Skip to main content

GR4VY

Calculate the ROI of payment orchestration

Access the ROI calculator here.

Payment orchestration has increasingly gained prominence amongst payment professionals and e-commerce businesses. 

By now, most merchants or businesses are aware of what payment orchestration is and have even scouted the market for the various types of payment orchestration layers available – building in-house, infrastructure-as-a-service, or software-as-a-service, learning the key differences between these

But to consider whether a payment orchestration platform is the right fit for a merchant’s payment strategy, a business needs to define and understand its return on investment (ROI) and the various use cases of payment orchestration.

Each business is unique and has its own “wow” or “ah ha!” moment that cannot be captured in mass market research or anecdotally exploring the wide range of benefits payment orchestration can bring. 

By implementing payment orchestration, businesses are empowered to strategically manage their business payment systems, employing software and services to streamline and optimize their payment process while securing ROI. This approach can significantly enhance the efficiency and effectiveness of an organization’s payment operations.

Here are some key benefits of payment orchestration:

  • Increased Conversion Rates: By offering multiple payment methods and gateways, payment orchestration ensures that customers have their preferred payment options available, which can reduce cart abandonment and increase conversion rates.
  • Reduced Payment Failures: A payment orchestration platform can intelligently route transactions through different PSPs to minimize the likelihood of payment failures.
  • Enhanced Customer Experience: It offers a seamless payment experience to customers, regardless of where they are or which payment method they use, resulting in higher customer satisfaction and retention.
  • Fraud Prevention: Advanced payment orchestration platforms integrate with third-party anti-fraud providers, which can reduce the risk of fraudulent transactions and chargebacks. 
  • Cost Optimization: It allows businesses to dynamically select the most cost-effective payment providers and payment methods for each transaction, potentially lowering transaction fees and operational costs.
  • Improved Authorization Rates: Payment orchestration can increase the probability that a transaction will be approved by selecting the best-performing payment service provider for each transaction type or region.
  • Global Expansion Support: For businesses looking to expand internationally, payment orchestration simplifies the process of accepting payments in different currencies through various local payment methods.
  • Data Insights and Analytics: It provides valuable insights into payment data, which can be used to make informed decisions about payment strategy and identify improvement areas.
  • Streamlined Operations: By centralizing payment processes, businesses can simplify reconciliation, reporting, and compliance with financial regulations. 
  • Adaptability and Scalability: Payment orchestration platforms can adapt to the changing needs of a business, allowing for easy scaling as transaction volumes grow or as new payment methods and technologies emerge.
  • Reduced Dependency: Using a payment orchestration platform reduces a business’s dependency on any single payment provider, mitigating risks associated with provider outages or service disruptions.
  • Efficient Payment Processing: Orchestrating payments can lead to more efficient payment processing, as it enables businesses to manage and automate workflows, reducing manual intervention and errors.

Overall, payment orchestration is about creating a flexible, efficient, and user-friendly payment ecosystem that can grow with your business and adapt to the evolving landscape of digital transactions.
Do you also want to find out how much you could stand to gain financially by partnering with Gr4vy? Check out our comprehensive ROI calculator for payment orchestration and enter your business payment information for your unique result. To explore the ROI in more detail, download our ROI eGuide. Alternatively, get in touch with our team to book a demo.

Why should businesses pay attention to edge computing?

With the increase in data breaches, it’s not just consumer confidence that is being affected. Governments are also beginning to take notice, and impose stricter regulations on how, where and when companies can store customer data. As cross border commerce continues to grow, merchants looking to take advantage of that growth to scale globally should be future-proofing their infrastructure with edge computing.

What is edge computing?

Edge computing is a distributed IT architecture in which data is processed as close to the originating source as possible. Traditionally, data was stored in a central data center, but with the sheer amount of data existing in today’s world, this gives way to latency issues, bandwidth limitations, disruptions to the network, and cybersecurity concerns. 

Now, with edge computing, a portion of the storage, resources and processes are moved out of the central data center, and moved closer to the source of the data itself so that the work is performed where the data is generated. In payment terms, this would mean card data is processed locally at “the edge” and then sent back to the main data center. 

As Stephen Bigelow, a journalist at TechTarget, defines it, “the principle is straightforward: If you can’t get the data closer to the data center, get the data center closer to the data.”

Why should leaders pay attention to edge computing?

According to McKinsey and Co., data regulation is taking center stage around the world – over 60 countries reported data protection localization requirements in 2021, meaning edge computing might soon become an operational necessity for many organizations. 

It is projected that spending on edge computing in 2025 will reach around $250 billion, and that 26% of servers shipped in 2024 will be deployed at the edge – an increase from 20% in 2019. In fact, Gartner predicted that by 2025, 75% of of enterprise-generated data will be created outside of centralized data centers

For businesses, the constantly changing regulations around data handling and localization can be a huge headache. As enforcement continues to get tighter, fines or repercussions for noncompliance can be substantial. One of the key stories emerging in recent years is the Reserve Bank of India barring Mastercard from issuing new debit or credit cards to India’s population for violating a rule that card networks must store Indian payment data solely in India. 

Find out more about Reserve Bank of India’s tokenization regulation and what it means for merchants

Outside of regulation, consumers are increasingly concerned about how their data is used, stored, and transmitted. Digital trust has become more of a focus point for consumers, with many looking for trusted partners or logos to put them more at ease. 

What are the benefits of edge computing?

Two of the key benefits of edge computing are in data sovereignty and edge security. Moving data across national and regional boundaries can pose a range of issues including security, privacy, technological, and other legal issues. Edge computing allows raw data to be processed locally, and have any sensitive data elements obscured, secured, and/or tokenized before sending anything to the primary data center, which may be in another jurisdiction. 

Secondly, edge computing allows an additional layer of data security. In addition to the tokenization mentioned above, edge deployment can be hardened against malicious activities, so that any data that is being sent back to the cloud or data center is secured through encryption. 

According to McKinsey & Co., companies that address issues around data privacy and localization, can have a competitive advantage in a few key areas:

  • Optimized customer experience – being able to offer customers a more personalized experience with a brand no matter where they are in the world
  • Lower compliance costs – being able to move efficiently between geographies and avoiding getting tied up with regulatory issues and the red tape internally to meet these
  • Positioning and reputational advantage – boost customer acquisition and retention by positioning a brand as the guardian of customer data and digital identity

The advantage of edge computing in payment orchestration

Payment orchestration platforms can help merchants overcome the complexities of payments – from deploying and managing multiple payment methods, through to adherence of local data and privacy regulations. Payment orchestration providers can work in conjunction with edge computing to provide payment solutions that have customer data stored locally, and therefore compliant with local privacy and data laws, while also able to be easily used across multiple continents and countries, as well as being standardised across the world.

