HostedPCI FAQ: Tokenization, PCI & Payment Gateways

Find answers to common questions about HostedPCI, payment tokenization, PCI compliance, payment vaulting, payment gateways and secure payment integrations.

About HostedPCI

What is HostedPCI?

HostedPCI is a PCI DSS Level 1 service provider offering secure payment capture, tokenization, payment vaulting and multi-gateway connectivity. HostedPCI helps businesses reduce PCI scope while keeping sensitive cardholder data out of their systems.

Is HostedPCI a payment processor or payment gateway?

No. HostedPCI is a secure payment infrastructure layer that connects businesses to supported payment gateways and processors while keeping sensitive cardholder data out of their systems.

What services does HostedPCI provide?

HostedPCI provides payment tokenization, secure payment vaulting, hosted payment capture, multi-gateway connectivity, payment orchestration, 3D Secure and secure phone payment solutions.

Is HostedPCI a PCI DSS Level 1 service provider?

Yes. HostedPCI is a validated PCI DSS Level 1 service provider and has maintained Level 1 compliance for more than 15 consecutive years.

What uptime does HostedPCI provide?

HostedPCI provides a 99.9% uptime commitment, with specific service-level terms defined in the applicable agreement.

Does HostedPCI provide 24/7 technical support?

Yes. HostedPCI customers receive access to 24/7 technical support through dedicated support channels.

How much does HostedPCI cost?

Pricing varies based on transaction volume, services and integration requirements, with custom packages available for more complex environments.

Learn more: HostedPCI Pricing

Payment Tokenization & Vaulting

What is payment tokenization?

Payment tokenization replaces sensitive cardholder data with a non-sensitive token that can be used in business systems without storing the actual card number.

What is a HostedPCI token?

A HostedPCI token is a secure, non-sensitive reference that represents a stored payment card. Businesses can use the token for payment workflows without storing the underlying card number in their own systems.

What is a payment vault?

A payment vault securely stores sensitive payment data and provides tokens that businesses can use instead of storing actual card numbers in their applications.

Why use an independent payment vault?

An independent payment vault keeps stored payment credentials separate from a single gateway or processor. This gives businesses more flexibility to change processors, use multiple gateways and reduce payment provider lock-in.

Where does HostedPCI store cardholder data?

HostedPCI stores cardholder data in its secure PCI DSS Level 1 payment vault, with supported data residency options in Canada, the United States, Europe and Australia.

Can customers have multiple stored payment cards with HostedPCI?

Yes. HostedPCI can securely store multiple payment cards for a customer, with each card represented by its own HostedPCI token.

Can HostedPCI tokens be stored in a CRM, ERP or other application?

Yes. HostedPCI tokens can be stored in business applications instead of the underlying card number, helping keep sensitive cardholder data out of CRMs, ERPs and other systems.

Can HostedPCI separate payment data for multiple clients or business units?

Yes. HostedPCI can use separate vault profiles to organize payment data by client, gateway, country, currency or other business requirements.

Can the same HostedPCI token be used with different payment gateways?

Yes. HostedPCI's gateway-neutral vault allows the same token to be used with different supported payment gateways configured within the merchant's environment.

What is the difference between HostedPCI tokenization and gateway tokenization?

Gateway tokenization generally creates and stores a token within a specific gateway or processor ecosystem. HostedPCI tokenization keeps the payment credential in an independent HostedPCI vault, giving businesses greater portability across supported gateways.

Does HostedPCI permanently store CVV?

No. HostedPCI does not permanently store CVV. A temporary CVV token can be used for the initial transaction and expires after use or after a limited period.

Payment Gateways & Processing

Which payment gateways does HostedPCI support?

HostedPCI supports more than 100 payment gateway integrations, including Stripe, Adyen, CyberSource, Worldpay, Chase Paymentech, Braintree and Authorize.Net. Supported features and transaction types vary by gateway.

Learn more: HostedPCI Supported Payment Gateways

Technical details: HostedPCI Gateway Parameter Guide

How does HostedPCI work with multiple payment gateways?

HostedPCI provides a normalized payment layer that connects businesses to multiple supported gateways. Merchants can use a consistent HostedPCI integration while routing transactions to different payment providers.

Can I switch payment processors or gateways without replacing my HostedPCI tokens?

Yes. Because payment credentials are stored in HostedPCI's independent vault, businesses can change supported gateways while continuing to use their HostedPCI tokens.

What is the difference between HostedPCI and a payment gateway?

A payment gateway handles payment transaction processing and communication with payment networks or processors. HostedPCI provides the secure payment data layer for capture, tokenization and vaulting and connects that data to supported gateways.

What information does HostedPCI need to connect to my payment gateway?

Requirements vary by gateway and may include merchant IDs, API credentials, security keys or other authentication details. HostedPCI provides gateway-specific requirements in its Gateway Parameter Guide.

Can I continue using my payment gateway's fraud prevention tools?

Yes, where supported by the gateway. HostedPCI can pass supported fraud and transaction data to the gateway so merchants can continue using available fraud prevention tools.

How does HostedPCI support recurring payments?

HostedPCI tokens can be used for recurring and Credentials on File payment workflows with supported gateways, allowing future payments without storing the underlying card number in the merchant's systems.

How do refunds work with HostedPCI?

HostedPCI supports refund or credit transactions through supported payment gateways. Available refund functionality depends on the specific gateway integration.

What payment transactions does HostedPCI support?

HostedPCI supports payment operations including authorization, sale, capture, void and refund or credit with supported gateways. Available transaction types vary by gateway.

Can one stored payment method be used across multiple merchant accounts or gateways?

