One-Line Definition
A Card Vault is an encrypted, PCI-compliant storage system that replaces raw card numbers with tokenized references, allowing merchants to charge a customer again — for subscriptions, one-click checkout, or installments — without ever holding the actual Primary Account Number (PAN) in their own database.
Real-Life Analogy
Think of a Card Vault like a hotel front desk that issues key cards instead of handing out master keys.
When you check in, the hotel doesn't give you the key to every room in the building. It gives you a plastic card encoded with a reference that only the hotel's lock system understands. You can open your room, charge items to your folio, and come back tomorrow — but if you lose the card, nobody can use it to rob the entire hotel.
A Card Vault works the same way. Your customer's real card number goes into a hardened, isolated environment (the vault). What comes back out is a token — a meaningless string like tok_9f2a71c8e4b3 — that your checkout system, your CRM, and your subscription engine can all reference. The token is useless outside the vault's domain. If your marketing database leaks, the attacker gets tokens, not card numbers.
Core Formula
Raw PAN → [ Vault Encryption + Tokenization ] → Token + Metadata
↓
Token stored in merchant DB
↓
Charge request (token + amount) → Vault → Card Network
↓
Vault returns: approved / declined / 3DS challenge
The critical property: the PAN never leaves the vault boundary. Your application talks to the vault through an API. The vault talks to the acquirer. Your servers are, in PCI DSS terms, pushed out of scope for cardholder data storage.
Comparison with Related Terms
| Term | What It Stores | Who Holds the Sensitive Data | Reusable for Future Charges? | Typical Owner |
|---|---|---|---|---|
| **Card Vault** | Token + encrypted PAN + metadata (expiry, cardholder name, BIN) | Vault provider (PSP, gateway, or dedicated vault vendor) | ✅ Yes — designed for it | Stripe, Adyen, Braintree, Spreedly, Vaulted |
| **Payment Gateway** | Transient authorization data | Gateway | ⚠️ Only if it also offers vaulting | Stripe, Authorize.Net, Checkout.com |
| **Tokenization (network)** | Network token (DPAN) mapped to PAN | Card network (Visa, Mastercard) | ✅ Yes, but network-controlled | Visa Token Service, Mastercard MDES |
| **PCI DSS SAQ A** | Nothing — fully outsourced | PSP only | Depends on PSP | Merchant |
| **PCI DSS SAQ D** | Everything — full PAN | Merchant | ✅ Yes, but massive compliance burden | Large merchants only |
Key distinction: A *network token* (like a Visa DPAN) is issued by the card scheme and survives card reissuance. A *vault token* is issued by your PSP or vault vendor and is scoped to that provider. Many modern vaults use both — a vault token that maps to a network token, which maps to the PAN.
Use Cases
1. Subscription billing (SaaS, streaming, boxes)
A customer signs up once. The vault stores the token. Every month, your billing engine sends charge(token, $29.00) to the vault. No re-entry, no stored PAN, no SAQ D. For a SaaS company with 50,000 subscribers, this is the difference between a 2-person compliance team and a 20-person one.
2. One-click checkout for returning shoppers
Amazon's "Buy Now" is the canonical example. The vault holds the token; the shopper holds the session. Conversion lifts of 20–30% are routinely reported when returning customers skip card entry.
3. Installment and BNPL flows
A $1,200 purchase split into 6 monthly charges. The vault holds the token and the schedule. If the customer's card expires mid-plan, the vault can request a network token refresh rather than dunning the customer.
4. Card-on-file for marketplaces and platforms
A marketplace like Etsy or Shopify's Shop Pay vaults the buyer's card once and lets any merchant on the platform charge it — with the platform as the merchant of record. This is the architectural backbone of modern embedded payments.
5. Fraud recovery and network token lifecycle
When a card is reported lost, the network can push a new DPAN to the vault automatically. Subscriptions keep running. Without a vault, every reissued card means a failed charge and a churned subscriber.
Misconceptions
"A vault means I don't need PCI compliance."
False. You still need PCI DSS — but you move from SAQ D (hundreds of controls, quarterly ASV scans, annual on-site audit for large merchants) to SAQ A or SAQ A-EP (roughly 20–40 controls, self-attestation). The vault doesn't eliminate compliance; it shrinks it.
"Tokens are just encrypted card numbers."
No. Encryption is reversible *by design* — if you have the key, you have the PAN. Tokenization is a one-way mapping: the token has no mathematical relationship to the PAN. A vault typically does both (encrypts the PAN at rest, issues tokens for reference), but the token itself is not a ciphertext.
"Any PSP vault is the same."
Vault portability matters. If your vault provider locks tokens to their platform, migrating to a new PSP means re-collecting every card — a conversion killer. Vendors like Spreedly and Vaulted exist specifically to provide provider-agnostic vaults, so tokens survive a PSP switch.
"Vaults are only for big merchants."
The opposite is closer to the truth. A solo founder selling a $9/month subscription has the same PCI exposure as a Fortune 500 — but none of the compliance budget. A vault is the cheapest way to stay out of scope.
"Storing CVV in the vault is fine."
Never. PCI DSS prohibits storing the CVV/CVC after authorization, even encrypted, even in a vault. Vaults store PAN, expiry, cardholder name, and sometimes BIN — never the security code.
Related Terms
- Tokenization — the process of replacing a PAN with a non-sensitive surrogate
- Network Token (DPAN) — a card-scheme-issued token that survives reissuance
- PCI DSS — the card industry's data security standard; vaults are the primary tool for reducing scope
- PSP (Payment Service Provider) — Stripe, Adyen, Checkout.com; most operate their own vaults
- Payment Orchestration — routing transactions across multiple PSPs; requires a portable vault layer
- SAQ A / SAQ A-EP — the two lightest PCI self-assessment questionnaires, achievable only with full outsourcing or a vault
- 3DS (3-D Secure) — authentication step that often precedes vaulting a card for the first time
- Recurring Billing Engine — the system that reads tokens from the vault and schedules charges
- Card-on-File — the industry term for a stored card credential, whether vaulted or not
- Merchant of Record — the entity legally responsible for the charge; determines who owns the vault relationship
Bottom line: A Card Vault is the infrastructure that lets you say "charge the customer again" without ever saying "here is the customer's card number." It converts a compliance nightmare into an API call, and it's the quiet prerequisite behind nearly every subscription, one-click checkout, and marketplace payment flow in modern e-commerce.