An infrastructure-first solution built natively in the cloud gives merchants the tools and features they need built into their own individualized cloud instances that they can quickly spin out as an ‘edge’ to new locations, adding new and localized payment services through a single universal API. 

It also enables merchants to enter new markets by creating edge Instances within a chosen country or region, keeping transactions and data secure within a local, unique edge that is compliant with local sales and privacy regulations. Unlike the shared tenancy SaaS platforms offer, an IaaS provider offers a single-tenant cloud infrastructure which reduces points of failure to ensure a merchant never loses a transaction. 

Merchants will not share infrastructure or server loads with other merchants meaning there is no risk of slowdown or interference from other merchants, as well as the ability to create bespoke deployments to improve regional storage. IaaS is not a ‘one deployment fits all’ solution – merchants have their own private payment infrastructure customized to meet their individual needs.

To find out more about how Gr4vy, a cloud-native IaaS payment orchestration platform trusted by companies globally, can help you reduce and simplify your regulation and compliance burden, and offer you security with unrivalled flexibility for all of your payments, get in touch with our team.

IaaS vs. SaaS: A merchant’s guide to payment orchestration platforms

Payment orchestration platforms have been developed to assist merchants with improving the checkout experience at both the front- and backend, and relieve the burden for merchants to deploy and manage multiple payment methods and providers. But with so many on the market, what is the difference between an IaaS vs. SaaS payment orchestration provider, and why should merchants care? 

What is payment orchestration?

With payment orchestration, merchants can cater to ever-evolving customer payment preferences and stay compliant to a range of data and regulatory requirements in local markets without eating into engineering and technology resources. 

For merchants without a POP, relying on a single payment provider or juggling multiple providers that are not integrated with each other can be an easily avoided headache. An orchestration layer – whether it is outsourced or built in-house – optimizes payment processing at each stage of the payment flow for online transactions, minimizing the number of failed transactions due to technical issues and allowing merchants to save costs.

Should payment orchestration be built in-house or outsourced?

For merchants that don’t want to invest the money, time, and technical resources into building an orchestration layer in-house, there is an option to outsource to one of a number of payment orchestration platforms (POPs) on the market. However, merchants must consider their needs and whether that fits a platform built as Software-as-a-Service (SaaS) or Infrastructure-as-a-Service (IaaS). 

What are the pros and cons of a SaaS payment orchestration platform?

SaaS platforms are widely available, and have a number of benefits depending on the size of the merchant. For start-ups and small businesses, SaaS platforms take the burden of managing and upgrading software completely off their hands – a major advantage for small teams with limited resources. Due to its delivery model, SaaS platforms manage all potential technical issues, such as data, middleware, servers, and storage, resulting in streamlined support and maintenance for the business. 

However, with SaaS platforms, merchants have no control over the cloud-based infrastructure it runs on, and if the provider experiences an outage, all merchants using it will experience an outage. If a merchant is processing a high volume of transactions using the shared bandwidth on that platform, all merchants will experience a slow-down. In addition, SaaS tools may be incompatible with other tools and hardware already in use, and integrations are normally up to the provider, so it limits an internal team’s ability to make adjustments to integrations on their end.

Perhaps more importantly, merchants are at the mercy of the SaaS organization’s security measures and data leaks can lead to a huge distrust in a brand. By 2025, cybercrime is estimated to cost $10.5 trillion globally, increasing by 15% year-on-year, and reports suggest that the average company with data in the cloud using SaaS platforms represents $28 million in data breach risk

Last year, major global SaaS-based companies such as MailChimp, Okta, Microsoft, and Hubspot have experienced data breaches that have hugely impacted their business customers and end-consumers who have been caught up in the mess. 

  • The average total cost of a ransomware breach is $4.62 million, slightly higher than the average data breach of $4.24 million
  • The average time to contain a breach was 80 days
  • By 2025, cybercrime is estimated to cost $10.5 trillion globally, increasing by 15% year-on-year

What is the alternative to a SaaS payment orchestration platform?

For large merchants who are scaling quickly and globally, and want control over their data and systems, IaaS platforms could be a better option. An infrastructure-first solution built natively in the cloud gives merchants the tools and features they need built into their own individualized cloud instances that they can quickly spin out as an ‘Edge’ to new locations, adding new and localized payment services through a single Universal API. 

Edge computing provides flexibility for organizations to achieve greater data sovereignty, greater autonomy, better security, and solve latency issues. A cloud-native POP enables merchants to enter new markets by creating Edge Instances within a chosen country or region, keeping transactions and data secure within a local, unique Edge that is compliant with local sales and privacy regulations. 

Unlike the shared tenancy SaaS platforms offer, an IaaS provider offers a single-tenant cloud infrastructure which reduces points of failure to ensure a merchant never loses a transaction. Merchants will not share infrastructure or server loads with other merchants meaning there is no risk of slowdown or interference from other merchants, as well as the ability to create bespoke deployments to improve regional storage. IaaS is not a ‘one deployment fits all’ solution – merchants have their own private payment infrastructure customized to meet their individual needs. 

Additionally, IaaS platforms do not have a single point of failure. While SaaS payment orchestration platforms (POP) may claim that having multiple payment service providers (PSPs), such as Stripe or PayPal, on the platform removes the risk of being a single point of failure, if the SaaS POP itself goes down, every single merchant loses access to payments, potentially resulting in a significant loss of revenue depending on recovery time. IaaS platforms, on the other hand, have a hugely reduced risk of downtime because it’s unlikely any of the large cloud service providers, such as AWS and Google Cloud, will go down in multiple geographies at the same time. 

Looking forward, regulations and standards such as PCI 4.0 will have a heavier focus on security in the cloud, and large merchants that are relying on a SaaS platform may fall foul of the breaches mentioned above because they aren’t retaining ownership of their data, and are bound to the platform provider’s standards. 

Interested in learning more about payment orchestration? Download our eGuide, ‘IaaS vs. SaaS: An e-commerce merchant’s guide to payment orchestration’, to discover which platform is best for your needs. 

If you’re ready to explore how an IaaS payment orchestration can support your payment strategy and future-proof your checkout, get in touch with our team for a full consultation with one of our experts. 

Supercharging sustainability for businesses with cloud computing

Around the world there is increased focus and scrutiny on the impact businesses and consumers are having on the environment. With sustainability and “going green(er)” as a hot topic across private and public sectors in almost every industry, cloud computing could be the key for supercharging sustainability for businesses. From reducing total cost of ownership (TCO) to reducing overall carbon footprint through cloud infrastructure, as well as longer term benefits such as security and innovation, the benefits of cloud computing are well-documented. 

Corporate social responsibility (CSR), a business model that aims for a company’s activities to enhance the world around them, has existed for a long time, but in recent years, more and more businesses – particularly technology companies or those driving digital transformation – have been seeking to do more activities that address climate change from a digital perspective. 

