Home / Companies / Basis Theory / Blog / March 2024

March 2024 Summaries

7 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
Social commerce refers to sales activity conducted on or influenced by social networks, including brand-managed posts, paid influencer promotions, livestream shopping, and advertisements linked directly to checkout. It offers merchants a way to demonstrate more complex products, build consumer trust through authentic-looking content, and reach customers where they spend substantial time online. However, businesses must develop effective audience-focused strategies, choose between selling through social platforms or directing shoppers to their own mobile-optimized sites, and manage logistics, affiliate tracking, inventory, and platform fees. While using a network’s built-in payment system can simplify early efforts, fees such as Instagram’s reported 5% sales charge can reduce margins, encouraging merchants to retain control of checkout and payments. More advanced approaches may use payment automation, multiple payment providers, and third-party token vaults to secure customer data, support varied payment methods and international transactions, lower compliance burdens, and improve authorization rates and processing costs.
Mar 20, 2024 937 words in the original blog post.
PCI DSS 4.0 is a major revision of the global card-data security standard for merchants and service providers that store, process, transmit, or can affect the security of payment card information, replacing PCI DSS 3.2.1 after March 31, 2024. The update broadens several traditional concepts, such as firewalls to network security controls and antivirus to anti-malware, while introducing stronger requirements for secure configurations, encryption, certificate and key management, multi-factor authentication, password practices, account reviews, secure software development, payment-page script monitoring, logging, vulnerability scanning, penetration testing, incident response, and security awareness. It also places greater emphasis on documented roles and responsibilities, targeted risk analyses, periodic scope validation, and continuous reviews of cryptographic technologies and security controls. The described changes assign responsibilities variously to merchants, Basis Theory, or both, though applicability varies by merchant environment and Self-Assessment Questionnaire type; organizations are advised to consult a Qualified Security Assessor for use-case-specific guidance.
Mar 19, 2024 1,862 words in the original blog post.
PCI DSS requires any organization that accepts major payment cards to protect cardholder data and demonstrate compliance annually, a process that can become more complex as transaction volumes and business operations grow. An interactive checklist is presented to help merchants address compliance considerations across configuration, data setup, development, and operations when using Basis Theory. PCI reporting obligations vary by merchant level, which is generally based on annual card transaction volume, with higher-volume organizations facing broader compliance scopes and Level 1 merchants typically requiring a third-party audit. Organizations validate compliance through either a Self-Assessment Questionnaire or a Report on Compliance and then submit an Attestation of Compliance. The standard comprises six security objectives and 12 principal requirements covering network security, data protection, vulnerability management, access controls, monitoring and testing, and organizational information-security policies, supported by more than 300 detailed sub-requirements.
Mar 18, 2024 768 words in the original blog post.
February’s engineering work combined major product releases with targeted reliability and usability fixes, including a beta launch of 3D Secure support for Enterprise customers to provide stronger card-fraud protection through the newer, more seamless 3DS 2.0 transaction flow. Platform performance improvements made Session API calls approximately 50% faster on average, with larger gains under heavier request volumes, following earlier search-indexing enhancements. The team also released version 1.0 of its React Native library after reaching feature parity with other Elements libraries, enabling simpler in-app credit card capture and processing. Additional updates addressed Android autofill hints and expiration-date display issues, iOS session-key token creation, more detailed internal Reactor errors, removal of deprecated Reactor Formulas, React Native documentation gaps, and custom-font support in Web Elements.
Mar 15, 2024 320 words in the original blog post.
Payment providers, or gateways, connect merchants to the electronic payments ecosystem and enable acceptance of cards, digital wallets, bank transfers, buy-now-pay-later services, and other payment methods while often providing security, fraud prevention, data management, and currency services. Full-service providers offer an accessible, predictable option for new digital businesses by bundling merchant accounts, payment pages, and processing, whereas independent gateways give growing businesses greater control to route transactions among providers for improved approval rates and lower costs. High-risk providers specialize in serving merchants in industries subject to greater scrutiny, such as e-commerce, gaming, and CBD. As companies mature, using multiple providers can improve automation, recurring-payment handling, and fee optimization, but it also increases the complexity and risk of managing sensitive customer data. Third-party token vaults can address this challenge by securely storing payment information and supplying merchants with non-reversible tokens that can be used to send payment details to selected providers without requiring the merchant to maintain a fully PCI-compliant data environment.
Mar 13, 2024 1,023 words in the original blog post.
Data portability enables customers or businesses to move data between providers, while interoperability allows different systems to use shared standards to exchange and interpret data, with telephone-number transfers and email serving as common examples. In payments, interoperability developed through networks such as SWIFT and broader financial standards that support increasingly rapid transactions across institutions, although transfer speeds vary by region and provider. Payment data portability is especially relevant when merchants change payment service providers and need to transfer stored cardholder details without requiring customers to re-enter them, but providers may impose costly or slow processes because facilitating a departure may not align with their commercial interests. The passage presents token vaults as an alternative model in which merchants retain cardholder data independently of any one processor, allowing them to securely share tokenized information with one or multiple providers under PCI-DSS requirements while reducing dependence on a single payment gateway.
Mar 11, 2024 907 words in the original blog post.
Batch payment processing allows merchants to collect authorized card transactions and submit them together for processing later, typically at the end of a business day, rather than completing each payment in real time. Payment transactions generally move through authorization, processing, and settlement, and merchants operating directly within the payments ecosystem can delay processing after an authorization has reserved or confirmed available funds. This approach is especially useful for restaurants, hotels, and car rental agencies, where final charges may change because of tips, incidentals, or other variable costs. Potential benefits include more accurate final billing, lower per-transaction processing costs in some arrangements, and simplified review of successful and failed payments, while drawbacks include slower access to funds, uncertainty over whether delayed transactions will succeed, and potentially higher costs if batches fail or must be resubmitted. Merchants may benefit from combining batch and real-time payment methods, potentially using a PCI-compliant third-party token vault to securely retain payment details and support flexible processing.
Mar 04, 2024 918 words in the original blog post.