Home / Companies / Basis Theory / Blog / Post Details
Content Deep Dive

What is Sensitive Authentication Data?

Blog post from Basis Theory

Post Details
Company
Date Published
Author
Basis Theory
Word Count
682
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

Sensitive Authentication Data (SAD) is payment-card security information used to authenticate cardholders or authorize transactions, including PINs and PIN blocks, CVV or CVC codes, full magnetic-stripe track data, and emerging authentication methods such as biometrics. Unlike a primary account number, which identifies and routes a transaction, SAD helps verify that the person making a purchase possesses or owns the card, making it particularly valuable for fraud prevention. Under PCI DSS v4.0, most organizations may retain SAD only for the time needed to complete authorization and must then securely delete it, while card issuers may store it only when they have a documented business need and strong security protections, including encryption. Other cardholder data, such as PANs, names, and expiration dates, can be stored under extensive PCI DSS controls, although businesses may use specialized PCI-compliant service providers to reduce the cost and time required to build and maintain their own compliant environments.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.