Why should businesses care about environmental impact?

While attitudes and levels of passion towards fighting climate change vary consumer-to-consumer, Deloitte research has shown that as consumers become more engaged with sustainability and environmental issues, they expect the same of business. According to the consulting giant, 65% of respondents expect CEOs to do more to make progress on societal issues – including making business supply chains more sustainable. Additionally, it found 42% of consumers have changed consumption habits because of a company’s stance on the environment, and younger consumers (ages 18 to 24 years old) are three times more likely to switch brands based on values than those 65 years old and above.  

In another study, Deloitte research has found that since 2020, 40% of consumers have chosen brands that have environmentally sustainable practices and values, and 35% of consumers say that having a transparent, accountable, and socially and environmentally responsible supply chain influences how much they trust a business. 

Consumer attitudes aside, companies should note that G7 finance ministers are committed to mandate climate reporting in line with the recommendations of the task force on Climate-related Financial Disclosures (TCFD). While a universal standard does not yet exist, environmental, social and governance reporting (also known as ESG reporting) does exist in the form of regional reporting frameworks, voluntary standards, and national legislation that vary significantly. 

As a result, the above has led investors in recent years to become more aware of the importance of ESG criteria in their investment decisions; which has then led many businesses to start integrating ESG into their operations and business strategies.

How can cloud computing lower carbon emissions and help companies go greener?

An IDC (International Data Corporation) forecast showed that the continued adoption of cloud computing could prevent the emission of more than 1 billion metric tons of carbon dioxide (CO2) by 2024 if datacenters continued to follow sustainable practices. 

The cloud has become the default solution for businesses looking to cut costs while enabling scalability, security, and flexibility of their operations. It can help companies to reduce the overall amount of energy needed for data storage, and cut their carbon footprint. 

Numerous independent studies have demonstrated the cost savings that organizations can achieve by migrating to the cloud. For instance, an IDC study estimated that AWS customers have a 51% lower cost of operations compared to running on premises infrastructure.

According to Gartner’s research, 95% of companies will be using the cloud by 2025, and according to industry figures, companies can save 15-40% on infrastructure costs by migrating to the cloud, with the top three reasons for doing so as: reducing IT costs, increasing agility and flexibility, and improving disaster recovery. 

So, how does cloud computing represent an environmentally friendly option for supercharging sustainability for businesses? 

  • Energy efficiency – cloud service providers invest heavily in data center infrastructure and technology to maximize energy efficiency. They use advanced cooling systems, energy-efficient hardware, and optimized datacenter layouts to reduce energy consumption. This results in lower carbon emissions compared to traditional on-premises datacenters. Additionally, some cloud service providers, such as Google Cloud, match their energy consumption with 100% renewable energy (not just carbon credits, but real power), driven by investments in wind and solar projects
  • Server virtualization – cloud providers employ server virtualization techniques, allowing multiple virtual servers to run on a single physical server. This consolidation reduces the overall number of servers needed, leading to lower power consumption and reduced electronic waste
  • Scalability – cloud services are designed to scale resources up or down based on demand. This elasticity enables efficient resource utilization. When workloads are light, fewer servers are active, saving energy. Conversely, during peak demand, additional resources can be provisioned temporarily
  • Location optimization – cloud providers often have data centers strategically located to take advantage of renewable energy sources. They may choose areas with abundant access to wind, solar, or hydroelectric power, allowing them to utilize cleaner energy for their operations
  • Reduced hardware manufacturing – cloud computing reduces the need for individuals and organizations to purchase and maintain their own hardware. This results in fewer electronic devices being manufactured, reducing the environmental impact associated with resource extraction and manufacturing processes
  • Data Center PUE (Power Usage Effectiveness) – cloud providers focus on improving the PUE of their data centers. PUE measures the ratio of total energy used by a data center to the energy consumed by IT equipment. Lower PUE values indicate greater energy efficiency
  • Server utilization – cloud providers optimize server utilization rates, ensuring that servers are used efficiently. This minimizes the “zombie server” problem, where underutilized servers continue to run, consuming energy unnecessarily
  • Energy-saving features – cloud services often provide energy-saving features like automatic server power management, load balancing, and dynamic resource allocation to reduce power consumption during periods of low demand
  • Reduced commute and travel – cloud computing enables remote work and collaboration, reducing the need for employees to commute to physical offices. This cuts down on transportation-related carbon emissions

While cloud computing offers many environmental benefits, it’s essential to note that its overall impact can vary depending on factors such as the energy mix used by the cloud provider, the efficiency of datacenter operations, and the sustainability practices they employ. Therefore, organizations should carefully consider the environmental credentials of their chosen cloud providers and actively manage their cloud resources to minimize their carbon footprint.

Making payments greener in the cloud

Although payments do not represent a core activity for most companies, they are a key business function, and an area that should not be overlooked when it comes to its sustainability and environmental impact. According to the 12th UN Global Compact-Accenture CEO Study — the world’s largest research initiative on sustainable leadership — an overwhelming 98% of executives now agree that sustainability is core to their role.

So, for businesses looking to make their payment options greener than a US dollar bill, what are the current payment options out there being used by consumers, and how are they impacting the environment? 

  • Digital wallets and mobile payment apps – Apple Pay, Google Pay, and Samsung Pay: These digital wallet services encourage paperless transactions and reduce the need for physical payment cards
  • Green banks and credit unions – look for banks and credit unions that have committed to sustainability initiatives, such as investing in renewable energy projects, reducing their own carbon emissions, and supporting eco-friendly initiatives in their communities
  • Online payment platforms – PayPal has set sustainability goals and is actively working to reduce its environmental impact through initiatives like renewable energy sourcing and responsible datacenter practices
  • Cryptocurrency – although largely leaving a heavy carbon footprint in the payments world, some cryptocurrencies, such as Ethereum, are exploring energy-efficient consensus mechanisms (e.g. Ethereum’s transition to proof of stake) to reduce their energy consumption
  • Green credit cards – some credit card companies offer cards that donate a portion of a consumer’s spending to environmental causes or provide rewards for eco-friendly purchases
  • Carbon offsetting options – some payment providers allow users to contribute to carbon offset projects when making transactions. This can help counterbalance the carbon footprint of a consumer’s purchases
  • Local and ethical banking options – consider local banks and credit unions that prioritize community and environmental concerns. They often have a more vested interest in supporting sustainable local initiatives
  • Eco-friendly e-commerce platforms – when setting up online stores or choosing payment providers for e-commerce, opt for platforms that are committed to sustainable practices in their operations, datacenters, and supply chains
  • Open banking and APIs – explore open banking platforms and APIs that allow for more transparency and control over your financial data, enabling you to make eco-conscious choices in your financial transactions
  • Donation-based payment providers – platforms like JustGiving allow users to make payments that directly support charitable and environmental causes, businesses can even now leverage their PSP to support any certified charity, and combine this in the same flow of funds to reduce costs and produce digital documents needed for filing taxes
  • Peer-to-Peer (P2P) payment apps – P2P payment apps like Venmo and Cash App can be used for splitting costs related to shared eco-friendly activities, such as carpooling or buying sustainable products

When evaluating payment options and providers for their environmental impact, consider factors such as the company’s commitment to sustainability, transparency in reporting their environmental efforts, and any specific initiatives they have in place to reduce their carbon footprint. Additionally, individual choices, such as opting for paperless statements and receipts, can further enhance the environmental friendliness of your payment practices.

