Home / Companies / Basis Theory / Blog / October 2025

October 2025 Summaries

11 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
Businesses may be designated high-risk based on their industry, financial stability, chargeback and fraud history, regulatory exposure, transaction patterns, and sales practices such as recurring billing, subscriptions, free trials, and card-not-present transactions. Payment service providers and acquirers evaluate content, financial, reputational, money-laundering, and transaction-laundering risks through automated monitoring, documentation reviews, and sometimes on-site verification, with higher-risk merchants typically facing elevated fees, rolling reserves, and closer underwriting scrutiny. Visa’s Integrity Risk Program, introduced in 2023, categorizes high-integrity-risk merchants into three tiers according to the potential severity of illegal activity and consumer harm, while Mastercard’s BRAM program addresses noncompliance and may result in merchants being listed in the MATCH database. MATCH listings can arise from issues including data compromises, laundering, fraud, insolvency, standards violations, illegal transactions, excessive chargebacks, or excessive fraud, potentially limiting access to payment processors. Specialized providers such as PaymentCloud, Soar Payments, and Durango serve different segments of the high-risk market, but merchants are encouraged to reduce risk through strong data security, fraud controls, chargeback management, tokenization, and multi-gateway payment strategies.
Oct 28, 2025 2,098 words in the original blog post.
High-risk merchants are businesses viewed by card networks and payment service providers as more likely to generate fraud, disputes, or chargebacks, either because their chargeback rate exceeds roughly 1% or because they operate in industries such as gambling, cannabis, adult content, e-commerce, subscriptions, travel, and digital health. These merchants often face stricter underwriting, higher processing fees, reserve requirements that may withhold up to 5% of transactions, longer contracts, and possible payment interruptions, with classifications determined by network-specific risk programs and factors including transaction volume, international sales, limited operating history, credit profile, and industry affiliation. While merchants classified because of excessive chargebacks may lower their risk designation by improving customer communication, refunds, fraud prevention, compliance, and transaction monitoring, businesses in inherently restricted sectors may remain high-risk indefinitely. The text recommends working with experienced processors, maintaining relationships with multiple payment service providers, using tokenization to retain control of customer card data when switching providers, and prioritizing transparent policies and customer service, illustrated by creator platform Passes, which adopted a multi-provider strategy after a processor unexpectedly shut off its service.
Oct 28, 2025 1,343 words in the original blog post.
Following the 1999 repeal of Glass-Steagall, which had separated conventional banking from riskier investment activities, narrow banks and neobanks have emerged as alternative models with distinct approaches to risk and services. Narrow banks hold full reserves and invest only in low-risk assets such as government securities, limiting lending-related exposure but relying mainly on customer fees for revenue, while neobanks provide app-based banking services through partnerships with licensed banks and commonly earn fees, interchange markups, and foreign-exchange charges. Few businesses fully combine both models because neobanks generally depend on traditional banks to safeguard deposits, although Wise is presented as a close example because it avoids lending and holds much of its customer funds in government-backed securities. For merchants, neobanks may offer more practical benefits than narrow banks by supporting multicurrency treasury management, helping serve customers with limited access to conventional banking, and potentially enabling payment methods that reduce reliance on established card networks and payment intermediaries, while pure narrow banks are expected to remain difficult to establish and largely niche.
Oct 23, 2025 989 words in the original blog post.
Merchants face a trade-off between relying on payment service providers to perform Know Your Customer (KYC) checks and gaining control of the customer data needed for identity verification, payment validation, underwriting, and potential migration to other providers. While PSP-managed KYC can simplify compliance, it may leave merchants unable to access or reuse customer personally identifiable information (PII), forcing them to recollect data when changing providers or adding multiple PSPs. Managing KYC data directly presents cybersecurity, data-residency, regulatory, cost, and operational challenges, particularly because storing sensitive information expands an organization’s compliance responsibilities and breach exposure. The text argues that tokenization platforms and secure data vaults can offer an alternative by storing encrypted PII outside a merchant’s systems while allowing token-based access for KYC checks, analytics, sharing, and processing through chosen PSPs or gateways. It presents Basis Theory’s tools as an example of this model, in which PII is collected, tokenized, verified through a proxy that reveals plaintext only in transit, and retained securely for later use without exposing raw data to the merchant’s own environment.
Oct 21, 2025 965 words in the original blog post.
Stablecoins are digital tokens typically pegged to fiat currencies such as the U.S. dollar, aiming to combine cryptocurrency’s rapid, low-cost blockchain transfers with greater price stability than assets like Bitcoin. Their reliability depends on transparent, verifiable reserves, as commodity-backed and algorithmic models can lose their peg during market shocks, manipulation, or security breaches, prompting the industry to favor fiat-backed models and tokenized bank deposits. They may reduce friction in domestic and cross-border payments, provide access for underbanked users, and lower merchant processing costs, while major retailers and payment providers such as Stripe are exploring or supporting their use. However, stablecoin transactions are generally final and irreversible, offering fewer consumer protections than card networks and creating risks from fraud, failed merchants, and “rug pull” schemes. Businesses adopting stablecoins may need to combine them with established payment methods, regulatory safeguards such as KYC and AML controls, and tokenization or payment-vault systems to protect customer and wallet information.
Oct 16, 2025 1,399 words in the original blog post.
