person) sends a token to the data tokenization solution.

Then, the token is detokenized and ready for further instruction.
These are the questions a merchant should ask when evaluating data tokenization vendors
Who owns the tokens, the merchant or the vendor?
Processor-issued tokens are under the processor's control. A data tokenization solution that issues its own tokens gives the merchant portability. Your tokens work wherever you route them.
Does transaction routing happen inside or outside of the authorization path?
Platforms that sit in the transaction flow create a single point of failure (SPOF). Routing logic that operates outside the authorization path means a platform outage doesn't take any payments down.
With a data tokenization vendor, how much of your own platform comes into PCI scope?
The value of a data tokenization solution is that systems downstream only ever see tokens. If the vendor’s architecture still requires sensitive data to pass through your application layer, the compliance benefit largely disappears.
Why would a merchant need data tokenization tools?
Many applications, databases, and devices rely on seeing or holding sensitive plaintext data to complete day-to-day operations. Doing so can bring these systems “into scope,” creating significant complexity, overhead, and costs for its stewards. The more places this plaintext data exists, the more effort it takes to ensure proper compliance.
This can hinder an organization’s response to shifting markets or customer demands. To complicate matters, the rules and requirements governing this data often change based on factors like geography, data type, and usage.
By replacing sensitive data with tokens, you reduce the number of applications, databases, and devices interacting with the plaintext value (e.g., credit card numbers). In doing so, tokens reduce the scope of requirements and their impact on an organization. To give you a sense of this effect, customers using Basis Theory’s compliant environment to store encrypted plaintext values can reduce their PCI Level 1 reporting requirements by up to 90%.
Data tokenization services provide tokens that can take any shape and are safe to expose, allowing them to integrate with existing systems easily to replace sensitive data. Some of the core benefits of data tokenization include:
- Reduced risk: Applications, devices, and databases collect, store, and use sensitive data to complete day-to-day operations, making them targets for adversaries. In addition, the more fragmented the system, the more surface area criminals have to attack and exfiltrate sensitive data.
- Tokens are undecipherable, unreadable, and unusable to those without permissions and access. These attributes prevent adversaries from seeing and using any exfiltrated data from applications, databases, or devices. Meanwhile, the actual credit card information stays encrypted and stored in a firewall environment.
- Reduce or eliminate compliance requirements: Companies, industry groups, and governments have created rules to govern the use, storage, and management of sensitive data, like personally identifiable information (PII), primary account numbers (PANs), and bank account data. These mandated protections—like access controls, firewalls, and audits—aim to prevent the theft and abuse of data used by organizations.
With a smaller compliance footprint comes the ability to respond to shifting regulations more quickly. Now centralized, encrypted, and stored in a compliant location, sensitive data can more easily adapt to new data residency laws, data protection requirements, and industry standards.
And because their applications use tokens rather than plaintext values, they can accommodate these new requirements without disrupting day-to-day operations.
- Safely using sensitive data: Historically, the risks and compliance requirements governing sensitive data have made it difficult to move beyond sensitive data’s primary use case (e.g., only using SSNs for credit checks). By quarantining and locking down this data, organizations lose opportunities to make better risk decisions, create new partnerships, and design more unified customer experiences.
By abstracting sensitive data, replacing them with tokens, and gating access, developers can unlock new partnerships, products, and insights that drive revenue or save costs.
Where can tokens be stored or shared?
Tokens do not contain the original plaintext values, allowing them to be stored anywhere.
What kind of data can be tokenized?
Any data, files, images, etc. We like to say, “If it can be serialized, it can be tokenized.”
What type of data tokenization solutions are being implemented?
Imagine an eCommerce company trying to facilitate a faster checkout experience for repeat customers (and reduce security and compliance risks). The credit card data is tokenized; however, if your backend sends the token as is, the payment will fail.
Instead, the checkout application sends the token and payment instructions to the tokenization system. Once the tokenization system proves that the checkout application has the necessary access and permissions, it detokenizes the previously tokenized payment data.
From here, the system may forward the card and payment information to a card processor.
Processor independence is a common use case for enterprise merchants. When card data is stored in a single place, with routing logic that lives outside of any processor, the merchant can switch processors or add a backup provider knowing the data tokenization vendor works with any of them.
A few other use cases have emerged that benefit from processor independence:
Retailers Optimizing Payments
A popular retailer wishes to pursue payment optimizations that include intelligent payment routing to reduce card transaction fees, but the customer card data is locked with their current processor. With Basis Theory, the retailer migrates the card data on file from the existing payment processor to Basis Theory, then starts using tokens and the proxy service to programmatically route payments to processors offering a lowest cost.
Confidential Computing
A consortium of private companies wanted to leverage key aspects of its members’ proprietary geo-location data without sharing the larger sample set. The consortium’s members migrate its data Basis Theory and set up necessary permissions and controls to allow members to ask the dataset Yes/No questions.
Information and Payment Clearinghouse
An embedded finance app wanted to provide a seamless end user experience, but three parties needed varying pieces of information that would’ve required the customer to sign up for two distinct services. The embedded finance company uses Basis Theory to establish a clearinghouse where Personally Identifiable Information (PII) and related payment information could be exchanged, and only one registration was needed.
Embedded eCommerce
A popular streaming service provider wanted to allow its customers to shop ads with their existing card-on-file (located on its hardware device), but couldn’t bridge the relationship from its existing payment processor to its retail partner (one of the largest in the world).
The streaming service uses Basis Theory’s proxy service to direct interactions to and from the retailer and processor, allowing the encrypted credit card number on their customer’s device to be used by its processor to pay the retailer.
Return to Top
What makes a good tokenization solution?

Tokenization vendors provide the foundation and supporting documentation developers need to build a tokenization solution that supports new products, partnerships, and insights. For example, with Basis Theory’s data tokenization solution, you can search sensitive data without detokenizing or decrypting the original value, collect user data seamlessly from within your application, or route requests and responses to and from third parties.
- Token Capabilities: Tokenization platforms provide immediate flexibility to their tokens, allowing developers to interact with their sensitive data a lot like plaintext. Here are some of the properties developers may receive on Day One.
- Aliasing: Tokens can be formatted or lengthened to preserve the look and feel of the underlying data.
- Masking: Tokens can reveal all or part of the original value.
- Tagging: Tokens can use metadata, allowing you to reference all of the data owned by a single customer.
- Fingerprinting: Tokens can be correlated, allowing developers to create irreversible relationships between multiple tokens that contain identical data.
- Impact levels and classifications: Tokens can ensure only authenticated and authorized actors have access and permissions to the underlying data.
- Searching: Tokens can be indexed, allowing for searching the underlying data set without decrypting the original values.
As you evaluate tokenization vendors and payment vaults, talk to our team or compare Basis Theory to orchestration or similar solutions.