Businesses operating in multiple geographies, with multiple currencies, multiple preferred payment methods, and with multiple regulatory and compliance requirements, are more than likely looking at adopting payment orchestration to enable them to scale at speed without technical debt. 

As part of a business’ RFI process, they should be looking at the sustainability of each player in the supply chain – including payments. For example, Gr4vy is currently the only cloud-native payment orchestration platform and runs on cloud providers such as Google Cloud. In this specific case, Google has made the goal to power all of Alphabet, from datacenters to storage, offices, and other facilities with carbon-free energy by 2030, meaning any company that partners with a Google Cloud-run platform can immediately transform its IT carbon footprint on integration. 

Interested in learning more about payment orchestration and the power of the cloud? Download our eGuide, ‘IaaS vs. SaaS: An e-commerce merchant’s guide to payment orchestration’, to discover which platform is best for your needs – including building a payment orchestration layer in-house.

Gr4vy, trusted by Woolworths Group, Setplex, Mythical Games, Ding, and more, is a powerful payments platform that allows you to deploy, manage, customize and optimize all your payments through one simple, universal integration. With a unique single-tenant, cloud-based infrastructure, Gr4vy makes scaling your business faster than ever. 

Gr4vy is the only cloud-native and 100% payment service provider agnostic payment orchestration platform. Gr4vy gives every merchant full control over the bespoke resilience, redundancy, and performance expected from a cloud service that integrates into their payment stack. To find out more about Gr4vy, get in touch with our team, or explore our platform.

Untangling the payments ‘spaghetti systems’ in retail M&A with payment orchestration 

The retail landscape is one that evolves on an almost daily basis as new brands are launched and established brands work to stay innovative, remain competitive, and keep a hold of their market share. A key element of ongoing evolution is through mergers and acquisitions (M&A), leaving stakeholders with an unsavory challenge on the menu – untangling the payments ‘spaghetti systems’ in retail M&A. 

Nearly every week, there is news of an acquisition within retail – whether it’s to expand a brand’s global footprint, add to a brand’s product range, bail out a struggling merchant that still has potential, or a strategic move to stamp out competition. 

Consulting behemoth, Bain & Co., this year published a report stating that it expects major retail players to “draw on record levels of cash amassed during the COVID-19 pandemic and take advantage of decades-low multiples” to pursue more M&A deals in 2023. Already this year, we’ve seen multiple household names announcing acquisitions across the world in various industries. This follows a busy period in late 2022 where we saw fast-growth companies like Gorillas, a groceries delivery startup, get snapped up by its competitor, Getir, in a deal that valued the new entity at roughly $10bn. 

The technology challenges of retail M&A for stakeholders

Of course, M&A is not without its challenges. Stakeholders are faced with the sometimes difficult task of aligning multiple company cultures and any necessary cutbacks or changes that must be made. On the back-end, they are faced with an entirely different set of challenges depending on the age and set-up of the company being acquired. 

This is further complicated when dealing with large parent companies acquiring multiple brands with multiple platforms powering them. In banking, this is often dubbed as ‘spaghetti systems’ whereby multiple M&As have led to numerous software environments that have been cobbled together over the years under one parent bank. On top of general business operations software, adding payments into the recipe can open up a whole new can of worms (or spaghetti…) for the parent company. 

While relatively small companies and start-ups can be an easier acquisition process from a technology perspective, the more established brands will have existing relationships and contracts with their chosen payment service providers (PSPs) and commerce platforms that can be tricky to unify. 

Take clothing giant Boohoo Group, for example, which over the past 5-6 years, has acquired multi-million dollar revenue-generating brands such as Debenhams, Pretty Little Thing, Miss Pap, and Dorothy Perkins, among others. Each of those companies will have been operating for years with its own chosen set of payment and risk providers, which Boohoo Group will then have to manage until each contract has been terminated. A problem the group will face with each new acquisition it makes. 

So, how can payment orchestration help brands unify on the payments front and untangle the ‘spaghetti systems’ post-acquisition? 

Data portability and tokenization – avoiding vendor lock-in

The security and management of sensitive card data remains a top priority for both businesses and consumers in the face of increasing incidents of data breaches and cyber-attacks. Each business should have implemented robust security measures to protect card data – typically through tokenization – but this often results in vendor lock-in with a merchant’s primary payment service provider (PSP). 

Storing card data with a PSP can severely limit the data portability of card data for a retailer, which is more of a significant headache during an M&A process, where a parent company now has multiple streams of PSP-tokenized card data that cannot be transferred from one service provider to another without any loss of functionality or security. This means the brands cannot easily switch between different PSPs without having to worry about the migration of sensitive card data which limits flexibility and means the parent company has less agility and control when it comes to its payment stack, workflows, and entire tokenization strategy. 

However, all is not lost. A number of payment orchestration providers can also give merchants access to an external vault. An external vault generates tokens that belong to the retailer and can be taken anywhere, anytime. These tokens can also be used in a vault provider’s system or externally with a service provider to ensure that portability and ownership coexist for optimal agility.

Keeping card data within an independent cloud vault also allows retailers to instantly process card data with any PSP without migration issues, as a cloud vault securely stores card data and helps guarantee PCI compliance. Retailers can also use this data to process payments with any PSP, routing card data on demand to a preferred processor based on cost, preference, location and a multitude of other factors.

For merchants that might not be ready for a full payment orchestration strategy, an external network tokenization vault is still an option for most businesses so they can take advantage of data portability in the meantime. 

To read more about PSP tokenization vs. network tokenization, the importance of data portability, and how to access a standalone Vault offering, check out this article

Deploy and test different payment methods immediately with a singular low-code integration 

As mentioned, businesses going through M&A already have a significant number of challenges and unpicking to do, and may be tempted to not touch any systems for a while out of fear that tugging on one piece of spaghetti might bring the entire thing to pieces. However, payment orchestration does not mean businesses have to pull the proverbial shutters down to make mass updates and changes. 

Historically, if merchants want to deploy new payment methods or providers, they have to dedicate an entire team of payment engineers to code and test each change. This process might be complicated if each brand in the M&A process runs on different systems and platforms that might be unfamiliar to the existing teams, and even further complicated if a global aspect comes into play and the parent company is acquiring brands that have custom in various geographies with separate payment methods and local regulations. 

