January 2026 Summaries
8 posts from Basis Theory
Filter
Month:
Year:
Post Summaries
Back to Blog
PCI DSS requires businesses handling payment cards to protect cardholder data in transit and generally prohibits transmitting unencrypted primary account numbers through email and other end-user messaging tools. Email creates exposure across sender and recipient devices, mail servers, caches, folders, and intermediary systems, potentially expanding the cardholder data environment and compliance burden. Although TLS protects some transmission links, meaningful compliance for emailed card data would require end-to-end encryption, which is difficult to deploy because both parties must use compatible encryption methods and securely manage keys. Organizations that receive unencrypted card information should use documented procedures to avoid replying with the data, remove it securely from all storage locations, notify senders of the risk, and involve IT staff. Recommended safeguards include employee training, phishing awareness, secure key handling, and technology providers that enable secure, expiring links or other alternatives, while the preferred approach is to avoid sending sensitive payment information through email altogether.
Jan 27, 2026
1,418 words in the original blog post.
Basis Theory’s December platform updates introduce customer-managed merchant certificates for Apple Pay and Google Pay, allowing businesses to retain existing certificate setups, avoid migration disruption, and support more than Apple’s 99-domain shared-certificate limit through new APIs, SDK capabilities, and documentation. Elements now performs progressively refined client-side BIN lookups as cardholders enter additional digits, improving real-time identification of card brands, types, and issuers, supporting payment-routing decisions, and helping merchants meet EU co-branding requirements. The company is also moving Test Tenants to an isolated environment by March 30, 2026, requiring customers to switch test API calls to api.test.basistheory.com, allowlist new IP addresses, and support a revised webhook signature header, while noting that Test Tenants remain behaviorally aligned with production but are not PCI compliant and must not contain live consumer data. Finally, fixes in specified Web Elements, React, and React Native SDK versions correct card-editing validation so pre-populated token data triggers validation properly and returns accurate field states.
Jan 23, 2026
711 words in the original blog post.
PCI-DSS is a payment-card security standard administered by the PCI Security Standards Council that requires organizations handling major credit card transactions to protect consumer cardholder and personally identifiable information. Compliance scope includes systems that directly collect, store, or transmit cardholder data within the Cardholder Data Environment, as well as systems connected to that environment, while systems with no access to it may remain out of scope; organizations must also account for compliant cloud providers and other partners. Reducing the number of in-scope systems can lower compliance costs, but shared infrastructure and direct connections to cardholder-data systems can expand scope because they may create access paths to sensitive data. Merchants can limit exposure by eliminating direct access to card information, often through payment service providers that collect data and return tokens, though relying on one provider can create dependency and reduce control. Third-party tokenization services offer a more flexible alternative by securely collecting card details and providing tokens while allowing merchants to route transactions through different payment processors, potentially supporting operational flexibility, cost optimization, and reduced PCI-DSS scope.
Jan 22, 2026
707 words in the original blog post.
Payment gateway iframes let merchants embed provider-hosted payment forms within their websites or applications, enabling relatively fast implementation while keeping sensitive payment data off merchant systems. Iframe swapping allows businesses working with multiple payment service providers to dynamically choose and replace the payment form based on factors such as customer location, IP address, payment method, costs, or expected authorization success rates, often without customers noticing. Payment integrations generally range from fully on-site gateways, which provide maximum design control but require substantial engineering, to hosted redirect pages, which are simpler but offer little control, with embedded iframes and on-site checkout with off-site processing occupying the middle ground. Hosted payment experiences may appear as embedded iframes, external redirect pages, or pop-ups, each involving different trade-offs in branding, usability, and implementation. Reputable gateway-hosted iframes can reduce security and PCI compliance burdens because payment data is processed by the provider rather than the merchant, although their customization limits may not suit brands seeking a completely seamless checkout experience. Tools such as Basis Theory Elements aim to combine secure iframe-based data capture and vaulting with greater interface customization and provider flexibility.
