Home / Companies / Basis Theory / Blog / November 2024

November 2024 Summaries

5 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
At a November 2024 Merchant Risk Council webinar, Basis Theory CEO Colin Luce described “Payments 3.0” as a shift away from reliance on a single payment service provider toward customized, distributed payment stacks that let merchants select specialized providers for vaulting, processing, fraud prevention, analytics, and orchestration. He contrasted this B2B infrastructure unbundling with the rebundling of consumer fintech services into super apps, arguing that merchants need centralized systems for secure credential storage and compliance while retaining the flexibility to connect with multiple external providers. Luce also emphasized that expanding recurring-payment capabilities across alternative payment methods and real-time rails will require more sophisticated token management, including relationships among PANs, network tokens, and processor-specific tokens. Payment optimization, he said, should prioritize conversion, authorization rates, growth, and customer experience before transaction cost, using real-time card, geographic, and transaction data to route payments intelligently and reduce friction such as 3DS challenges. He concluded that merchants should optimize their existing processor integrations and payment data payloads before simply adding more processors, particularly in their highest-volume markets.
Nov 26, 2024 1,505 words in the original blog post.
The quarter began with the release of Token Intents and Bank Verification Enrichment, alongside several webhook and portal improvements. Token Intents are short-lived resources that accept card details, including CVC, from Elements and allow merchants up to 48 hours to authorize a card before creating and storing a vault token; successful authorizations can be converted into PCI-compliant tokens without CVC, while unsuccessful attempts expire automatically. This approach can help merchants manage processor downtime and avoid storing invalid card information. Bank Verification Enrichment validates whether bank accounts exist and can be charged for ACH pay-ins or payouts, supporting use cases such as marketplace disbursements, fintech payments, and subscription billing. Additional updates include email alerts for disabled webhooks, Terraform support for webhook creation, more specific HTTP header logs, and small portal usability fixes for MFA.
Nov 20, 2024 365 words in the original blog post.
Payment processors move funds between customers and merchants through card networks and other payment methods, while payment gateways provide merchant-facing technology, support, predictable pricing, and connections to processors; in practice, many major providers now perform both roles. Payment orchestrators add a decisioning layer that lets merchants route individual transactions among multiple processors and gateways based on factors such as approval rates, pricing, risk, payment type, and chargeback exposure, although they do not process payments themselves. Rather than choosing only one provider type, merchants can combine gateways, processors, and orchestration to improve transaction success, reduce costs, support more payment methods, and avoid dependence on a single provider. Effective orchestration depends on secure tokenization, programmable APIs or SDKs, and clear data portability if a merchant changes partners or brings payment operations in-house.
Nov 19, 2024 1,067 words in the original blog post.
Merchant payments cover a business’s outbound financial obligations, including payments to suppliers, vendors, partners, and customer refunds, and are the cost-side counterpart to inbound customer payments. Businesses are increasingly replacing paper checks with electronic payment methods to reduce administrative work, improve cash-flow visibility, strengthen supplier relationships, and accommodate recurring transactions, with Same-Day ACH volume rising 67% in the third quarter of 2024. Available automation options include accounting software vendors such as QuickBooks, NetSuite, and SAP; plug-ins such as Versapay and Paystand; standalone platforms such as Bill.com and Tipalti; and token orchestration providers such as Basis Theory, which vault sensitive data and provide integrations while reducing PCI compliance burdens. As digital payments expand, protecting card and payer information remains essential, illustrated by creator platform Passes, which abandoned plans to build its own cardholder data environment after recognizing the operational, training, audit, and security demands involved.
Nov 07, 2024 654 words in the original blog post.
PCI DSS 4.0 introduced more than 50 future-dated requirements that were scheduled to become mandatory on March 31, 2025, creating significant implementation and assessment obligations for organizations handling cardholder data. Key changes include requiring multi-factor authentication for all access to cardholder data environments, a technically demanding requirement primarily affecting businesses that store payment data in-house rather than relying on third-party vaulting or payment providers. Requirements concerning payment-page script security, including 6.4 and 11.6, require organizations to inventory, authorize, justify, monitor, and protect third-party scripts used on checkout pages to reduce web-skimming and formjacking risks, with options including removing unnecessary scripts or using a fully hosted payment page from a payment service provider. Additional protections require a web application firewall or equivalent controls, while updated SAQ and RoC processes emphasize risk assessments when environmental changes occur. The material advises merchants to prepare carefully to avoid noncompliance and notes that outsourcing payment-data handling can reduce PCI scope and simplify compliance efforts.
Nov 06, 2024 752 words in the original blog post.