Payment orchestration is a modern-day equivalent to this that avoids the headache of technical debt and hiring huge teams of engineers. Payment orchestration is a layer that sits between a merchant and its partners in the payments ecosystem. It exists to help merchants to streamline, manage, and expand their partnerships with multiple gateways, processors, payment service providers, fraud/risk providers, and much more.

Merchants connect to a payment orchestration platform normally through an API integration, and, once connected, they have access to unlimited payment providers, payment methods, and anti-fraud providers worldwide. In some cases, merchants can leverage their existing e-commerce platform plugins, significantly simplifying the integration process.

By using a payment orchestration to access multiple payment providers, through one singular no/low-code integration, merchants can:

  • Set up automatic failover and retries on the back-end so that if one PSP cannot process a transaction, another PSP automatically kicks in and the merchant does not lose the sale
  • Avoid vendor lock-in with a centralized PCI DSS Level 1 certified vault, allowing merchants to securely collect and store card data and tokenize transactions while seamlessly migrating all data across multiple PSPs
  • Get advanced visibility by using insights across all payment providers within the merchant’s orchestration ecosystem, so merchants can set up routing rules for the most efficient pricing
  • Work with even more payment methods across the world – one integration with a payment orchestration platform will give you access to the payments ecosystem across multiple countries, with the ability to build more bespoke offerings if and when a merchant needs them
  • Simplify payments management and reporting, consolidating all your payment reporting in one single place

To find out more about payment orchestration 101 and some of the frequently asked questions, check out this article breaking it down for merchants

Avoid having a single point-of-failure in your payments stack

As businesses going through mergers and acquisition seek to unify the experience on the front- and back-end, it’s important that there are no hiccups in the payment process that might negatively impact consumers – or indeed, revenue for the company and its brands. 

One key element all merchants should consider when auditing their payments stack – whether they’re sticking to PSP-only or moving towards a payment orchestration layer with either a platform partner or built in-house, is whether they will run into a single point-of-failure. 

While SaaS payment orchestration platforms (POP) may claim that having multiple payment service providers (PSPs) on the platform removes the risk of being a single point of failure, if the SaaS POP itself goes down, every single merchant loses access to payments, potentially resulting in a significant loss of revenue.

IaaS platforms, on the other hand, do not have a single point-of-failure. IaaS platforms have a highly reduced risk of downtime because it’s very unlikely any of the large cloud service providers, such as AWS and Google Cloud, will go down in multiple geographies at the same time. In fact, during the 2022 summer heatwave in the UK, Google Cloud experienced a local outage, and Gr4vy, an IaaS payment orchestration platform, was able to immediately move all merchants over to another region while remaining compliant with local data regulations, ensuring merchants did not lose a single transaction.

Interested in learning more about IaaS vs. SaaS in payment orchestration? Download our eGuide, ‘IaaS vs. SaaS: An e-commerce merchant’s guide to payment orchestration’, to discover which platform is best for your needs – including building a payment orchestration layer in-house

If you’re ready to get started, book a call with one of our payment experts to receive a bespoke consultation and find out why Gr4vy is trusted by Woolworths Group, Setplex, Mythical Games, Ding, and more. 

With a unique single-tenant, cloud-based infrastructure, Gr4vy makes scaling your business faster than ever through a powerful payments platform that allows you to deploy, manage, customize, and optimize your payments through one simple, universal integration. 

Built natively in the cloud, Gr4vy gives every merchant full control over the bespoke resilience, redundancy, and performance expected from a cloud service that integrates into their payment stack. To find out more about Gr4vy, get in touch with our team, or explore our platform

Is there a better alternative to PSP tokenization for merchants?

With data breaches abound and PSP (payment service provider) restrictions existing, how can retailers prioritize tokenization and data portability to create a cohesive checkout and payment experience, and what is the alternative to PSP tokenization?

A frictionless checkout experience and a need for data security and portability are crucial concerns for retailers and consumers alike. On one side, consumers demand payment optionality at checkout, while on the other, retailers strive to meet that challenge by utilizing various payment service providers (PSPs) and payment methods. It’s no wonder then that at the heart of tokenization and data portability, payments play a pivotal role, as the total volume of tokenized payment transactions will surpass 1 trillion by 2026.

Not all tokenization approaches are created equal

Tokenization isn’t new, but today’s retailers stand to benefit from the technology, as losses from online payment fraud will exceed $362 billion globally over the next five years. Why? Tokenization allows retailers to forego the traditional route of storing sensitive card details and replace that data with tokens that enhance security and portability.

These digital identifiers replace card data during transactions, ensuring bad actors cannot access and use the information. The tokens can also securely pass through multiple systems without worry as information is locked down.

Retailers that leverage network tokens also stand to benefit from increased authorization rates. In 2020, Visa’s Token Services showed an uplift of 3.2 percent in authorization rates. It’s important to note, however, that not all tokenization approaches are equal when it comes to tokens and data portability.

One of the main things retailers must consider with data portability is the restrictions that can come with growth. Retailers that tokenize card data with PSPs will find that card data is replaced with PSP-specific tokens sent on every request rather than relying on original card data.

Storing card data with a single PSP can severely limit data portability for retailers. So, what is the alternative to PSP tokenization? Instead, retailers should utilize network tokenization, which extends on the idea of PSP tokens by allowing retailers to send card data to a network tokenization service to determine what scheme to connect with to issue a network token.

More importantly, retailers that take advantage of network tokens can quickly switch between different PSPs without worrying about migrating sensitive card data, which is vital for maintaining flexibility during changing market conditions.

How to take action

Retailers that want to capitalize on data portability need to consider who owns the token — the retailer or the PSP. For retailers that want maximum flexibility, an external vault is necessary for tokenization. An external vault generates tokens that belong to the retailer and can be taken anywhere, anytime. These tokens can also be used in a vault provider’s system or externally with a service provider to ensure that portability and ownership coexist for optimal agility.

Keeping card data within an independent cloud vault also allows retailers to instantly process card data with any PSP without migration issues, as a cloud vault securely stores card data and helps guarantee PCI compliance. Retailers can also use this data to process payments with any PSP, routing card data on demand to a preferred processor based on cost, preference, location and a multitude of other factors.

While understanding what goes on behind the customer checkout process isn’t always easy, retailers that implement a comprehensive tokenization and data portability strategy will be able to decrease security threats while delivering a checkout experience that keeps customers coming back to buy.

Gr4vy’s Cloud Vault – tokenization for merchants

As an alternative to PSP tokenization, Gr4vy’s vault-as-a-service makes it easy to store, pull, update and distribute card data while minimizing the PCI compliance process. Merchants can easily store original raw card data, billing and shipping details and link them to a vaulted card. Token management is made effortless as merchants can provision network tokens and their cryptograms, provision PSP tokens and distribute card data for third-party processing. The centralized cloud vault supports regional data deployment, keeping merchants compliant and ahead of local data regulations. 

