Tokenization · QVault

The card number
that never leaks.

Replace raw card numbers with scheme network tokens wherever they are stored or sent. Credential fraud collapses, PCI scope shrinks, and saved-card payments keep working long after the plastic is reissued.

Two hubs, one vault

Built for both sides of the token.

Issuers provision and manage tokens for their cardholders; acquirers and merchants store tokens instead of card numbers for repeat payments. QVault runs both hubs on one hardened core.

Stored credentialtok_4f9•••/DPAN
Raw PAN exposureZero
Card reissuedToken auto-updated
CryptogramFresh per transaction
PCI scopeDramatically reduced
Issuer token hub

Own every token your cards create.

Provision scheme tokens (DPANs) with the major card networks, then approve, suspend and delete them across wallets and merchants for your entire portfolio — with full visibility into where each card credential lives.

  • Network tokenizationProvision DPANs with the major schemes; every transaction carries a unique cryptogram.
  • Push provisioningAdd a card to Apple Pay, Google Wallet and merchant apps straight from your banking app.
  • Portfolio controlApprove, suspend or delete any token across every wallet and merchant, on demand.
Acquirer & merchant hub

Vault a card once. Charge it forever.

Store a customer's card as a token and charge it for one-click checkout, subscriptions and instalments — without ever holding the card number yourself. When cards are lost, reissued or expire, the token updates automatically and recurring payments keep succeeding.

  • One-click & recurringTokenized cards power saved-card checkout, subscriptions and instalments.
  • Automatic lifecycle updatesReissued and expired cards refresh their tokens via network lifecycle events.
  • Card numbers off your systemsStore the token; the PAN stays sealed in the vault — and only there.
Capabilities

Tokenization across the whole card lifecycle.

One hardened vault behind issuing and acquiring alike — provision, store, update and charge network tokens without the card number ever touching your systems.

Network tokenization

Provision scheme tokens (DPANs) with the major card networks. Each transaction carries a unique cryptogram, so an intercepted credential is worthless elsewhere.

Issuer token hub

Approve, suspend and delete tokens across wallets and merchants for your entire portfolio, with full visibility into where every card credential lives.

Acquirer & merchant hub

Vault a customer's card once and charge the token forever — for one-click checkout, subscriptions and instalments — without ever holding the card number yourself.

Push provisioning

Let cardholders add their card to Apple Pay, Google Wallet and merchant apps straight from your banking app — a one-tap flow QVault handles end to end.

Lifecycle management

Lost, stolen, expired or reissued cards update their tokens automatically via network lifecycle events. Recurring payments simply keep succeeding.

Hardened vault

HSM-backed keys, envelope encryption at rest, strict access audit and PCI DSS 4.0 controls — engineered to make bulk extraction pointless.

How it works

From PAN to token in three steps.

Capture once

The card is entered a single time — at checkout, in-app, or via issuer provisioning — directly into QVault's PCI-scoped capture surface.

Token issued

QVault exchanges the PAN for a network token and returns an opaque reference your systems store and use from then on.

Charge the token

Every payment uses the token plus a fresh cryptogram. The real card number stays sealed in the vault — and only there.

For developers

Vault a card in one call.

Send the card once; get back an opaque token you can charge forever. The raw number never lands in your database, your logs, or your PCI scope.

  • Charge by tokenReuse tok_… for every future payment — no PAN required.
  • Signed lifecycle webhooksGet notified the moment a token is updated or revoked upstream.
Read the docs →
POST /v1/vault/tokens Authorization: Bearer sk_live_••• { "pan": "5399•••••••••1234", "exp_month": 11, "exp_year": 2028, "hub": "acquirer" } // 201 Created { "token": "tok_4f9a2c7b", "network_token": "DPAN", "pan": null, "cryptogram": "fresh_per_charge", "pci_scope": "reduced" }
0
Raw PANs stored
4.0
PCI DSS controls
100%
Tokens auto-updated
3
Major networks
Under the hood

Vault-grade controls, by default.

Every credential is sealed behind the same hardened core — the security posture PCI DSS 4.0 assessors expect, engineered in from the first byte.

HSM-backed keysEncryption keys are generated and held inside FIPS-validated hardware security modules.
Envelope encryption at restEvery stored credential is wrapped under a data key that is itself encrypted by a root key.
Fresh cryptogram per transactionTokens are useless if intercepted — each authorisation carries a single-use cryptogram.
Automatic lifecycle updatesReissued, expired and replaced cards refresh their tokens via network lifecycle events.
Strict access auditEvery read and provisioning action is logged, scoped and reviewable per operator.
Dramatically reduced PCI scopeWith PANs out of your systems, the surface an assessor has to examine collapses.
Shrink your scope

Get card numbers out of your systems for good.

Whether you issue cards or store them, QVault removes the most dangerous data you hold. Start the conversation today.