July 2023 Summaries
8 posts from Basis Theory
Filter
Month:
Year:
Post Summaries
Back to Blog
Basis Theory’s new HTTP service is designed to let developers collect and route sensitive data, including payment card PANs and personally identifiable information, without bringing front-end applications into PCI compliance scope. By replacing a payment service provider’s payment elements with Basis Theory Elements, companies can send card data directly to third-party endpoints such as Stripe while simultaneously tokenizing it in Basis Theory’s vault, enabling a multi-vaulting approach. The service supports collecting PANs quickly without requiring a company to establish its own PCI environment or disrupt existing PSP agreements, and it can call multiple third-party endpoints for use with several payment providers. Proposed benefits include processor failover during outages, payment retry strategies, reduced disruption for high-risk merchants, and easier testing of alternative PSPs. It can also route PII directly to KYC providers without storing it, allowing businesses to retain control of their user experience while reducing exposure of sensitive data in front-end code.
Jul 27, 2023
870 words in the original blog post.
Compliance Genie is a free AI-powered tool designed to help payments professionals quickly navigate complex payment regulations, initially focusing on Mastercard and Visa network rules that can span roughly 1,500 pages. Developed in collaboration with Kapa.ai, the tool was trained on rulebooks and common industry questions to provide an accessible interface for regulatory inquiries. It aims to reduce reliance on lengthy document searches, potentially unreliable web results, and expert consultation by offering tailored answers, acknowledging uncertainty when it cannot provide a reliable response, supporting multiple languages, and operating continuously. The developers plan to improve the system through user feedback and expand its knowledge base with sources such as PCI standards, EU PSD2 regulations, and U.S. Office of the Comptroller of the Currency federal regulations.
Jul 26, 2023
600 words in the original blog post.
Navigating the payments industry requires a grasp of transaction mechanics, the ecosystem of providers, data-security obligations, and continually changing regulations. Foundational resources include PCI-DSS standards and explanatory material on compliance, customer data handling, and the roles of payment-industry participants. To follow market developments, the text recommends specialist news outlets, newsletters, research organizations, and expert blogs such as American Banker, PYMNTS, PaymentEye, Payment Cards and Mobile, Finextra, Glenbrook, and Noyes Payments Blog, covering topics from payment networks and mobile wallets to international markets and technical implementation. Provider-operated blogs from Dwolla, BlueSnap, Stripe, Rapyd, and Tipalti can offer practical perspectives, though their commercial interests should be considered. Online learning options including Coursera, CFTE, LinkedIn Learning, and Khan Academy provide courses and certifications, while tools such as Google Alerts can help readers identify breaking news and additional resources.
Jul 19, 2023
1,018 words in the original blog post.
Payments compliance encompasses the regulations, standards, and security practices merchants must follow to protect customers, banks, payment gateways, card networks, and other participants from fraud, data breaches, and financial crime. Its importance has grown alongside global e-commerce, as security failures can cause major financial losses, damage customer trust, expose connected partners to risk, and lead to higher processing fees, reserves, fines, mandatory audits, or loss of payment-processing access. Core requirements include Know Your Customer measures that verify customer and cardholder information, Anti-Money Laundering controls that detect suspicious transactions and prevent criminal use of merchant platforms, and PCI-DSS standards governing the protection and testing of payment data. Because stored personally identifiable information is a frequent target for attackers, merchants can reduce both breach exposure and PCI-DSS costs by using third-party tokenization services, which store sensitive data in secure token vaults while allowing merchants to process payments without retaining the underlying information.
Jul 17, 2023
803 words in the original blog post.
A 16-page white paper examines Know Your Customer requirements and the responsibilities businesses face when collecting, storing, and processing customer identity data. It covers federal KYC rules, state gaming and privacy obligations, regulations affecting virtual currency exchanges and other money services businesses, and state-by-state breach-notification requirements involving Social Security numbers or government-issued IDs. The paper emphasizes that noncompliance can carry significant consequences and describes the challenges of managing sensitive KYC data across differing regulatory environments. It also presents Basis Theory’s KYC Data Engine as a platform designed to establish a secure data vault quickly while enabling compliant KYC data use for functions including credit decisions, identity verification, customer support, audits, examinations, and testing.
Jul 12, 2023
411 words in the original blog post.
Basis Theory’s June updates introduce an Elements HTTP Client Service in private beta that lets browser-based Elements send sensitive data directly to approved third parties without passing through Basis Theory’s platform or a customer’s codebase, helping reduce compliance scope while optionally integrating with its Vault for tokenization. The platform now also supports atomic Transactions, enabling multiple token changes to be grouped together and rolled back if any operation fails, which helps maintain data consistency during updates or restructuring. Multi-factor authentication has been automatically enabled for portal users to strengthen account security and support PCI DSS 4.0 requirements, while future portal controls for MFA are planned. Additional improvements include new workflow-focused documentation, nullable token properties in Elements forms, Firefox and Axios fixes, expanded API merge-patch and content-type support, card-data fixes, enhanced Proxy and Reactor transformations, form-data processing support, and a larger code limit for Proxy Transform logic.
Jul 11, 2023
478 words in the original blog post.
Payment gateway fraud involves card-not-present purchases made with invalid, stolen, fabricated, or compromised card details, exposing merchants to lost goods, chargebacks, fees, and possible disruption or termination of payment-processing relationships. With card-not-present fraud losses projected to rise sharply, merchants remain ultimately accountable even when processors or third-party security providers handle transaction services. Effective prevention requires balancing fraud reduction against unnecessary declines and customer friction through measures such as address and card-code verification, 3-D Secure authentication, transaction and volume limits, and custom risk scoring. The text recommends that merchants strengthen control by using tokenization to securely store card data, automating fraud assessments before submitting transactions, routing approved payments to suitable processors, and evaluating alternate routing after soft declines, particularly when operating across multiple gateways or processors.
Jul 10, 2023
972 words in the original blog post.
Cross-border payments are international transactions involving parties in multiple countries and can use methods ranging from bank transfers, cards, and global ACH to digital wallets, buy-now-pay-later services, cryptocurrencies, and blockchain platforms. Although the customer checkout experience may appear simple, merchants and processors must manage currency conversion, exchange rates, taxes, transaction and interchange fees, intermediaries, sanctions, licensing, reporting obligations, authentication, fraud prevention, and local acquiring requirements. Merchants should select payment options that match regional consumer preferences and work with payment platforms that can identify customer origin, configure payment connections and authentication appropriately, and provide analytics on acceptance rates, usage, and fees. High costs and unfavorable bank exchange rates remain major obstacles, while digital platforms such as PayPal, Wise, and Revolut can offer faster transactions, lower fees, and improved exchange rates. Blockchain-based systems including Ripple and Stellar may further reduce reliance on intermediaries and improve speed, transparency, and security, though adoption remains limited.
Jul 05, 2023
1,003 words in the original blog post.