Data portability concerns also become a thing of the past with Gr4vy’s subscription cloud vault services. Merchants can quickly import existing card data and PSP tokens from any PSP into Gr4vy’s vault. They can export data as a PSP token, Network Token, Card Push, or export it into a new service. Additionally, data stored in the cloud vault belongs to the merchant, removing vendor lock-in for maximum portability and flexibility. Discover more information on the level of service and plans Gr4vy offers or sign up here.

This article first appeared on Total Retail

Gr4vy wins ‘Best Fintech Cloud Payments Solutions Company’

Gr4vy’s cloud-native payment orchestration platform has been awarded ‘Best Fintech Cloud Payments Solutions Company‘ at this year’s Fintech Awards, by Wealth and Finance International. Now in its sixth year, the awards recognize leadership and innovation in the fintech industry worldwide.

Gr4vy was selected for its benefits and features that make its platform unique. Gr4vy’s infrastructure takes the complexity out of building and managing payment ecosystems, allowing merchants to customize and optimize all their payments through one simple, universal integration.

Gr4vy’s IaaS platform offers merchants future-proofed payment infrastructure designed to grow with their business so they never lose a transaction. With Gr4vy’s IaaS platform, merchants get cloud architecture, single tenancy (no commingling of data), data localization (can spin up an instance or edge instance anywhere in the world), reduced latency and failover redundancy.

  • Payment orchestration: Gr4vy offers each customer a personalized payment method at checkout and ensures each payment is routed to its optimal service provider every time. With Gr4vy, merchants can control every part of a transaction lifecycle to help reduce fraud and chargebacks, optimize processing fees, and more. Gr4vy supports 100+ unique payment methods and is constantly adding new connections to its portfolio. 
  • Customized workflows: Gr4vy’s No-code Workflow Engine allows merchants to build workflows that optimize transaction routing based on country, currency and time of day and create workflows to reroute transactions due to downtime. Merchants can also design workflows to offer specific payment methods based on the day of the week, time of day, or location, and Gr4vy will automatically reflect these inputs in the checkout experience.
  • Vaulting & tokenization: Gr4vy’s centralized vault gives merchants the freedom to move around and work with multiple payment providers while allowing them to securely and intelligently collect and store card data, simplifying the burden of PCI DSS compliance. Gr4vy supports tokenization and storage of all recurrent APMs. Gr4vy’s network tokenization solution centralizes the storage of network tokens allowing merchants to use them interoperably between PSPs. With the Gr4vy Vault, they can enable one-click checkout experiences, collect and store card data and use network tokens to tokenize transactions.
  • A white-label solution: Gr4vy offers architecture that enables third parties to provide orchestration to their clients invisibly. As a result, merchants gain payment infrastructure and orchestration through Gr4y’s platform to manage all their payment needs.

To find out more about Gr4vy’s cloud-native IaaS payment orchestration platform, check out our guide to payment orchestration, or explore the platform. If you’re looking to integrate with an award-winning payment orchestration platform trusted by brands across the world, get in touch with the Gr4vy team.

Reserve Bank of India’s tokenization regulation explained

The Reserve Bank of India (RBI), India’s central bank and regulatory body, last year announced a ruling for the handling of consumer card data and recurring payments that explicitly states transactional data must not leave the country and must reside in local storage within India. These regulations are aimed at ensuring the security, confidentiality, and integrity of financial transactions, as well as promoting transparency and consumer protection but creates a complex problem for companies looking to expand into India. So, what does Reserve Bank of India’s tokenization regulation mean for merchants operating in or expanding to the Indian market, and how can they remain compliant while reaping the rewards of a fast-growth digital commerce market?

Reserve Bank of India’s tokenization regulation

What is the Reserve Bank of India’s tokenization regulation and why was it implemented?

The Indian e-commerce market is expected to grow to $111.40 billion USD by 2025, and $350 billion USD by 2030. In 2019, the government announced ‘Digital India’ with the aim to transform the country into a digitally empowered society, and encourage more businesses and consumers to embrace digital technologies. This transformation was only accelerated by the COVID-19 pandemic, and now, India is one of the largest and fastest-growing markets for digital commerce. 

However, with an increase in e-commerce, there has been an increase in data breaches. India has suffered a number of mass data breaches across a number of sectors in recent years. This included Know Your Customer (KYC) information as well as credit card and bank details of the nation’s consumers. Given the number of debit and credit card holders in India has been steadily increasing over the years, with almost 900 million active debit card holders and 64 million active credit card holders by the end of 2020, this leaves a large target for fraudsters. 

To try and combat the rise of cybersecurity woes, RBI announced in March 2020 that merchants and payment aggregators had 15 months to “purge” all card data that had been stored, add tokenization, and devise an alternative mechanism to handle recurring payments that would involve the storage of card-on-file (CoF) data by organizations other than card issuers and card networks. That deadline was then extended until 30th June 2022, after pressure from industry stakeholders. 

What does Reserve Bank of India’s tokenization regulation mean for merchants?

The new policy affects a number of key players, namely merchants, banks, and intermediary payment systems. Until banks, card networks, and payment gateways are live with consumer-ready solutions, merchants are stuck. And while a number of leading banks are ready, merchants, on the other hand, are not yet set-up at the backend for adoption, and customers who have stored their card details online through various platforms would be affected. 

Even with the deadline extension, merchants that are operating in or expanding their business to India have little time to deploy tokenization with only the resource of in-house development teams. Complex payment infrastructure requires dedicated in-house payment teams, incurring technical debt, inflexibility, and potential regulatory challenges. 

So, how can merchants act quickly?

Future-proof your payments by taking them to the cloud

Affected companies could become compliant by setting-up their own data centers, which would entail setting up both IT components and other non-IT components (including large servers). However, while companies’ own data centers provide complete ownership and control, deploying a new data center is expensive and time consuming as it entails numerous activities such as:

  • Finding the right location
  • Hiring several vendors
  • Deploying resources to build and maintain it
  • Certifications such as PCI DSS/ PA-DSS
  • Security audits as applicable
  • …and much more

Additionally, setting up such a data center can take several months and could end up becoming one of the largest projects a company undertakes. There are alternatives available to building and expanding one’s data center as merchants become compliant – including integrating scalable cloud-native payment infrastructure while eliminating the need to hire large payments teams.

To build scalable cloud-native payment infrastructure, merchants must add a layer that can orchestrate and standardize all the payment methods that consumers require in a way that utilizes the benefits of cloud computing without taking on the burden of PCI compliance. Server-less functions should remain dormant until a consumer needs that payment method. Unified reporting should be replicable and available wherever an accounting team sits – home or otherwise – and Edge computing should push user experiences closer to customers and their specific needs.

