Risk & Compliance

    PCI Vault

    Secure card data storage with PCI DSS Level 1 certification. Tokenize once, always operate with tokens. The PAN never touches your infrastructure.

    Architecture

    How the Vault works

    Each card data point passes through four security layers before storage. The merchant never accesses the PAN — only the token.

    1
    Layer 1

    Ingestion

    REST API with mutual TLS 1.3. Card data is received in an isolated PCI DSS Level 1 environment.

    2
    Layer 2

    Encryption

    AES-256-GCM with automatic key rotation via dedicated HSM. The PAN is encrypted before touching disk.

    3
    Layer 3

    Tokenization

    A unique non-reversible token is generated. The merchant operates with the token; the PAN never leaves the vault.

    4
    Layer 4

    Storage

    Database encrypted at rest with audited access. Logical isolation per merchant. Encrypted backups.

    Compliance

    Reduce your PCI scope from SAQ D to SAQ A

    When card data doesn't touch your infrastructure, most of the 300+ PCI DSS controls no longer apply. Akua absorbs compliance complexity and you operate with secure tokens.

    PCI Vault — SAQ D vs SAQ A compliance reduction

    Integration

    One API, zero contact with sensitive data

    Integrate PCI Vault with a single REST endpoint. Send the PAN once; receive a token you use for all subsequent operations: charges, refunds, subscriptions.

    PCI Vault API integration
    Performance

    Security without compromising speed

    Level 0PCI DSS — Certification validated annually by external QSA
    <0msTokenization latency — Includes AES-256 encryption + token generation
    0.00%Vault availability — Contractual SLA with multi-AZ redundancy
    0PANs in your infra — Sensitive data never touches your servers
    Capabilities

    Enterprise-grade security

    AES-256-GCM encryption

    Military-grade encryption with automatic key rotation via dedicated HSM. PAN is encrypted in memory before persisting.

    Non-reversible tokens

    Generated tokens contain no information derived from the PAN. It's impossible to reconstruct original data from the token.

    Per-merchant isolation

    Each merchant operates in an isolated context. One merchant's tokens are not valid or accessible from another.

    Multi-region AWS

    Infrastructure deployed in multiple availability zones with automatic replication and transparent failover.

    Immutable audit logs

    Each vault operation is recorded with timestamp, actor and context. Logs exportable for PCI audit.

    Lifecycle management

    Tokens with configurable expiration policies. On-demand deletion via API to comply with right to be forgotten (GDPR/LGPD).

    Use cases

    Where

    Recurring payments

    Store tokens for periodic charges without re-requesting card data. Compatible with Akua Subscriptions.

      Card-on-file

      Offer the "one-click payment" experience by storing tokens instead of PANs. Security and conversion.

        Vault migration

        Import PANs from your current vault to Akua via secure API. Migration with zero downtime and no data exposure.

          Multi-merchant platforms

          PayFacs and aggregators use a centralized vault with logical isolation per merchant. One vault, multiple businesses.

            Protect the data,
            simplify compliance

            Akua PCI Vault: secure storage, instant tokenization and PCI scope reduction in a single integration.