October 2022 Summaries
2 posts from Basis Theory
Filter
Month:
Year:
Post Summaries
Back to Blog
Organizations seeking greater control over cardholder data often face high costs, lengthy implementation timelines, and operational constraints associated with PCI compliance and dependence on payment service providers. Basis Theory’s PCI Blueprint uses tokenization to replace sensitive card data with tokens, helping reduce PCI scope while preserving capabilities such as payment processing, PAN searching, data deduplication, and integration with multiple providers. The blueprint includes a PCI Level 1 cardholder environment, customizable card-capture interfaces, access controls, token features, and a proxy service that can route, transform, tokenize, or detokenize payment data without disrupting existing systems. Preconfigured but customizable templates are intended to simplify implementation, while search indexes, fingerprints, and token properties enable selected card-data operations without exposing underlying PANs. For organizations pursuing PCI Level 1 certification, Basis Theory says its infrastructure addresses most assessed controls and, alongside partners such as Secureframe and Prescient Security, can support compliance management and audit preparation.
Oct 24, 2022
980 words in the original blog post.
Basis Theory has introduced its Open KMS SDK, an encryption and key-management tool designed to help applications adapt to changing security, compliance, and customer requirements. The SDK uses JSON Web Encryption and JSON Web Keys to combine encrypted data with metadata about the associated key, algorithm, size, and location, allowing encryption configurations to change without requiring broad application-code changes. It centralizes encryption-schema registration for auditing and configuration management, provides integrations for major cloud KMS providers such as Azure and AWS, and standardizes key rotation through configurable validity intervals. The SDK also supports dependency injection for dynamic, multi-tenant key selection, enabling per-user or per-customer encryption keys, and integrates with Entity Framework so sensitive database fields can be automatically encrypted and decrypted through model annotations. Basis Theory plans to expand provider, algorithm, language, and framework support, while positioning the SDK alongside its broader tokenization platform for reducing exposure of sensitive data.
Oct 05, 2022
1,230 words in the original blog post.