The advantage of being able to scale payment infrastructure up and down based on peaks and valleys in a merchant’s annual sales cycles is a huge benefit of a cloud-native payment orchestration platform. Moreover, it offers significant savings that can increase the bottom line.

‘Go Data-Centric’ and ‘Get Regulatory Compliant Privacy’ concerns have increased around the world. Data breaches continue to rise, leaving customers sceptical of how their data is held, with governments reacting in turn to protect their citizens. Several countries have blocks and set rules on what and where data can be kept on their citizens. 

In addition to RBI’s requirements, the industry has seen examples on a global scale, including European GDPR rules, and the fallout from the collapse of the Privacy Shield regulation which means that if a US Customer Service agent looks at customer data, then there is a breach of privacy even if that data is held locally. The problem is that most payment companies and solutions are not built to be distributed, and breaking a monolithic stack into parts is a challenging task for a payment processor and a merchant.

To become future-proof and ready to deal with the rapidly changing regulations, merchants need to start looking towards the benefits of Edge computing, which can keep data local while still allowing access to locally regulated payment companies and types.

How can edge computing and payments help merchants stay compliant? 

Edge computing is a distributed computing paradigm that brings computation and data storage closer to the edge of the network, and closer to where data is generated and consumed. By processing data locally – at or near the source – edge computing reduces latency, enhances real-time processing capabilities, and minimizes the need for data transmission to a centralized cloud infrastructure.

In the context of the payment industry and Reserve Bank of India’s tokenization regulation specifically, edge computing can have several potential applications, such as:

  • Localized compliance – In countries like India, where data sovereignty and compliance requirements are important considerations, edge computing can help ensure that payment data remains within the geographical boundaries of the country. This can aid in complying with local data protection regulations
  • Data security and privacy – Edge computing can enhance data security and privacy by keeping sensitive payment data within the local network or device. This can reduce the risk of data breaches and unauthorized access, as data doesn’t need to be transmitted to a remote cloud server for processing
  • Faster transaction processing – Edge computing can reduce latency in payment processing by performing certain computations locally. This can be particularly beneficial for real-time transaction verification, fraud detection, and authentication, enabling faster and more efficient payment experiences

Although now mandated by RBI for India specifically, merchants across the globe should be future-proofing their business and remaining compliant to PCI regulations by tokenizing customer payment details at the payment service provider (PSP) level, or even deeper at the association level.

Managing these tokens and keeping them up-to-date in a controllable manner can be a major headache for merchants, and a drain on development resources. It is essential to develop a strategy for keeping this updated, particularly with network tokens, as it can create cost savings if done correctly. To future-proof even further for global growth, merchants should be considering a strategy that is cloud-native and Edge-ready to stay locally compliant. 

Edge computing should push user experiences closer to customers and their specific needs such as this one in India. To become future-proof and ready to deal with the rapidly changing regulations, merchants need to start looking towards the benefits of Edge computing, which can keep data local while still allowing access to locally regulated payment companies and types.

The advantage of being able to scale your payment infrastructure up and down based on peaks and valleys in your annual sales cycles is a huge benefit of a cloud-native payment orchestration platform. Moreover, it offers significant savings that can increase your bottom line.

As payments move to the cloud, merchants mustn’t be afraid to modernize payment infrastructure, take on digital transformation and go global. Look to build or buy cloud native payment orchestration that takes advantage of the benefits of cloud technology, such as auto-scaling, Edge computing for local compliance, and cloud-based self-updating vaulting technology. With this foundation, you will be able to take on whatever the future holds.

With cloud-native Infrastructure-as-a-Service (IaaS) payment orchestration and optimization solutions like Gr4vy, merchants can utilize the benefits of cloud computing without taking on the burden of PCI compliance, and remain locally compliant while adding the orchestration layer to standardise all the payment methods that Indian consumers require. If you want to do business in India while remaining compliant, get in touch with our team today to see how Gr4vy can help.

The strategic CTO’s survival guide to budget planning 2024

The cheerful reality is that as a Chief Technology Officer (CTO), you can’t escape death, taxes and the annual budgeting season. For many businesses, 2023 has been a volatile year. Creeping inflation has caused consumers to be far more discretional with their non-essential spending, and with no signs of the economy easing in consumers’ eyes, 2024 will be high pressure for merchants to meet KPIs, focus on the business’ core activities, increase customer acquisition, and most importantly, retain existing customers. With budget preparation and deadline right around the corner, we’ve prepared a guide for next year’s budget considerations to prepare you for 2024. 

The importance of the budget cannot be overemphasised – its accuracy is critical to both the organization’s success and the success of the CTO as plans are set and opportunities are identified for the next 12 months. The CTO’s budget involves unique considerations that revolve around investments in technology and innovation, including payments, customer service, operational measures, ensuring compliance across multiple regions, maintenance of any infrastructure – and ensuring alignment with the organization’s strategic commercial initiatives. 

So, what are some of the areas the strategic CTO should consider to survive budgeting season? We broke it down into two categories – technological priorities for 2024, and some of the more general best practices for CTOs as budget planning season approaches. 

What should strategic CTOs be prioritising in the budget for 2024?

  • Focus on innovation and future-proofing – Allocate a portion of the budget to support research and development (R&D) initiatives and innovative projects that can provide a competitive advantage and future-proof the organisation. For example, you can future-proof your payments infrastructure by having dedicated cloud instances to support your business capacity, resilience, redundancy and performance requirements
  • Keep cybersecurity at the top of the agenda – Allocate sufficient resources to protect the organization’s data, systems, and intellectual property from cyber threats. Depending on your company’s size and needs, considering IaaS vendors over SaaS vendors will eliminate or minimize risks. For example, if you’re looking to optimize your payments in 2024, an IaaS payment orchestration provider can offer a regionalized approach to privacy and data regulation – allowing merchants to be compliant with GDPR, CCPA, Australian Privacy Law Standards, PCI DSS Level 1 and SOC2 Type 2 – through one integration, without being a single point of failure
  • Review legacy systems – Assess the cost and impact of maintaining legacy systems versus investing in modern technologies. In some cases, modernizing systems can lead to long-term cost savings and improved performance
  • Leverage cloud services – Consider leveraging cloud-based services and infrastructure to reduce upfront capital expenses, increase scalability, and improve cost efficiency
  • Implement vendor management – Outsourcing some of the non-core activities to your organization can help to reallocate internal teams to more value-added activities to the business. By outsourcing to expert third-parties, you can negotiate favourable contracts, consolidate spending, obtain better pricing – and spend more time on innovation
  • Consider total cost of ownership (TCO) – When evaluating technology investments, take into account any ongoing maintenance, support and upgrade expenses, and the actual cost of opportunity if you choose not to outsource those investments. For example, more and more merchants are considering implementing payment orchestration but is it better to buy or to build? How would building an MVP vs. outsourcing to a payment orchestration platform provider affect your business in terms of cost and other benefits?

