August 2023 Summaries
8 posts from Basis Theory
Filter
Month:
Year:
Post Summaries
Back to Blog
Payment processing involves multiple intermediaries, including gateways, processors, card networks, and banks, creating substantial costs for merchants that can range from roughly 1.5% to 4.5% per transaction, with U.S. credit card fees exceeding $126 billion in 2022. Full-service payment service providers, or aggregators, simplify setup and reduce PCI compliance burdens but often charge relatively high fixed and incidental fees while retaining control of customers’ card data, limiting merchants’ ability to switch providers. Costs can also rise because of cross-border transactions, currency conversion, refunds, chargebacks, and specialized high-risk payment requirements. The proposed path to greater efficiency is payment automation that screens transactions for risk and routes them among multiple providers based on factors such as geography, transaction risk, and volume discounts. Third-party tokenization can support this diversified approach by securely storing payment details outside a single processor’s system, allowing merchants to retain flexibility in choosing providers while reducing compliance exposure.
Aug 30, 2023
865 words in the original blog post.
PCI DSS Requirement 3 focuses on protecting stored account data to reduce the harm caused by accidental or malicious exposure, emphasizing that organizations should collect and retain only the data necessary for legal or business purposes. Its seven sections require documented policies and assigned responsibilities, minimized retention and secure deletion practices, prohibition of sensitive authentication data storage after authorization, restricted display and copying of primary account numbers, and techniques such as masking, truncation, tokenization, hashing, and strong cryptography to make stored PAN unreadable. The requirement also mandates strict protection of cryptographic keys, including limited access, secure storage, minimal locations, and lifecycle procedures for generating, distributing, rotating, retiring, replacing, and destroying keys. The text notes that Basis Theory, a PCI Level 1 compliant provider, offers a managed cardholder-data environment and tokenization tools intended to help companies secure payment data while reducing the scope, cost, and operational burden of PCI DSS compliance.
Aug 28, 2023
1,799 words in the original blog post.
A Global Payments and Fraud report from the Merchant Risk Council, Cybersource, and Verifi surveyed 1,072 payment and fraud-management merchants worldwide and found rapid expansion in payment options, particularly digital wallets and buy-now-pay-later services. In North America, digital wallets were accepted by 76% of respondents, followed by direct debit or bank transfers at 73% and cards at 60%, while merchants accepted an average of 5.3 payment methods and added 3.2 in the prior year, primarily to improve customer experience. Key payment metrics included payment success rates, revenue, and payment costs, while global e-commerce fraud losses declined from 3.6% of revenue in 2022 to 2.9%, with North America reporting 2.4%. Fraud-management spending varied substantially by region, reaching 10% of revenue in North America and Europe, 15% in APAC, and 19% in Latin America. Phishing, first-party misuse, card testing, and identity theft were identified as major fraud threats, and merchants cited using data effectively, detecting emerging attacks, and tracking payment-network rule changes as leading challenges, with fraud analytics expected to be a major investment priority.
Aug 24, 2023
1,026 words in the original blog post.
Merchant Discount Rate (MDR) is the composite fee merchants pay payment service providers to process transactions, typically averaging 1% to 3% and covering costs for gateways, card networks, acquiring and merchant banks, and the provider’s margin. Unlike interchange fees, which are largely standardized card-network charges that vary by card type, geography, and merchant category, MDRs are provider-specific and may use flat-rate, interchange-plus, or less common tiered pricing models. MDR can also include supplementary costs such as cross-border, refund, and chargeback fees, making providers’ pricing difficult to compare and potentially more variable than interchange. Merchants can often negotiate MDR based on anticipated volume or reduce costs by routing transactions among multiple payment providers, though full-service providers may offer convenience and reduced PCI-DSS compliance exposure in exchange for higher flat fees and limited access to customer card data. Third-party tokenization services can help merchants preserve secure access to payment credentials while allowing transactions to be sent to different providers, supporting greater pricing flexibility and automated payment-routing decisions.
Aug 23, 2023
971 words in the original blog post.
PCI DSS Requirement 2 aims to reduce the risk of system compromise by requiring organizations to replace vendor default credentials and settings, remove unnecessary accounts, software, services, protocols, and functions, and maintain secure configurations across system components. Its first section requires documented, current, and understood security policies, procedures, roles, and responsibilities; its second requires configuration standards that address vulnerabilities, protect administrative access with strong encryption, isolate functions with different security needs, and document safeguards for any insecure protocols that remain necessary. The requirement also addresses wireless environments connected to cardholder data systems or transmitting account data, requiring secure default settings and changes to encryption keys when authorized personnel leave or a compromise is suspected. Basis Theory states that its PCI Level 1-compliant platform can help businesses secure and handle cardholder data without bringing their own systems fully into PCI scope, though readers are directed to the PCI Security Standards Council for authoritative and current requirements.
Aug 17, 2023
941 words in the original blog post.
Payment gateways enable businesses, especially online and subscription-based merchants, to securely accept card-not-present payments by connecting to acquiring processors, validating payment details, and offering capabilities such as fraud prevention, recurring billing, and multiple payment methods. Selecting a gateway requires evaluating required functionality, pricing, security practices, scalability, and available customer support. Widely used providers include PayPal, Stripe, Square, Adyen, Worldpay, Ingenico, Braintree, WePay, 2Checkout, Amazon Pay, and Cybersource, each serving different merchant sizes, sales channels, geographic markets, and integration needs. Merchants generally need both a gateway and a processor for virtual and card-not-present transactions, while in-person payments require a processor and may require a gateway when no physical terminal is used. Using a PCI-compliant gateway does not by itself ensure PCI compliance, as merchants must also protect cardholder data, monitor networks, and maintain appropriate access controls.
Aug 15, 2023
1,169 words in the original blog post.
PCI DSS Requirement 1 requires organizations to install and maintain network security controls, chiefly firewalls and network segmentation, to protect cardholder data within a defined Cardholder Data Environment (CDE). It emphasizes documented responsibilities, firewall configuration standards, traffic logging, and regular reviews to ensure that only authorized inbound and outbound traffic can reach the CDE, including traffic from wireless networks. PCI DSS v4.0 adds requirements to isolate the CDE from untrusted networks through controlled connections, anti-spoofing protections, limits on direct access to systems storing cardholder data, and restricted exposure of internal network information. It also requires security measures for devices that connect both to untrusted networks and the CDE, with controls that actively prevent threats and cannot be changed without authorized approval. The passage presents Basis Theory as a PCI Level 1-compliant provider that offers an externally assessed CDE and tokenization tools intended to help businesses secure payment data while reducing their own PCI compliance scope, while noting that official PCI SSC materials remain the authoritative source for current requirements.
Aug 10, 2023
1,092 words in the original blog post.
Basis Theory’s July updates focused on simplifying development with sensitive data through a new command-line interface, AI-enhanced documentation, and an official React Native SDK. The CLI enables developers to create, update, deploy, and inspect logs for proxies and reactors from their terminals, with reactor logging currently available by invitation. Documentation now incorporates Kapa.AI, which answers questions and interprets code examples by searching the company’s guides, API references, and support materials, while feedback from user interactions helps improve the documentation. The React Native SDK is replacing the existing bridge, adding credit-card reveal functionality for issuing use cases in July and planned collection support in August. Additional improvements included expanded proxy and reactor configuration limits, lower API response times, improved handling when the Elements script is blocked, and new multi-factor authentication controls for disabling MFA, regenerating backup codes, and managing settings through the portal.
Aug 07, 2023
532 words in the original blog post.