Token & Vaulting

The HostedPCI tokenization and payment vaulting services are the core of the business that we provide to merchants for all of their online payment needs. The tokenization process replaces the credit card PAN or Automated Clear House (ACH) account details with a secure token. The token is 16 digits in length for Credit Card and also keeps the first four and last four digits of the card to make it easier for Merchants to verify a customer’s card. The real Credit Card PAN and ACH account numbers are stored within a HostedPCI secure vault. Each merchant receives their own staging vault and live vault to keep their information separate from all other merchants.

How it works

The token that is used by HostedPCI looks like a real credit card. The first 4 digits and the last 4 digits of the token match those of the credit card number, but in fact, the token is not a real credit card number. By default, the token fails MOD 10 (Modulus 10) LUHN checks. The combination of the credit card PAN tokens is customizable according to the needs of the merchants. The available combinations are 4+8+4, 1+11+4, 6+6+4, and 8+4+4 (8-digit BIN). The ACH data token will contain the same first two digits of the Routing Number and will also have the same last 4 digits as the Account Number.

Once HostedPCI has collected the credit card or ACH data using one of the methods listed above, it is then stored within a merchant-specific designated vault. All merchants receive their own staging and production vault, completely separate from all other merchants that use our solution. Each vault is set up as its own environment, which means that tokens cannot be interchanged between vaults — each set of tokens created within a vault is for that vault only and cannot be used in any other vault. This logic ensures that each merchant’s data is securely stored and cannot be accessed by anyone who does not have the specific token generated by your iFrame and API credentials.

The HostedPCI tokenization and vaulting solution is independent and durable, which means it can be used with any payment gateway that is on our list of supported gateways. For more information on our vaulting solutions please contact us.

Case Studies

Travel

HPCI Travel Case Study

This merchant required the ability to collect and store credit cards securely from their booking page until required for payment. The transaction process starts with the first 2 requests being sent to the airline company to determine if tickets were available and then the 3rd transaction needs to be sent securely with the credit card number to the airline.

Municipality

HPCI Municipality Case Study

This municipal merchant of ours required the ability to accept credit cards from their clients in a PCI compliant way in order to reduce their PCI scope as much as possible. The biggest trouble was to collect the customer’s card over the phone while being able to provide guidance to their clients regarding the transaction process and also collect the card during off hours with an unassisted IVR.

Insurance

HPCI Insurance Case Study

This merchant needed the ability to securely collect and store the credit card information that they received from their customers within their call centres and then send this information along with the customer data over to their designated Payment Gateway to complete the transaction. In this case the merchant had a different merchant account for each of their call centre sites — in total, 7 different gateway merchant accounts needed to be configured.