Home / Companies / Basis Theory / Blog / December 2023

December 2023 Summaries

6 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
PCI DSS requires businesses that accept major payment cards to protect cardholder data through encryption and related controls across its lifecycle. Requirement 3 focuses on stored data, directing organizations to minimize retained account information, prohibit post-authorization storage of sensitive authentication data, restrict PAN access, secure cryptographic keys, and maintain documented key-management procedures. Requirement 4 governs data in transit, requiring documented processes and strong cryptography whenever cardholder data or PANs move across open public networks. Compliance also depends on using accepted encryption standards such as AES or TDES, protecting backups, separating encryption keys from encrypted data, enforcing access controls, and regularly patching and testing systems for vulnerabilities. The passage presents dedicated cardholder data environments as a way to centralize protection, while promoting Basis Theory’s PCI Level 1-compliant platform as an outsourced solution intended to reduce the infrastructure, cost, and compliance scope faced by businesses handling payment data.
Dec 26, 2023 748 words in the original blog post.
A universal payment vault securely stores customer payment details as tokens while allowing merchants to send those details to payment service providers of their choosing, unlike many PSP-owned vaults that can restrict data portability and create vendor lock-in. By minimizing the need for customers to repeatedly enter payment information, vaults can reduce checkout friction, support repeat purchases and subscriptions, and help merchants maintain lower PCI-DSS compliance burdens. Universal vaults additionally enable merchants to route transactions among providers based on geography, payment method, pricing, approval performance, or emerging options such as buy now, pay later, potentially reducing costs, avoiding soft declines, and improving successful payment rates. This flexibility and merchant control are presented as increasingly important as digital payment preferences evolve quickly and consumers remain sensitive to inconvenient checkout experiences.
Dec 19, 2023 891 words in the original blog post.
Digital transactions account for an estimated 36% to 50% of payments worldwide, yet many checkout experiences remain fragmented, confusing, and inefficient, contributing to lost revenue for businesses. Research from the Baymard Institute indicates that poor user experience may cause up to 17% of online cart abandonment, while a 2022 Forrester report estimated that checkout-related UX issues cost businesses as much as $2.8 trillion annually in lost sales. Effective payment flows should prioritize simple and familiar interfaces, fast completion with minimal distractions, strong security protections, flexible support for preferred payment methods, and transparent pricing and instructions. The material promotes a visual Payments UX Best Practices guide featuring retailer examples and practical improvements intended to increase conversion rates and revenue.
Dec 18, 2023 345 words in the original blog post.
Frictionless payments are a design principle aimed at minimizing the steps, delays, and obstacles between consumers and completed purchases, using methods such as stored card details, tokenization, digital wallets, contactless NFC cards, and device-integrated services like Apple Pay and Google Pay. Demand for these options expanded during the COVID-19 pandemic as consumers favored touch-free transactions, while online commerce required stronger fraud prevention and authentication tools. For merchants, streamlined payments can improve operational efficiency, reduce customer frustration and abandoned sales, support repeat business, and enhance security through biometrics, secure logins, and tokenized card data, although implementation costs, transaction fees, uneven adoption, and resistance from less technology-comfortable customers remain challenges. As payment systems become increasingly mobile and fraud grows more sophisticated, smartphones’ biometric capabilities are positioning them as central tools for secure authentication, while merchants are encouraged to automate systems and avoid dependence on a single payment service provider to maintain flexibility in fees, preferred payment methods, and cross-border processing.
Dec 13, 2023 965 words in the original blog post.
3D Secure (3DS) adds identity authentication to online card payments, helping reduce fraudulent card use and merchant chargeback exposure but potentially increasing checkout friction, confusion, and transaction failures. Although it is not generally mandatory for domestic U.S. or most American transactions, merchants serving Europe must use 3DS 2.0 to comply with PSD2, while the EU, UK, Australia, and India impose strong authentication requirements. Adoption in the Americas has been constrained by concerns about customer experience and conversion losses, with reported U.S. 3DS transaction failure rates of 29% compared with lower rates in high-adoption European markets, though the U.S. accounts for much of a rapidly growing global 3DS services market. Improvements in 3DS 2.0, rising fraud and data-breach risks, and the need to support international commerce are expected to drive wider adoption across the Americas, despite continuing merchant concerns over approval rates.
Dec 12, 2023 855 words in the original blog post.
Basis Theory’s November updates expanded its payment platform with React Native support and enhanced anti-fraud capabilities for merchants and fintechs. The new Basis Theory Elements for React Native enable developers to securely collect credit card and text data through customizable input components while keeping sensitive information tokenized within Basis Theory, reducing direct exposure to plaintext data and PCI compliance requirements. The platform also added or emphasized integrations with fraud prevention providers Forter, Sardine, and Kount, alongside features including device fingerprinting, payment verification, card fingerprinting, and streamlined 3D Secure support to help identify fraudulent activity and strengthen transaction authentication. Additional improvements resolved token retrieval issues involving special-character aliases, addressed a React Native Metro issue, and enabled Web Elements to reveal primitive data types.
Dec 08, 2023 394 words in the original blog post.