Cards

What is Card vault?

A PCI DSS compliant store of tokenised card credentials that lets a merchant charge a card again without holding the PAN.

A Card vault is a secure, PCI DSS compliant system used to store sensitive payment card details, primarily the Primary Account Number (PAN).

Its chief function is to reduce a merchant's compliance burden by offloading the storage of this hazardous data to a certified third party, such as a payment gateway or PSP.

Instead of holding the PAN, the merchant stores a non-sensitive surrogate value known as a token. This token acts as a reference, allowing the merchant to initiate future payments without ever touching the raw cardholder information, thereby significantly descoping their PCI DSS obligations.

When a customer makes their first purchase, their card details are sent directly to the vault provider's secure environment. The vault then returns a unique token to the merchant, which is saved against the customer's profile.

For subsequent transactions, such as for a recurring subscription or a one-click Checkout, the merchant simply sends this token and the transaction amount to the payment provider. The provider uses the token to retrieve the securely stored PAN and process the payment.

A common point of confusion is the portability of these tokens. Most basic vault tokens, often called gateway or PSP tokens, are proprietary.

This means they are tied to a specific payment provider, creating lock-in and making it difficult for a merchant to switch providers without undergoing a complex and costly data migration project.

Worked example

A customer signs up for a £29.99 monthly subscription for a SaaS product. During the initial sign-up, they enter their Mastercard details into the Checkout form.

These details are transmitted directly to Cardflo's PCI DSS Level 1 compliant vault, bypassing the SaaS merchant's servers entirely. Cardflo's vault stores the PAN and returns a unique, non-sensitive token, for example, `Cflo_tok_xyz789`, to the merchant.

The merchant stores this token in their database, associated with the customer's subscription. One month later, the merchant's billing system automatically initiates a Merchant-Initiated Transaction (MIT) by sending a request to Cardflo's API containing the token `Cflo_tok_xyz789` and the £29.99 charge amount.

Cardflo retrieves the underlying card details and processes the payment, never exposing the PAN to the merchant. This process greatly reduces the merchant's PCI scope and risk of a data breach.

Scheme notes

The concept of a vault is provider-specific technology, not a direct card scheme product. However, modern vaults are deeply integrated with scheme services.

Both Visa (through its Visa Token Service, VTS) and Mastercard (Mastercard Digital Enablement Service, MDES) strongly advocate for the use of network tokens.

Advanced vaults, like those provided by Cardflo, integrate with VTS and MDES to provision these scheme-native tokens instead of, or in addition to, proprietary gateway tokens.

While a basic vault stores the static PAN, one connected to scheme tokenisation services can ensure the payment credential remains 'live' even if the physical card is lost or expires, as the schemes and issuers update the token in the background.

This is a significant advantage over vaults that only support proprietary tokens.

Why it matters for merchants

Implementing a Card vault is fundamental for any merchant handling card-on-file transactions, such as subscription businesses or e-commerce stores with one-click Checkout. The primary benefit is the drastic reduction in PCI DSS compliance scope, which saves significant time and money on security audits and infrastructure.

By preventing raw card data from ever touching the merchant's systems, a vault also minimises the reputational and financial damage of a potential data breach. However, merchants must be aware of vendor lock-in associated with proprietary vault tokens.

Using a provider like Cardflo, whose vault supports network tokens and offers secure token migration services, provides greater flexibility and allows merchants to route transactions through multiple acquirers, optimising for cost and approval rates without being tied to a single gateway.

Frequently asked

How does using a vault impact a merchant's PCI DSS scope?

Utilising a third-party vault can significantly reduce a merchant's PCI DSS audit requirements, often allowing them to qualify for simpler Self-Assessment Questionnaires like SAQ A or SAQ A-EP.

Because the merchant never stores, processes, or transmits raw PANs on their own servers, the security obligations for their internal infrastructure are greatly diminished.

What is the difference between a PSP-specific vault and a vault-agnostic solution?

A PSP-specific vault ties the tokens to a single acquirer, which can lead to vendor lock-in because those tokens may not be portable to a different gateway.

A vault-agnostic or independent vault provider allows the merchant to store data centrally and route transactions to multiple acquirers, providing greater flexibility and redundancy in their payment stack.

What is the difference between a vault token and a Network token?

A vault token (or gateway token) is a proprietary identifier created by a specific payment provider. It is only recognised within that provider's ecosystem, leading to vendor lock-in.

A Network token is created by the card schemes (Visa, Mastercard) themselves and is interoperable across any payment provider who is integrated with the scheme's token service. Network tokens are generally superior as they are automatically updated by the issuer, reducing declines from expired cards.

Does using a vault make me fully PCI compliant?

Using a vault significantly reduces your PCI DSS compliance scope, but it does not eliminate it entirely. You are still required to complete a Self-Assessment Questionnaire (SAQ), typically SAQ A, which is the simplest form.

This attests that you have outsourced all cardholder data functions to a compliant third party. Your own security practices for your website and systems still matter.

Can I move my vaulted cards from one PSP to another?

Yes, but it can be a complex and costly process. It requires a secure data transfer between the old and new PCI-compliant providers, involving coordination and fees from both parties.

To avoid this lock-in, it is preferable to use a provider that supports network tokens from the outset, as these are portable. Alternatively, choose a provider with a clear and fair policy on data migration.

Does a vault help with authorisation rates?

A basic vault itself does not directly improve authorisation rates; it is primarily a security and compliance tool. However, a modern vault that is integrated with services like network tokenisation and Account Updater will significantly improve approval rates.

These integrated services ensure the stored credentials remain current, preventing declines due to expired or re-issued cards and reducing Involuntary churn.

Is a vault only for subscription payments?

No, while vaults are essential for subscriptions and recurring billing, they are also widely used by e-commerce merchants to offer 'card on file' or 'one-click' Checkout functionality.

This convenience dramatically speeds up the purchasing process for returning customers, which can lead to higher conversion rates and increased customer loyalty. Any merchant who wants to store a customer's card for future use needs a vault.

See how Card vault plays out in practice

Industries and regions where this term drives real acquiring, routing, or dispute decisions.

Related terms

Apply with Cardflo

Ready to improve your payments setup?

Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.

Apply now