PCI compliance costs depend largely on a merchant’s annual card transaction volume, with requirements escalating from Level 4 businesses processing fewer than 20,000 transactions to Level 1 businesses processing more than 6 million and subject to external audits. Direct expenses can include logging systems, quarterly vulnerability scans, penetration testing, remediation, redundant infrastructure, and auditor fees, producing estimated annual costs from roughly $70,000 to more than $500,000 for complex enterprises. Indirect costs may arise from segregating payment environments, expanding IT and operations staffing, and diverting resources toward recurring security work, while breaches can lead to higher processing and chargeback fees, reserve holdbacks, and reputational damage. Non-compliance may result in card-brand fines, increased transaction fees, fraud and breach liability, mandatory remediation, or loss of the ability to accept card payments. Merchants can reduce PCI scope by using full-service payment providers or tokenization platforms that store card data and provide tokens, although full-service providers can limit portability, whereas token orchestration platforms may allow merchants to use multiple payment providers while shifting much of the compliance burden externally.
Oct 16, 2025 1,225 words in the original blog post.
Basis Theory announced a $33 million Series B funding round led by Costanoa Ventures, with participation from Stage 2 Capital, Moneta VC, and existing investors including Bessemer Venture Partners, Kindred Ventures, Box Group, and Offline Ventures. The company says the investment will support its goal of giving merchants greater control over payment data and infrastructure, particularly as AI-driven agentic commerce expands. Basis Theory recently launched basistheory.ai and helped establish the Agentic Commerce Consortium, initiatives intended to enable secure, controlled adoption of AI agents that can initiate, approve, and manage transactions. The funding is expected to accelerate development of PCI-compliant agentic payment capabilities, broaden support for payment methods and international use cases, and strengthen the platform for future security needs, while its existing payment vault aims to reduce vendor lock-in, improve authorization rates, and lessen PCI compliance burdens.
Oct 14, 2025 694 words in the original blog post.
September’s updates introduced performance, feature, and integration enhancements aimed at improving developer speed and security, including fixes for Web Elements autocomplete and focus behavior and a new Copy Button element for securely copying values from other components. A new DELETE /apple-pay/{id} endpoint allows Apple Pay resources to be unlinked and automatically deleted in one step. The team also released an AI Commerce whitepaper, completed Visa IC/MC AgentPay integration and certification, and resolved an issue affecting unavailable documents. In addition, the /connections/apple-pay and /connections/google-pay features were deprecated and are scheduled to shut down on December 1.
Oct 10, 2025 134 words in the original blog post.
Open banking allows consumers to authorize approved third-party providers to access and aggregate data from multiple financial accounts through APIs, replacing traditionally siloed banking relationships with centralized views and services. Data APIs support account visibility, transaction APIs enable activities such as bill payments, and product APIs help identify or compare financial offerings. Providers can use this access to offer personal financial planning, direct bank-based payments, personalized recommendations, automated invoicing and budgeting, faster credit decisions, and improved payment collection for businesses. Because aggregating sensitive financial data increases exposure to breaches, privacy concerns, and regulatory compliance costs, tokenization can protect information by substituting sensitive data with unusable tokens stored in secure external vaults. The combination of open banking and tokenization is presented as a way to expand convenient financial services while limiting data access, reducing security risks, and easing compliance demands.
Oct 09, 2025 1,103 words in the original blog post.
PCI DSS 4.0 merchant compliance levels, established by the PCI Security Standards Council, categorize organizations primarily by annual card transaction volume to determine the effort required to demonstrate compliance, rather than the underlying security requirements, which apply to all entities that store, process, or transmit cardholder data. Using general Visa-based thresholds, Level 1 covers merchants processing more than 6 million transactions annually, Level 2 covers 1–6 million, Level 3 covers 20,000–1 million, and Level 4 covers fewer than 20,000, although card brands and acquirers may apply different thresholds or impose stricter levels after incidents or for high-risk businesses. Level 1 generally requires quarterly network scans, external penetration testing, and an on-site Qualified Security Assessor review resulting in a Report on Compliance, while Levels 2 through 4 commonly rely on quarterly Approved Scanning Vendor scans and Self-Assessment Questionnaires, with Level 2 sometimes subject to additional acquirer requirements. Merchants should use historical or projected volume to identify their level and confirm it with their acquirer, while recognizing that PCI-compliant payment service providers and tokenization technologies can reduce the systems exposed to card data and therefore lessen assessment, testing, cost, and operational burden without changing the merchant level itself.
Oct 07, 2025 1,533 words in the original blog post.
PCI DSS is a payment-card security standard that requires merchants and service providers handling cardholder data to protect it through 12 broad controls covering network security, secure configurations, encryption, vulnerability management, secure development, access restrictions, authentication, physical safeguards, logging, testing, and security policies. Compliance obligations generally increase with annual transaction volume, with Visa’s Level 1 applying above six million transactions and requiring an independently assessed Report on Compliance, while lower levels commonly use Self-Assessment Questionnaires. Organizations that store, process, or transmit card data are responsible for compliance, although payment and tokenization providers can reduce the systems and processes included in a merchant’s compliance scope. Compliance can involve substantial implementation, maintenance, testing, audit, personnel, and opportunity costs, particularly for larger organizations, while noncompliance can lead to fines, higher processing costs, added requirements, legal action, and remediation work after incidents. The material emphasizes limiting direct exposure to cardholder data through service providers, encryption, tokenization, and segmented cardholder-data environments as a way to reduce risk and administrative burden, though such approaches may involve tradeoffs in payment flexibility and data use.
Oct 06, 2025 3,231 words in the original blog post.