Yes, where configured and supported. A HostedPCI token can be used across multiple payment profiles and supported gateway connections within the merchant's environment.

Does HostedPCI support ACH payments?

Yes. HostedPCI supports ACH tokenization and payment workflows through supported integrations, including Stripe ACH.

PCI Compliance & Security

How does HostedPCI help reduce PCI DSS scope?

HostedPCI helps reduce PCI DSS scope by securely capturing and vaulting cardholder data so merchant applications can use tokens instead of directly handling sensitive card numbers.

Does using HostedPCI automatically make my business PCI compliant?

No. HostedPCI can significantly reduce PCI DSS scope, but merchants must still meet the PCI DSS requirements that apply to their specific payment environment and integration.

Which PCI SAQ applies when using HostedPCI?

The applicable PCI SAQ depends on how payments are accepted and how HostedPCI is implemented. Merchants must meet all eligibility requirements for the SAQ they use.

Do I still need vulnerability scans when using HostedPCI?

Using HostedPCI can reduce the systems subject to PCI DSS scanning requirements, but it does not automatically eliminate every scanning requirement. Remaining requirements depend on the payment integration, environment and applicable PCI DSS requirements.

How often does PCI DSS compliance need to be validated?

PCI DSS compliance is generally validated annually, although specific security activities and scanning requirements may need to be completed more frequently.

Does HostedPCI provide an Attestation of Compliance (AOC)?

Yes. HostedPCI provides its current PCI DSS Attestation of Compliance as a validated Level 1 service provider.

How does tokenization protect cardholder data?

Tokenization replaces sensitive card numbers with non-sensitive tokens, reducing the amount of cardholder data stored, transmitted or processed within merchant systems.

How does HostedPCI support 8-digit BINs while meeting PCI DSS requirements?

HostedPCI can support 8-digit BIN requirements through configurable token formats while keeping the underlying card number protected within its PCI DSS Level 1 vault.

Integration & Development

How does HostedPCI integrate with websites and applications?

HostedPCI integrates through secure hosted payment components and APIs, including payment iframes, tokenization APIs and payment transaction APIs.

What ecommerce platforms can HostedPCI integrate with?

HostedPCI can integrate with ecommerce platforms and custom checkout applications that can use its hosted payment components or APIs.

Can HostedPCI integrate with custom applications, CRMs and ERP systems?

Yes. HostedPCI APIs and tokenization services can integrate with custom applications, CRMs, ERPs, booking systems, billing platforms and other business applications.

How does the HostedPCI iframe work?

The HostedPCI iframe securely captures payment card data within a merchant's checkout experience and returns a token instead of exposing the actual card number to the merchant's application.

Which browsers and mobile devices support the HostedPCI iframe?

The HostedPCI iframe supports current major desktop and mobile browsers, including Chrome, Edge, Firefox and Safari.

How does HostedPCI support mobile payment experiences?

HostedPCI's hosted payment components can be used in mobile-friendly payment experiences while keeping sensitive cardholder data out of the merchant's application.

What APIs does HostedPCI provide?

HostedPCI provides APIs for payment tokenization, payment transactions and other secure payment data workflows, allowing businesses to build custom payment integrations.

Learn more: HostedPCI Documentation Guide

Does HostedPCI provide staging and production environments?

Yes. HostedPCI provides separate staging and production environments so businesses can build and test integrations before processing live transactions.

How do we perform end-to-end testing with a payment gateway?

HostedPCI provides a staging environment for integration testing. End-to-end gateway testing uses the test capabilities and credentials available from the selected payment gateway.

Additional HostedPCI Capabilities

How does HostedPCI support 3D Secure?

HostedPCI supports 3D Secure 2 with multiple payment gateway integrations to help authenticate ecommerce transactions and manage payment fraud risk.

How does HostedPCI secure payments over the phone?

HostedPCI provides secure IVR and call-center payment solutions that allow customers to enter payment information without verbally providing sensitive card details to an agent.

How do HostedPCI payment links work?

HostedPCI supports secure payment collection through SMS and email links, allowing customers to enter payment information through a HostedPCI-hosted payment experience.

What is payment orchestration and how does HostedPCI support it?

Payment orchestration connects businesses to multiple payment gateways and payment services through a centralized infrastructure layer. HostedPCI supports multi-gateway routing while maintaining centralized payment tokenization and vaulting.

How does HostedPCI support payment gateway failover?

HostedPCI supports multi-gateway payment architectures designed for payment routing and redundancy. Failover configurations can be tailored to the merchant's gateways and routing requirements.

Where can HostedPCI store payment data?

HostedPCI provides payment data residency options in Canada, the United States, Europe and Australia, giving businesses flexibility over where their payment data is stored.

Getting Started With HostedPCI

What do I need to get started with HostedPCI?

Businesses typically start by defining their payment use case, selected payment gateways and integration requirements. HostedPCI then provides account setup, credentials, documentation and access to the appropriate staging environment.

Do I need a merchant account and payment gateway to use HostedPCI?

For payment processing, businesses generally need a merchant account or processor relationship and a supported payment gateway. HostedPCI connects securely to these providers rather than replacing them.

How long does a HostedPCI integration take?

Integration timelines depend on the HostedPCI services, payment gateways and complexity of the payment environment. HostedPCI works with each business to determine the implementation requirements for its specific use case.

Where can developers find HostedPCI integration documentation?

Developers can use the HostedPCI Documentation Guide for iframe integration, tokenization, payment APIs, IVR, 3D Secure, ACH and gateway-specific implementation requirements.

Learn more: HostedPCI Documentation Guide