April 2023 Summaries
4 posts from Basis Theory
Filter
Month:
Year:
Post Summaries
Back to Blog
PCI-DSS requires organizations involved in card payments to protect customers’ personally identifiable information, with violations ranging from major data breaches to insecurely stored card details, weak access controls, or unauthorized data removal. Incidents may be disclosed by breached companies or reported by consumers to banks and card networks, which can trigger compliance audits and penalties. Although card networks typically fine payment gateways rather than merchants directly, gateways commonly pass costs on through fees, higher processing rates, reserve requirements, and high-risk classifications. Penalties can begin around $5,000 and recur monthly, potentially growing beyond six figures, while reserve requirements can strain businesses with limited margins. To reduce exposure, the text recommends keeping payment data outside a merchant’s systems through a full-service payment provider or, more flexibly, a third-party tokenization provider that stores card data and gives merchants nonreversible tokens while allowing them to select among payment gateways.
Apr 21, 2023
899 words in the original blog post.
March platform updates added the ability to send sensitive data collected through Elements directly to a proxy, supporting uses such as securely handling EBT PINs or recollecting CVVs for fraud prevention. Card BIN capabilities now support either six- or eight-digit values based on card length through front-end metadata and events or backend fields such as card_mask and card_bin, enabling fraud reduction, payment optimization, risk management, and more tailored customer experiences. The pricing interface on the website and within the platform was redesigned to present plans, tiers, and packages more clearly. Additional changes include a fix for token updates when metadata contains null values, a new React Native Elements guide, support for valid integer date strings in card-token expiration dates, tighter card expiration month validation, and Web Elements performance and reliability improvements.
Apr 07, 2023
297 words in the original blog post.
Risk management involves identifying, prioritizing, and mitigating operational, financial, regulatory, data, and reputational threats, and the piece argues that it should develop alongside a high-growth company rather than be treated as a late-stage requirement. It contrasts first-time founders, who may purchase minimal coverage until a claim or contractual demand exposes gaps, with repeat founders that often establish safeguards earlier, noting that risks are cross-functional and can affect security, legal, finance, and operations simultaneously. The proposed approach favors early adoption of scalable protections and specialized external partners over placing all responsibility on internal executives, particularly for fintech companies facing changing regulations, vendor exposure, and sensitive-data risks. It presents Vouch insurance as a means of transferring litigation and loss-related costs and Basis Theory’s data-tokenization platform as a way to reduce exposure by securing sensitive information and limiting the impact of breaches, arguing that coordinated use of such services can create a more cohesive risk-management program as a company grows.
Apr 05, 2023
1,999 words in the original blog post.
A webinar featuring Tilled CEO Caleb Avery examined payment processing, data ownership, and the risks of relying on a single provider. It argues that some established processors, including Stripe and Worldpay, can retain ownership of customer payment tokens and data, making migrations costly, lengthy, and operationally difficult, as illustrated by merchants facing multimillion-dollar token buybacks and months-long transfers. The discussion frames payment redundancy as a business-continuity measure that can also support smart routing and higher transaction approval rates. While Stripe gained adoption by simplifying integrations and developer tools, software companies are now portrayed as seeking broader capabilities such as monetization, customer-focused experiences, turnkey interfaces, flexible APIs, competitive pricing, and control of their data. Tilled and Basis Theory are presented as alternatives emphasizing payment optionality, PayFac-as-a-service support, and data portability, with the central recommendation that businesses bring payment data under their own control to reduce vendor lock-in and retain flexibility.
Apr 03, 2023
819 words in the original blog post.