Jan 20, 2026
884 words in the original blog post.
Global merchants face added complexity in cross-border payments because of currency conversion, differing regulations, local payment preferences, higher fees, and lower approval rates than domestic transactions. While full-service payment service providers can simplify these challenges, relying on a single provider may create outage risks, obscure costs, limit control over customer data, and forfeit potential foreign-exchange revenue. A multi-processor strategy with geographic routing allows merchants to direct transactions to the most suitable provider based on customer location, processing costs, approval likelihood, risk, transaction volume, and chargeback considerations. Maintaining access to customer payment data is essential for this approach, and programmable third-party token vaults can securely store data while enabling transactions across multiple providers and reducing PCI-DSS compliance scope. By combining tokenized payment infrastructure with intelligent routing systems, merchants can improve resilience, raise transaction success rates, reduce costs, and strengthen margins.
Jan 15, 2026
897 words in the original blog post.
Health and fitness businesses can reduce avoidable revenue loss and involuntary churn by improving payment experiences for member sign-ups, renewals, drop-in purchases, upgrades, trainer payouts, refunds, and peak-demand transactions. High cart-abandonment rates and subscription losses caused by payment failures highlight the value of reducing checkout friction through early mobile-wallet options, fewer form fields, and one-tap purchases. A programmable token vault can securely store card and bank-account information independently of a single payment service provider, enabling brands to use payment data across processors and transaction types while limiting PCI-DSS compliance exposure. For multiregional operators, local payment methods, geographic transaction routing, and retries through local processors may improve authorization rates and lower cross-border costs. The text also emphasizes safeguarding bank details for payouts, applying consistent refund and dispute-management rules, using data or generative AI to identify fraud patterns, and tracking metrics such as mobile conversion, authorization rates, recovered renewals, and monthly involuntary churn.
Jan 13, 2026
832 words in the original blog post.
AI systems such as ChatGPT combine natural language processing, machine learning, and generative AI to interpret prompts, identify patterns in data, and present responses in human-like language, but their probability-based outputs can sometimes be inaccurate. This pattern-oriented approach may be useful for payment orchestration, where merchants using multiple payment service providers can employ custom AI models to assess transaction factors, contracts, fees, volume commitments, and real-time data to select a likely optimal routing option. Unlike static rule-based programs that require manual updates, an AI decisioning engine could continuously adapt to changing approval rates, costs, and transaction patterns. The approach is particularly relevant when paired with a programmable token vault, which can securely store payment details outside a merchant’s core PCI-DSS environment, support repeat purchases, enable additional security checks, and allow merchants to route payments among providers based on factors such as geography, payment method, processing fees, and currency conversion.
Jan 08, 2026
919 words in the original blog post.
Visa’s Acquirer Monitoring Program (VAMP) is intensifying enforcement against card-not-present fraud and disputes, creating greater compliance pressure for merchants and payment service providers through possible fines, holdbacks, and network removal. VAMP calculates a count-based ratio by dividing combined TC40 fraud reports and TC15 disputes by TC05 settled transactions, meaning numerous low-value incidents can materially affect a merchant’s standing. Beginning April 1, 2026, the excessive merchant threshold for the United States, Canada, and EU will decline from 220 to 150 basis points, although merchants generally must also record at least 1,500 combined fraud and dispute events monthly to enter monitoring. Acquirers face substantially lower portfolio-level thresholds, which may lead them to impose stricter requirements on individual merchants regardless of whether those merchants exceed Visa’s direct threshold. Certain pre-dispute resolutions and fraud reports qualifying for Compelling Evidence 3.0 may be excluded, making timely dispute handling and evidence collection important. Merchants are encouraged to establish recurring reporting on fraud, disputes, settled transactions, and VAMP ratios; segment risk by factors such as region, checkout type, product, customer cohort, and payment method; and use fraud scoring, bot prevention, and pre-dispute tools to identify and reduce emerging risks.
Jan 06, 2026
919 words in the original blog post.