Home / Companies / Basis Theory / Blog / May 2023

May 2023 Summaries

4 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
Payment automation uses technology to streamline accounts payable processes, helping organizations manage vendor and partner payments as transaction volumes exceed manual staff capacity. By automating tasks such as invoice capture through OCR, payment matching, and electronic disbursements via ACH or corporate cards, it can reduce data-entry errors, lower transaction costs, limit paper-check fraud, improve managerial oversight, and free employees for higher-value work. Although some AP teams may initially view automation as a loss of control, properly configured systems can provide stronger controls and greater focus on payment outcomes, though inadequate security can create fraud and data-breach risks. The text emphasizes protecting sensitive financial information through tokenization and third-party token vaults, which can limit exposure after a breach, enforce least-privilege access, reduce compliance scope, and prevent dependency on a single payment automation vendor.
May 24, 2023 771 words in the original blog post.
Merchants can use payment data to assess business performance, but default dashboard metrics become most valuable when analyzed regularly for trends and actions rather than viewed only as snapshots. Important measures include customers’ preferred payment methods, transaction volume by product or plan, authorization rates, and transaction failures such as declines, chargebacks, disputes, and fraud, all of which can affect revenue, customer experience, processing costs, and risk management. Website checkout analytics, including drop-off, conversion, repeat-purchase, and time-to-purchase rates, can further reveal opportunities to simplify purchasing and improve retention. Ongoing, segmented analysis can help businesses identify seasonal patterns, operational inefficiencies, payment recovery opportunities, and potential fraud issues, while supporting decisions on expansion into new products, markets, or payment options. Organizations are also encouraged to take ownership of payment data through a PCI-compliant cardholder data environment, either by building one internally or using a specialized third-party provider.
May 18, 2023 1,211 words in the original blog post.
Basis Theory introduced several product updates focused on privacy, developer flexibility, and platform performance across its SDKs and services. Its Web and Mobile Elements now include a conceal font that masks entered data to help prevent browser password managers from storing it, while Android adds dedicated textPassword and numberPassword field support already available on iOS and Web. Expressions can now use six- or eight-digit BINs for aliases, masks, and other workflows, enabling more customized card-data handling. A private beta also allows larger token payloads for securely storing KYC and KYB documents, giving customers greater control over data portability when changing providers. Additional improvements include ExcelJS support in Reactors, proxy compression fixes, new ElementRemovedFromDOM error reporting, React and JavaScript SDK reliability updates, and a more than 52% improvement in token-read API performance.
May 11, 2023 468 words in the original blog post.
Secure payment systems protect customers from fraud and identity theft while helping merchants avoid fines, legal liability, reputational damage, and the potential loss of card-processing privileges. A central recommendation is to keep personally identifiable information and card data outside a merchant’s systems by using a hosted payment service provider, which stores sensitive data and returns tokens, potentially reducing PCI-DSS compliance scope but introducing fees and provider dependence. Merchants that retain sensitive data should use tokenization in addition to encryption, since encrypted data may be exposed if decryption keys are compromised, whereas tokens do not reveal the underlying information. The material also emphasizes limiting employee access to only the transaction data needed at a given time through controlled browser-based interfaces and token-vault access. Finally, it recommends choosing a reliable tokenization provider with secure APIs, a PCI-DSS Level One-certified token vault, and tools for preventing customer data from entering, being stored in, or being removed from internal systems.
May 04, 2023 720 words in the original blog post.