•••• •••• •••• 1246 PAN · not stored
Tokenized on the platform — PCI DSS Level 1 vault
Token issued Recurring & one-click
tok_7f3a…9c21
Local vault Visa Token Service (VTS) Mastercard SCOF
Acquirer migration — case study 02 ~1 week
Tokens moved to the new acquirer95%
Zero customer action — recurring payments never stopped
Tokenization

Tokenization — local vault, Visa Token Service and Mastercard SCOF

Payment tokenization replaces a customer’s Primary Account Number (PAN) with a unique, non-sensitive token — entirely worthless to a fraudster if intercepted. Your merchants keep the token for recurring subscriptions, one-click checkouts and refunds without ever holding the actual PAN.

  • Local tokenization and card vault — cards are tokenized on the platform and held in a PCI DSS Level 1 vault; raw cardholder data never enters or resides within your merchants’ systems
  • Visa Token Service (VTS) — supported since 2022
  • Mastercard Secure Card on File (SCOF) — supported since 2024
  • Token migration between acquirers — token extraction, conversion and re-tokenisation handled at the infrastructure level; 95% of a PSP’s stored tokens moved in about one week with zero customer action
  • Tokenized recurring payments — with smart retry logic and full automation for SaaS, memberships and subscriptions
Read the tokenization guide

Frequently asked questions

Payment tokenization is a process of data substitution that replaces highly sensitive data, most commonly a customer's Primary Account Number (PAN), with a unique, non-sensitive equivalent known as a token. The token retains certain non-sensitive elements like the last four digits and the card scheme, but is entirely worthless to a fraudster if intercepted.

Unlike encrypted data, which can be reversed to its original form with the correct decryption key, a stolen token cannot be mathematically reversed to reveal the PAN. The original data is removed from the merchant's environment entirely and held in an ultra-secure, off-site data vault managed by the tokenization service provider.

By ensuring that raw cardholder data never enters or resides within the merchant's systems, the number of systems, processes, and personnel that fall under PCI DSS requirements is dramatically reduced. This translates into lower audit costs, reduced complexity, and a significantly smaller attack surface.

Set up your payment processing system

in 7 days, not a year
Request demo