Home / Companies / Basis Theory / Blog / August 2024

August 2024 Summaries

4 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
Basis Theory’s June and July updates focused on enterprise identity management, event visibility, and platform usability. Enterprise administrators gained read-only user roles and improved insight into enabled features, login providers, and two-factor authentication status, while support for OCID, SAML, and Okta enterprise connections was introduced; future additions are expected to include organization-wide 2FA enforcement and email-domain restrictions. Webhook subscriptions entered private beta, enabling customers to receive Tenant event notifications for service monitoring, debugging, and asynchronous workflows. Other improvements included an AMEX Account Updater fix, broader tokenization field support, React Native input overrides, test BIN details, fingerprint-related token performance enhancements, completed rate-limit rollout, CardDetails enrichment for card tokens, self-managed Tenant quotas, and a new Proxies page in the Portal.
Aug 27, 2024 267 words in the original blog post.
Basis Theory’s Chief Information Security Officer explains that he joined the company because its developer-friendly payments vault can reduce the substantial security and PCI compliance burden faced by merchants that handle card data. He views strong compliance as the result of security and privacy being embedded throughout a product, rather than as a separate obligation, and argues that cybersecurity can create customer value and drive revenue rather than function only as a cost center. Since joining, he has introduced automation to identify unused code, removed several hundred unnecessary lines to reduce the attack surface, and is pursuing stronger dependency management and software supply-chain security. He also cites Basis Theory’s culture of sustainable growth, autonomy, collaboration, and willingness to challenge conventional assumptions as an important reason for joining, with the goal of helping build a trusted payment data platform and security-focused brand.
Aug 22, 2024 713 words in the original blog post.
Payment gateways broker transactions between merchants, customers, card networks, and financial institutions by collecting payment data, conducting fraud and account checks, submitting credentials for authorization, and reporting outcomes, while payment switches operate within or alongside gateways to select the most efficient processing route. Using information such as Bank Identification Numbers, switches direct approved transactions toward the appropriate issuer, acquirer, wallet, or other provider to improve authorization rates, speed, and processing costs. They also help gateways connect with a growing range of payment methods, including cards, digital wallets, Buy Now Pay Later services, and local options. Merchants can create their own upstream switches to screen for fraud, categorize transactions by factors such as geography or risk, and route payments among multiple payment service providers based on cost and performance. Building such systems requires secure, PCI-DSS-compliant handling of cardholder data, often through token vaults that store sensitive information and provide transferable tokens for use with different providers.
Aug 06, 2024 933 words in the original blog post.
Gaming revenue has increasingly shifted from one-time game and console sales toward microtransactions for virtual goods, upgrades, unlockables, and currency, particularly in free-to-play titles. As virtual worlds handle valuable assets and billions of transactions, gaming merchants face growing obligations around consumer protection, privacy, fraud, money laundering, and payment-data security, with the CFPB identifying gaming among non-traditional markets it is monitoring in 2024. Companies must balance compliant, secure payment flows with a smooth user experience while maintaining accurate card-on-file information and addressing losses from theft, scams, and criminal activity. For high-risk merchants, the passage suggests that using multiple payment processors alongside third-party tokenization and card-vaulting providers can reduce PCI compliance burdens, preserve control over payment data, support fraud and compliance partners, update stored card details, and improve transaction approval rates.
Aug 01, 2024 602 words in the original blog post.