A payment vault stores a customer’s card details and hands back a token to use in their place. payFURL Vault does that as an additional layer alongside whatever vault a business’s payment provider already runs, not instead of it, so a stored card can work across more than one provider rather than being locked to just one.
The Vault isn’t there to compete with what a provider already offers, it’s built to sit alongside it and add something they can’t provide on their own: a copy of that card that isn’t locked to any one gateway. That’s what gives a business options, whether that’s running two providers side by side, failing over automatically, or adding a new provider later without re-collecting a single card.
Enter a card once, through payFURL’s hosted checkout, and it’s encrypted and stored inside payFURL’s own PCI-scoped vault. In its place, payFURL creates a token, a safe stand-in with no value to anyone outside the vault. The business doesn’t need to manage the card data itself: whenever a charge, renewal, or provider switch comes up, payFURL retrieves the right payment method from the vault and uses it.
This process, tokenisation (or tokenization in American spelling), is the method the PCI Security Standards Council points to for shrinking how much of a business’s own systems fall under card-data compliance rules.
Every payFURL account has one of these running underneath it: payFURL Vault, the reason a card only ever has to be entered once.
We built payFURL because we believe companies should never lose a sale, overpay on a transaction, or fall victim to fraud because their payments infrastructure failed them. The Vault is that belief applied to one particular, unglamorous problem: a renewal payment that fails for reasons that have nothing to do with whether the customer wants to keep paying. Most businesses only find out once it’s already gone wrong.
Key facts
How payFURL Vault works
A customer enters their card through payFURL’s hosted checkout. The raw card number never touches the business’s own server.
The card data is encrypted straight away, inside payFURL’s PCI-scoped environment, using AWS Key Management Service.
payFURL creates a token for that payment method and keeps the underlying card data safely in the vault. The business only ever deals with the token, never the raw card details.
When a charge or renewal is due, payFURL uses that token to pull the vaulted payment method and authorise it with the business’s chosen provider. If that decline is temporary, payFURL retries it through the business’s nominated backup provider.
Tokenisation vs. encryption (they’re not the same thing)
The two get used interchangeably, and that’s where a lot of confusion starts.
- Encryption is reversible. Scramble the data with a key, and anyone with the right key can unscramble it back to the original card number.
- A token can’t be turned back into a card number without access to the vault that issued it. A token has no mathematical relationship to the card number it replaces, so intercepting one on its own gives an attacker nothing usable. They’d also need separate access to the vault that issued it.
payFURL Vault uses both: encryption to protect the stored card data at rest, tokenisation so that protected data never has to travel anywhere else in a business’s systems.
Why it exists: PCI scope reduction
Any business that takes card payments is, technically, on the hook for PCI DSS, the security standard governing how card data is stored, processed and transmitted. How big that obligation gets depends entirely on how much raw card data touches the business’s own servers.
A business that never stores, processes or transmits a raw card number can usually attest to the lightest self-assessment category, SAQ A, instead of a much heavier one. That’s basically the whole idea behind payFURL Vault: raw card data terminates inside payFURL’s own PCI-scoped environment, never on the business’s own server.
Why more than one vault isn’t redundant
A single card payment usually touches more than one kind of token, and they’re doing different jobs, which is why having more than one doesn’t mean one of them is spare.
The provider processing a charge (Stripe, eWAY, PayPal, or any other) holds its own token, so it can authorise that payment without seeing the card again. payFURL holds a separate, vaulted record of the same card, one that isn’t tied to that provider, so the business has a card file it can use across whichever provider is right for a given transaction. Card networks like Visa and Mastercard can also issue their own network token for a card, bound to one specific business and worthless if it’s ever stolen elsewhere. That’s a standard part of how card networks protect transactions industry-wide, not something specific to any one platform.
These layers sit on top of each other rather than competing. A provider’s own token doesn’t help a business that wants to add a second provider or move away from the first. payFURL’s vaulted record does exactly that, without touching what the provider already does for authorisation.
What’s actually different here
payFURL publishes where card data is held: client data collected in Australia stays in Australia.
payFURL also holds PCI DSS v4.0.1, Level 1 Service Provider certification, independently audited and reassessed every year, the highest tier PCI DSS defines.
And because the vaulted record isn’t tied to one provider, a temporary decline can be retried automatically through a nominated backup provider using that same stored card, without the business or the customer having to do anything.
Why it matters beyond compliance: fewer payments failing silently
For any business running recurring billing (subscriptions, memberships, donations), a failed payment costs more than the one transaction. Baremetrics, a subscription analytics firm, puts the average cost of failed payments at close to 9% of monthly recurring revenue, citing separate research from Paddle that puts involuntary churn at 20 to 40% of total churn, depending on the business.
payFURL Vault is built around that specific failure mode in three ways: a failed charge doesn’t have to be the end of the payment, a temporary decline can be retried through a nominated backup provider using the same vaulted card, and if a business changes provider entirely, the card file moves with it instead of forcing every customer to re-enter their details.
FAQ
No. A gateway processes a transaction and moves money. A vault stores the payment credential used to authorise that transaction. Many providers bundle a basic vault into their gateway, but that vault typically only works with that one gateway. payFURL Vault is provider-agnostic by design.
No, it reduces the scope of what needs to be assessed, not the obligation to be compliant at all. The vault itself still has to meet the full standard; tokenisation just keeps that burden off every other system the business runs.
The card isn’t lost. It can be moved to a new provider, one payment method at a time, without asking the customer to re-enter their details.
Not by tracking card expiries or refreshing reissued cards automatically. That’s not something payFURL Vault does today. What it does help with is what happens after a charge fails: a retry through a nominated backup provider on a temporary decline, and a card file that isn’t lost if the business switches providers.
With payFURL, most businesses are live within days, not months. Setup is a single API integration or dashboard-only provider configuration, with no additional code required.
Every payment, perfected. Reduce costs. Reduce fraud. Increase revenue.
Sources: PCI Security Standards Council, Tokenization Guidelines; Baremetrics, Involuntary Churn.
Talk to us about the Vault.
PCI DSS v4.0.1, tokenised end-to-end, provider-agnostic by design.