Product

The credential layer for merchants who own their payments.

Keep every stored card when you change PSPs. Earn the network-token uplift the schemes publish, on Visa, Mastercard, and American Express at once. Audit the whole credential lifecycle from one surface.

Built to PCI DSS Level 1SOC 2 Type II · in progressISO 27001 · in progressPSD2 RTS aligned
your tokentok_*
direct network connectionsVTS · MDES · AETS
authorize viaany PSP

Built on direct network connections, not someone else’s vault.

Most "tokenization" is gateway tokenization: a placeholder reference scoped to a single PSP’s vault. Veliro provisions credentials directly with the networks, bound to your merchant identifier, recognized across acquirers, never inside a PSP scope.

Architecture · credential boundary
three layers · one boundary
Veliro credential boundary architectureThree layers, top to bottom. The merchant application connects over TLS to Veliro’s credential layer, a Level 1 PCI service provider hosting four components: a tenant-isolated HSM-backed vault, a cryptogram engine for TAVV, UCAF, and AEVV, a signed lifecycle bus, and a declarative routing policy. The credential layer connects directly to the card networks (MDES, VTS, AETS). PSPs and acquirers (Stripe, Adyen, Worldpay, Checkout.com) sit beside this path as rotatable authorization routes; they never see the credential.Merchant applicationSecure Fields SDK · web · iOS · Androidapi.veliro.com · TLS 1.3 · mTLS optVELIRO · CREDENTIAL LAYER (Level 1 PCI)VaultHSM-backedFIPS 140-2 Level 3Cryptogram engineTAVV · UCAF · AEVV5-min TTL · single-useLifecycle bussigned · replayable12 event types · wildcardRouting policyBIN · MCC · costdeclarative · auditableprovisioning · direct connectauthorization · token + cryptogramCARD NETWORKS · DIRECTMDES · VTS · AETSPSP & ACQUIRER · ROTATABLEStripe · Adyen · Worldpay · Checkout.com · …

Merchant application

Secure Fields SDK · web · iOS · Android

Veliro credential layer · Level 1 PCI

  • VaultHSM-backed · FIPS 140-2 L3
  • Cryptogram engineTAVV · UCAF · AEVV
  • Lifecycle bussigned · 12 event types
  • Routing policyBIN · MCC · declarative

Card networks · direct

MDES · VTS · AETS

PSP & acquirer · rotatable

Stripe · Adyen · Worldpay · Checkout.com · …

What changes when you own the credential layer.

Portability across PSPs, scheme-published authorization uplift, one operational surface, and interchange plus PCI scope savings. Each outcome below is backed by evidence you can audit, not a marketing claim.

Change PSPs without re-enrolling stored cards.

Credentials land on your network identifier, not a gateway vault. A processor change is a routing-policy edit: same tok_* on every acquirer, no customer comms.

0customer-visible card re-entries on a PSP switchSame tok_* across acquirers, zero opt-in funnels.

Recover interchange and PCI scope costs.

Tokenized CNP interchange runs roughly 10 basis points lower5 than PAN CNP on typical Visa and Mastercard programs. Secure Fields keeps card data off your servers so PCI scope contracts to SAQ‑A6.

~$1Mper $1B CNP volume, interchange differentialPlus six‑figure PCI savings from SAQ‑D → SAQ‑A scope reduction.

Earn scheme-published uplift on every network.

MDES, VTS, and AETS on one integration, with the right TAVV, UCAF, or AEVV cryptogram per transaction. Visa reports a +4.6% CNP approval lift1 for tokenized vs non-tokenized credentials.

Mastercard, Visa, and Amex publish their own uplift bands. Most teams ship one PSP and leave the rest of that revenue on the table. Veliro retrieves all three cryptograms with the correct ECI indicator and lets you attribute the uplift against your own baseline.

Scheme & industry benchmarksnot Veliro measurements
Visa CNP approvals
tokenized vs non-tokenized1
+4.6%
Visa
Mastercard approvals
first-attempt CNP2
up to +3pp
Mastercard
Fraud on tokenized
vs PAN-based online3
−28–34%
Visa
False declines
network-token pilots4
−5–8%
Mastercard

Operate and reconcile from one surface.

Every credential, cryptogram, and signed lifecycle event in one audit trail. Twelve event types and a wildcard; HMAC-SHA256 signed; replayable per delivery.

No fan-out across three network portals, no PSP-shaped data model in the middle. Lifecycle ships into BigQuery, Snowflake, or your OpenTelemetry pipeline in its native event shape.

