August 2025 Summaries
8 posts from Basis Theory
Filter
Month:
Year:
Post Summaries
Back to Blog
A Cardholder Data Environment (CDE) is the collection of systems, networks, applications, people, and processes that store, process, transmit, or can access payment card data and sensitive authentication information under PCI DSS. Because every in-scope component must meet PCI DSS’s 12 requirements and hundreds of sub-requirements, organizations seek to limit CDE scope to reduce security, audit, and operational costs while avoiding potential fines, reputational damage, insurance increases, and legal claims. Common CDE components include web and database servers, point-of-sale terminals, network devices, payment applications, and relevant third-party providers. Organizations may store cardholder data such as primary account numbers, expiration dates, names, and service codes, but are prohibited from retaining sensitive authentication data such as magnetic-stripe data, CVV codes, and PINs after authorization. Achieving compliance involves securely implementing controls, continuously maintaining policies and processes, and completing recurring assessments, while organizations can either build an internal CDE or use a specialized service provider and tokenization platform to reduce their compliance footprint.
Aug 28, 2025
1,022 words in the original blog post.
Payment-stack unbundling refers to replacing a single full-service payment service provider with a coordinated set of specialized partners for functions such as processing, fraud prevention, tokenization, routing, billing, and security. The approach is presented as a shift from the speed-to-market priorities of “Payments 2.0” toward “Payments 3.0,” which emphasizes optimization of approval rates, fees, customer experience, and business-specific requirements. Merchants can use multi-processor routing and programmable payment vaults to direct transactions to suitable providers, retain control of payment data, reduce vendor lock-in, and access more specialized expertise. While bundled providers can be useful for smaller organizations seeking simplicity, the discussion argues that growing merchants may find they are paying for unused features and receiving generalized services, making a customized stack potentially more attractive despite its added implementation and maintenance demands.
Aug 26, 2025
956 words in the original blog post.
PCI-DSS is an industry standard requiring merchants that accept credit cards to protect payment and personal data in transit and storage, with compliance obligations varying across four levels based on sales volume. While full-service payment service providers can simplify early operations by handling processing and much of the compliance burden, relying on one provider can create risks such as fixed or unfavorable fees, restrictive rules, data portability challenges, and business interruptions during outages. A token vault can support a multi-processor strategy by securely storing customer payment details and providing tokens that allow merchants to route transactions among different processors without directly handling sensitive card data. This approach can improve resilience, preserve access to customer payment information, enable payment-method and fee optimization, and provide backup processing options, though it adds some implementation and operational complexity.
Aug 21, 2025
999 words in the original blog post.
Basis Theory introduced a simplified 3D Secure integration for customer-initiated transactions, enabling merchants to redirect users to a hosted authentication page that manages 3DS challenges, while merchant-initiated transactions require 3DS MIT. The company also launched a Documents API for securely uploading, storing, and retrieving sensitive records such as identification, tax, and social security documents, with particular relevance for regulated industries and Vertical SaaS platforms managing multiple payment processors. Internal network optimizations reportedly made most API calls 30% faster, while Web Elements v1.20.0 reduced average first-time load times from 230 ms to 120 ms and cached loads from 110 ms to 80 ms. Additional updates include configurable Web Elements titles, corrected card autocomplete attributes, deprecation of the /latest version in favor of v1.22, and React 19 support for React Native.
Aug 15, 2025
242 words in the original blog post.
AI chatbots and agentic payment systems are reshaping e-commerce by enabling consumers to receive rapid product recommendations and allowing AI agents to shop and pay independently under user-defined rules, but these conveniences may increase chargebacks when purchases are unwanted, misunderstood, or disappointing. Chargebacks already affect roughly 0.6% to 1% of card-not-present transactions, imposing lost revenue, merchandise costs, and bank fees on merchants, and autonomous purchasing could make disputing a charge the fastest way for consumers to reverse an unfamiliar transaction. Merchants can use AI-based fraud prevention tools to counter these risks through real-time risk scoring, behavioral biometrics, device fingerprinting, and synthetic-identity detection, while AI customer support, dissatisfaction prediction, smart payment retries, and clearer billing data can help prevent service-related disputes. Responsible deployment requires merchants to address algorithmic bias, safeguard privacy through consent and data-minimization practices, and comply with standards and laws including PCI-DSS, GDPR, and the CCPA.
Aug 14, 2025
1,534 words in the original blog post.
Credit and debit cards differ primarily in that credit transactions use issuer-provided borrowed funds while debit transactions draw from a consumer’s bank balance, creating lower financial risk and generally lower processing costs for merchants. Debit processing costs vary by transaction type, with signature debit typically routed through Visa or Mastercard networks at higher rates, PIN debit often using regional networks at lower rates, and PINless debit potentially accessing lower-cost domestic routing options. In the United States, the 2011 Durbin Amendment caps many debit interchange fees at 21 cents plus 0.05% of the transaction, whereas full-service payment providers may charge uniform card-processing rates such as 2.9% plus 30 cents regardless of payment type. The material argues that debit’s widespread use, lower dispute window, and reduced risk of nonpayment make transaction routing an important cost-management opportunity for merchants, particularly those that use multiple payment processors and tokenization systems to direct debit transactions to lower-fee providers.
Aug 12, 2025
1,315 words in the original blog post.
AI agents are goal-oriented software systems that use AI to reason autonomously, gather information, ask clarifying questions, adapt to user preferences, and potentially complete tasks such as purchasing travel and updating calendars when granted account access. Unlike chatbots, which primarily provide conversational access to information, or conventional bots, which follow fixed scripts to repeatedly execute narrow tasks, agents can evaluate alternatives and change their approach to achieve broader user goals. Although AI agents may overcome protections such as CAPTCHAs and introduce new fraud or security risks, they can also improve consumer services when used with authorization. Merchants are encouraged to prepare by verifying customers’ consent for agent-led payments, creating dedicated transaction channels, strengthening fraud detection and payment decisioning, and developing policies that balance purchase reversals with chargeback protection.
Aug 07, 2025
1,386 words in the original blog post.
Total processing volume (TPV) measures the value of payments a business processes through a particular payment service provider (PSP) over a defined period, while gross merchandise value (GMV) represents the business’s total sales volume across all channels and providers. Neither metric directly indicates profitability, but comparing TPV by provider with overall GMV can reveal payment-volume distribution, growth trends, dependence on individual processors, and opportunities to negotiate fees. For businesses using a single digital PSP, TPV generally equals GMV, whereas companies with multiple providers can use TPV to evaluate whether their payment mix supports cost efficiency, service needs, and operational resilience. Adding providers may reduce the risk of disruptions caused by a single processor and improve negotiating leverage, although there is no universal transaction-volume threshold at which diversification becomes necessary. The passage also argues that businesses should regularly track TPV and projected growth, consider secure tokenization infrastructure to facilitate working with multiple processors, and use their volume allocation to seek better pricing while retaining backup payment-processing capacity.
Aug 05, 2025
1,024 words in the original blog post.