Skip to content

    How Fintechs Handle PCI Compliance

    Building a Fintech Payment Solution

    Fintech founders have a short list of priorities: the product, the customer, and the bridge between the two. Everything else is a distraction, and being able to tell the difference between a priority and distraction determines how fast the company can move.

    PCI compliance is one of those distractions for fintech companies.

    It feels important because it’s serious. Collecting and storing payment data is the toll that’s paid to build the product, but it’s not part of the product. For many fintech companies, this toll will grow as the product begins to scale.

    Which is why the fastest fintechs tend to be ruthless about the distinction between priority and distraction.

    Sophia Goldberg, co-founder of Ansa, was direct when describing how her team decides what to build versus what to outsource:

    “Hyper-focus is the name of the game at this stage in our company, and we want to keep our team really lean because it gives us more shots on goal,” Goldberg says. “We are staying focused on what our merchants need and how we can solve it. Anything that we don’t need to touch right now, we don’t.

    “If there’s a vendor and a partner we can trust, let’s use them instead.”

    Ansa viewed PCI compliance as something that would gobble engineering time and operational focus that was needed for their core product, so they offloaded the part of the stack that doesn’t differentiate them: securing storage and handling of payment data.

    Knowing which parts of your payment stack are worth owning and which are dressed as priorities but are, in reality, distractions is a pattern worth understanding as a fintech.

    What would be a distraction with fintech payment processing? 

    Not all payment problems deserve the attention of your team. A simple test is to ask if solving the problem makes your product better for your customers.

    Treating compliance infrastructure as something to own is a trap many fintech companies can fall into. This is a distraction with fintech payment processing. Maintaining a PCI Level 1 Cardholder Data Environment (CDE), passing annual PCI DSS audits, and staffing a security team to maintain compliance is operational overhead. All are necessary functions of payment processing, but they don’t make your product better.

    Matt Donofrio, Head of Revenue at Marble, said that as they were building their customer experience, they determined it was easier to offload PCI compliance responsibilities to an organization that was already PCI compliant.

    “We needed a solution that we could implement quickly, and was not super operationally heavy,” Donofrio said. “It was clear to me that Basis Theory was what we needed, and I’d be hard pressed to think there’s something more relevant to what we were trying to solve—which was to maintain PCI compliance.”

    Return to Top

    What are the most common fintech payment solutions? 

    The most common fintech payment solutions combine alternative and local payment methods with AI-driven fraud detection, and embedded payments.

    Digital wallets, buy now, pay later (BNPL) and account-to-account payments continue to grow in both consumer demand and merchant acceptance. Full-service payment processors will bundle access to these methods to make onboarding easier.

    Fraud detection is an area where active investment pays off as fraud tactics get more sophisticated and specialized. A specific instance is a recent spate of software supply chain attacks. Supply chain remains one of the most serious areas of risk for fintech companies because every piece of software and every service integrated with it represents a potential vulnerability.

    This extends to the tools themselves. Vetting fraud and AI providers with the same rigor you’d apply to a PSP is worth the investment.

    Return to Top

    Why do fintechs need tokenization? 

    Tokenization is the process of replacing sensitive data—a card number, a bank account number, a passport—with a unique identifier (token) that has no exploitable value on its own. The token can be stored and used in your systems in place of the real data, while the actual sensitive information is held in a vault.

    Fintechs have a few options for where tokenization happens, and the provider you choose has downstream consequences. Card networks and payment processors can tokenize on your behalf, with the resulting tokens locked to that specific provider. Third-party tokenization providers offer tokens that work independently of any single processor.

    Building a cardholder data environment internally is the fourth option. This brings the most control along with the most compliance burden, audit requirements, and engineering overhead that industry estimates put between $70,000 and $250,000 annually.

    Return to Top

    How does a fintech use a payment vault? 

    A fintech payment vault is infrastructure that tokenizes and securely stores sensitive data — card numbers, bank account details, personally identifiable information — independently of any single processor, so a fintech can route that data to whichever partner it needs without ever holding the raw values itself.

    The distinction between a payment vault and processor-level tokenization comes down to who controls the token. With processor-issued tokens, your payment data is portable only within that processor's ecosystem. With an independent vault, the token is yours. You can use it to send transactions to any processor, fraud provider, or network service you choose, and you can add or switch providers without forcing customers to re-enter their payment information.

    That portability is what makes a vault a catalyst for unbundling your payments stack—that is, moving away from a single, all-in-one payment provider and instead assembling a stack of best-fit partners for each function: one processor for your primary market, a backup for redundancy, a specialized provider for an emerging payment method, a dedicated fraud tool. Unbundling gives fintechs more control over cost, performance, and risk, but it's only practical if your payment data isn't locked to any one of those providers. A vault is what makes that possible: tokenize once, then route freely.

    This is also where PCI scope reduction becomes concrete rather than theoretical. Fintech teams like MoneyGram, Melio, and Method use a payment vault to handle sensitive payment and identity data without taking on PCI DSS scope themselves or building security infrastructure from scratch. That means engineering time goes toward the product, not toward maintaining a cardholder data environment.

    Maxio took this approach as the company planned for international expansion. When their existing payment stack was limited to the United States, Maxio needed to add multiple payment service providers (PSPs) and ultimately, a third-party payment vault.

    “Many providers hold tokens hostage in an attempt to prevent you from leaving their platform. Because we had Basis Theory in place, this was a non-issue,” explained Jon Cochrane, GM of Partnerships and Payments at Maxio. “We could simply focus on creating the best product experience for our customers. Without Basis Theory, that was a potential seven-figure problem for us.”

    By unbundling their payment stack, Clara Leigh, Technical Lead at YouPay, said it gave her all the control she was hoping for.

    “I like to ship fast, and ship well,” Leigh explains. “We were sick of waiting on external factors in order to implement changes. Basis Theory expedited that process.

    “Our payments are controlled in-house, I don’t have to wait for anything. I can just do it.”

    Return to Top

    Frequently Asked Questions About Fintech Payments 

    How does tokenization reduce PCI compliance scope?

    Tokenization removes raw cardholder data from most of a company's systems. Because tokens have no exploitable value outside the vault that issued them, systems that only handle tokens generally fall outside the strictest PCI DSS scope requirements.

    Why do fintechs outsource PCI compliance instead of building it in-house?

    Building and maintaining a PCI-compliant cardholder data environment requires significant engineering time, security resources, and ongoing audit costs. Most fintechs outsource a majority of their PCI compliance responsibilities to a vault provider so their team can focus on product development instead of compliance infrastructure.

    What does it mean to unbundle payments?

    Unbundling payments means moving away from a single, all-in-one payment provider and instead assembling a stack of specialized partners. These partners can help with processing, fraud, alternative payment methods, and more. It gives fintechs more control over cost and performance, but requires payment data that isn't locked to one provider.

    What should a fintech look for in a payment vault provider?

    Keeping payment data accessible and portable is the job of a third-party payment vault. In order to ensure that a provider's services meet the true business need, organizations should, among other factors, consider the provider's:

    • Expertise: Does the provider know your company’s unique payments needs?
    • Experience: How much experience does the provider generally have and is it in the areas you need to leverage?
    • Reputation: How well-regarded is this provider in the marketplace?
    • Cost: Does the price work with your budget and business needs?

    When you’re ready to offload PCI compliance and build a vault your team actually controls, talk to our team.

    Return to Top

    Stay Connected

    Receive the latest updates straight to your inbox