Lifecycle event stream12 types · HMAC‑SHA256
14:39:12.401token.updatedd4e5f6a7-… · card_expiry_date=0329
14:39:11.218token.cryptogram.invalidateda1b2c3d4-… · eci=05 · ttl=300s
14:39:10.984token.network_token.activatedscheme=VISA · network_token_state=ACTIVE
14:39:08.117token.createdd4e5f6a7-… · source=CARD_ON_FILE
Sources · scheme & industry benchmarks
  1. Visa, “Deep Dive into Tokenized Transactions”: global CNP approval uplift for tokenized vs non-tokenized credentials.
  2. Mastercard network tokenization materials: reported uplift for first-attempt CNP approvals.
  3. Visa Token Service reporting and Visa Economic Empowerment Institute: fraud reduction on tokenized vs PAN-based online transactions.
  4. Mastercard network tokenization pilot reporting: reduction in false declines on legitimate transactions.
  5. Visa and Mastercard published interchange schedules: tokenized CNP rate programs typically price ~10 bp below non‑tokenized CNP equivalents in major regions.
  6. PCI Security Standards Council, SAQ‑A vs SAQ‑D scope guidance: hosted iframe (Secure Fields) integrations qualify the merchant for SAQ‑A. Reported savings depend on prior posture and scope.

One credential surface, four outcomes on day one.

Veliro isn’t an engineering-only decision. Each role below gets something specific when you go live, whether that is four teams or one engineer wearing four hats. No dedicated payments team required.

Engineering

One REST contract from sandbox to production. Idempotency-Key on every mutating call; signed webhook events you can replay per delivery.

POST /v1/tokens
Idempotency-Key: 8d…f3
{ "card_on_file": "cof_01H…" }

Operations

One audit trail across MDES, VTS, and AETS. Suspend a credential without an engineering ticket; replay an event window the same way.

  • 14:38token.suspendedcase=CX‑8417
  • 14:39replay.firedwindow=14:00‑14:30

Finance & revenue

Scheme benchmarks on tokenized CNP price ~10 bp under non‑tokenized and report 28–34% less fraud on the same volume. Secure Fields contracts the checkout from SAQ‑D to SAQ‑A; the annual QSA bill follows.

Interchange (CNP)−10 bp5
Fraud (CNP)−28–34%3
PCI scopeSAQ‑D → SAQ‑A6

Security & compliance

The audited boundary. The vault contains your PCI scope: SOC 2, PCI Level 1, and ISO 27001 attestations on the same surface.

PCI DSS
Level 1 service provider
BYOK
KMS‑backed signing (optional)
Retention
7‑year signed audit log

Operate the credential layer, not a PSP dashboard.

Search credentials, replay lifecycle events, and reconcile changes across networks from one surface. Built for whoever runs payments day to day: a dedicated ops team or one engineer with ops on their plate.

One integration in place of three scheme integrations, their certifications, and a PSP-locked vault.

Consolidate the credential estate onto one surface. Keep the network-token benefits the schemes publish. Keep every PSP a choice you can revisit on a Tuesday.

The credential layer is the one piece of payments infrastructure you should never rent from a processor. Own the token, own the cryptogram, own the audit trail, and a PSP becomes a routing decision you change on a Tuesday.

Three composable primitives. One contract surface.

Tokens, cryptograms, and lifecycle are orthogonal REST resources. Compose them, don’t subscribe to a flow. Each links to the API reference on the homepage with request schema, idempotency semantics, and scheme coverage.

Tokens

Credentials provisioned to your merchant identifier on Visa VTS, Mastercard MDES, and Amex AETS. The credential follows you across PSPs and networks.

POST /v1/tokens · synchronous · idempotent

View API reference

Cryptograms

Per‑transaction TAVV, UCAF, and AEVV cryptograms with the right ECI indicator. Single‑use, short TTL, idempotent by request key.

POST /v1/merchants/{m_id}/tokens/{id}/cryptogram · single‑use

View API reference

Lifecycle

Signed events for every credential state change. Replayable per delivery, rotatable signing secret, wildcard or per‑type subscriptions.

POST /v1/webhooks · 12 event types

View API reference

Audit‑ready from day one.

The vault boundary contains your PCI scope by architecture. Attestation status and audit timing live in the trust center.

Compliance 2026 roadmap

  • SOC 2 Type IIIn flight
  • PCI DSS Level 1Service-provider scope locked
  • ISO 27001In flight
  • PSD2 · EU SCARTS-aligned by design

Detailed attestation status and audit timing live in the trust center (NDA).

Start in a sandbox. Ship to production. Grow into the plan that fits.

Every Veliro engagement starts in the same self-serve sandbox and grows from there. No payments team required to get your first token on a network, and a demo whenever you want a walkthrough.

Own the credential layer. Keep every PSP a choice.

Sandbox key in minutes. First portable credential on a network soon after. Then keep it, whatever PSP you pick next.