To discover more about payment orchestration, how it can benefit your business, and how you can mitigate the risk of your payment orchestration provider becoming a single point of failure, check out our payment orchestration 101 breakdown.

What are the best practices for strategic CTOs for 2024 budget planning?

  • Align with business strategy – Understand the company’s priorities and how technology can support and drive those objectives by ensuring the technology budget aligns with the overall business strategy. This includes making the key distinction between what represents a core activity to the organization vs. what doesn’t – e.g. could business performance be improved with something as simple as offering more payment options to a consumer? Or perhaps you have an arduous back-end process for managing returns or subscriptions that is impacting the bottom line
  • Invest in talent – The success of technology initiatives relies on having a talented and motivated team working to drive the business’ core activity to reach its goal(s). Allocate funds for recruiting, training, and retaining skilled IT professionals to ensure high-quality maintenance of your current technology stack but also future-proof it for the years to come 
  • Adopt agile budgeting and continuously optimize costs – Embrace agile budgeting practices that allow for flexibility and adaptation to changing technology needs and/or market conditions. Regularly review technology expenses and identify areas where cost optimization might be possible – this could include eliminating redundant services, re-negotiating contracts, or adopting more efficient processes. CTOs must be able to respond quickly to emerging opportunities and challenges and develop contingency plans for any unexpected technology-related emergencies
  • Involve stakeholders and communicate budget decisions – Collaborate with other executives, department heads, and key stakeholders to understand their technology needs and priorities. Involving them in the budgeting process can help to foster buy-in and support for technology initiatives. Transparent and open communication builds trust and understanding among team members and other departments
  • Track Key Performance Indicators (KPIs) – Define and track technology-related KPIs that measure the effectiveness and efficiency of technology investments. Use these metrics to evaluate the success of projects and optimise spending

At the end of each budget cycle, conduct a thorough review of the budget’s performance and the outcomes of technology initiatives. Use the insights gained to refine future budgeting processes. By following these best practices, CTOs can develop budgets and strategically align technology investments with business goals, foster innovation, and deliver value to their organisations.

A CTO’s job satisfaction is around building more innovative solutions for a business. Take the pain out of managing and optimizing your payments for 2024 with Gr4vy’s cloud-native IaaS payment orchestration platform. With a payment orchestration partner, merchants can route any transaction to their PSP of choice through one integration. Reduce transaction costs as well as fraud and chargebacks, optimize processing fees, restrict the sale of prohibited goods, and more. 

Gr4vy makes it even easier for merchants to optimize their checkouts with multiple currencies, in multiple countries, and with multiple providers. Get in touch with our team to find out how we can help take the pain of payments out of your budget for 2024.

To find out more about the differences between IaaS and SaaS payment orchestration platforms, and which one might be right for your business, download our eGuide, ‘IaaS vs. SaaS: An e-commerce merchant’s guide to payment orchestration’.

Behind the Checkout: What is network tokenization?

Increased payment security has been top of mind for businesses for several years, as news throughout the year of major data breaches continues to make headlines. One way of improving payment security whilst improving customer experience has been through the use of tokens. Traditionally, merchants have been using tokens with payment service providers (PSPs) but are increasingly opting for a provider-agnostic strategy of using network tokenization for better flexibility and portability of data.  

But what exactly is network tokenization, how does it differ from PSP tokens, and what are some of the main questions and concerns merchants might have around network tokenization? Co-founder and Chief Product Officer of Gr4vy, Cristiano Betta, breaks it down.

If you prefer to learn via video or audio, access the full recorded ‘Behind the Checkout’ webinar on network tokenization for even more insight

What is network tokenization and how can it be used to enhance security? 

While network tokenization has been around for a few years, it’s still a relatively new technology with increasing adoption. Instead of the traditional route of merchants storing card details, those are replaced with network-specific tokens with enhanced security and portability. 

Many merchants will have used tokenized cards with a payment service provider (PSP), which replaces the card data with a PSP-specific token which is sent on every request, rather than relying on the original card data. Network tokenization extends this idea by giving a merchant a similar, yet PSP-agnostic solution. Merchants can send the card data to a network tokenization service, such as Gr4vy, and that service will determine what scheme to connect with and then issue a network token. It’s similar to the original process but unlike PSP tokens, merchants are not restricted to using that token with any PSP, allowing for more flexibility. 

What are the benefits of network tokenization for merchants?

There are a range of benefits besides portability – the main ones include higher authorization rates, lower costs, and account updater functionality. There are several industry reports, but it works out at about a 40-50 basis point (BPS) uplift in authorization rates just from using network tokens. 

To find out more about how network tokenization can increase authorization rates for merchants and other benefits for merchants, check out the full recording of the ‘Behind the Checkout’ webinar

On the technical side, network tokens have a built-in account updater, taking the burden from the merchant to use an additional account updater service. If, for example, a customer is issued a new card by the bank because their card expired or was misplaced, the network token will automatically start to refer to that new card. This is particularly beneficial to merchants that are doing recurring payments because it increases the longevity for the merchant. No longer will subscription payments bounce each time a customer changes their card details. 

What are some of the considerations for merchants when selecting the right provider for network tokenization?

One of the main things a merchant should be considering is the restrictions they may face as they grow. One of the key benefits of choosing a network token over a PSP token is the portability and the ability to use that token with multiple payment service providers rather than getting locked into one. 

When a merchant generates network tokens, it is extremely important to consider who owns those tokens – are they generated for the merchant? Or are they generated for the payment service provider? For merchants that want more flexibility, an external vault becomes essential. With external vaults, the token that’s generated belongs to the merchant, and therefore a merchant can take those network tokens anywhere. They can use them in the vault provider’s system, or they can use them externally with whichever service they choose. Portability and ownership go hand-in-hand. 

For more information on Cloud Vault and how merchants can ensure maximum data portability across their card data when working with multiple PSPs, check out this article with four actionable insights

Finally, merchants should consider the risks of shared tenancy. A lot of vault providers operate on a Software-as-a-Service (SaaS) shared tenancy model which means merchants share the risk with each other should anything go wrong. With an Infrastructure-as-a-Service (IaaS) model, merchant and customer data is completely segregated, so if there are any issues or concerns, and a merchant wants to pull their data out, it’s their data to move as they see fit. 

To access the full webinar with more information and insights on the areas covered above, view the library of on-demand ‘Behind the Checkout’ content here. If you’re interested in learning more about Gr4vy, and how its centralized vault makes it easy to store, pull, update, and distribute all your card data, simplifying compliance while ensuring you are always on top of local data regulations, check out Cloud Vault, and get in touch with a member of the team.