Skip to content

Own your customers, don't let your processor hold you hostage.

Own your customers' tokens in a secure vault. This lets you control your processor experience: orchestrate or switch processors without losing your customers' valuable card information.

A workflow. A customer types a card into Fern & Field's checkout, and the number travels into the Cedar vault, turning into the token tok_7gq2x9 as it crosses the vault's edge. The vault, PCI DSS Level 1 and SOC 2, keeps the card and passes the token to your servers. Each charge runs from your servers as the token, through the vault, and out to Stripe as the card. Then Adyen is plugged in and charges go to it. Then Stripe is unplugged, and charges keep going to Adyen, with your servers holding the same token all along.

How it works.

Like a coat check: you keep the ticket, we keep the card.

  1. Entered

    Collect card details

    Customers type their card into Cedar's fields on your page or in your app. The card number goes straight to the vault, never through your servers.

  2. Tokenized

    Encrypt into a token and vault it

    We encrypt the card and store it in our PCI DSS Level 1 vault, and hand you a token to keep in its place.

  3. Charged

    Use the token

    Charge the token with Cedar Payments, or send it to any processor. We swap in the card on the way, so only the processor sees it.

  4. Updated

    Cards always stay updated

    Network tokens and account updater keep saved cards working when a bank reissues them, so the token you hold keeps paying.

Your cards, not your processor's.

Keep card numbers out of your systems and out of any one processor's hands, on their own or as part of a bigger build.

Switch processors easily

Bring your saved cards in from your current processor, add another, or leave one behind. The tokens stay the same, so no customer is asked for their card again.

Higher approval rates

We charge saved cards as network tokens, which banks approve more often than raw card numbers, and account updater keeps them working when a bank reissues the card.

Route every payment

Send each payment to the processor with the lowest fee or the best approval rate for that card, and retry a decline through the next one, all from the same token.

Ready for agent checkout

When a shopping agent pays for a customer with a network token, we recognize it as an agent payment and charge it like any other card. The customer's limits are checked by the card network.

await cedar.vault.forward({
  token: "tok_7gq2x9",
  to: "https://api.stripe.com/v1/payment_methods",
});

Your server sends"card": "tok_7gq2x9"

Stripe receives"card": "**** **** **** 4242"

What your code sees, and what your processor sees.

Send the token anywhere you'd send a card. We swap in the card number on the way, so it reaches the processor and nowhere else.

PCI DSS Level 1
The highest level of card security certification, for companies that store cards.
SOC 2
Our security controls are independently audited.
Every access logged
Permissions decide who can use a card, and every use is in an audit log.

Head to head.

Four places to keep card numbers, and what each one ties you to.

Yours to take anywhereCedarLocked to one processorYour processor's vaultAll the PCI workBuild your ownOne more vendorA standalone vault
Responsible for PCI DSS complianceIncludedIncludedNot includedIncluded
Card numbers kept off your serversIncludedIncludedNot includedIncluded
Charge through any processorIncludedNot includedIncludedIncluded
Switch processors without asking for cards againIncludedNot includedIncludedIncluded
Network tokensIncludedIncludedNot included$Extra cost
Account updaterIncludedIncludedNot included$Extra cost
Routing by price, approval rate and retriesIncludedNot includedNot included$Extra cost
Permissions and audit logsIncludedIncludedNot includedIncluded
Same system of record as your payments and booksIncludedNot includedNot includedNot included

Included$ Extra cost

It's all part of the bigger build.

Follow one payment from the checkout to your books. It passes through six blocks, and they fit together on one system of record.

A customer pays on Hosted checkout. The card goes into Token vault and comes out as a token. A second customer pays with another card, saved as a token of its own. Payments orchestration picks a processor: the first payment goes to Cedar for the highest approval rate, the second to Processor A for the lowest fee. Both are approved, and Accounting and Tax book each one with its fee and sales tax.

Hosted checkout

Fern & FieldCoffee Roasters**** **** **** 4242Pay $24.00

Token vault

You are hereCard saved astok_7gq2x9Visa •••• 4242

Payments orchestration

RuleHighest approval rate→ Cedar

Payments

CedarCedar PaymentsApproved
Processor AYour other processorApproved

AccountingTax

Your ledger$24.00 via CedarFee $1.00 · Sales tax $1.94$60.00 via Processor AFee $1.62 · Sales tax $4.85Booked

Questions about Token vault.

Anything else? Book a call with us.

What is a token?

A stand-in for a card number, like a coat check ticket. You keep the token and we keep the card. The token only works through your Cedar account, so it's worthless to anyone who steals it.

Does this take us out of PCI scope?

Mostly. Cards typed into Cedar's fields go straight to the vault, so your pages and servers never see a card number, and most businesses qualify for the short questionnaire, SAQ A, instead of the full SAQ D. You still complete it each year, and we give you what you need to.

Can we use Token vault without Cedar Payments?

Yes. Collect and store cards with Cedar, then charge them through any processor you use. Add Cedar Payments or Payments orchestration later and the same tokens work there too.

Can we move cards in from our processor, or take them with us?

Yes, both ways. We import saved cards through a secure transfer with your current processor or vault, and if you ever leave, we export them to whoever you choose. Your customers never type a card again.

How is a network token different from a vault token?

A vault token stands in for the card inside Cedar. A network token is issued by Visa or Mastercard for a card and a merchant, and the networks keep it current when the card is reissued. We create network tokens for your saved cards and use them when you charge, which helps more payments go through.

Can we take payments from AI shopping agents?

Yes. When a shopping agent pays for a customer with a network token, through Visa Intelligent Commerce or Mastercard Agent Pay, we recognize it as an agent payment and charge it like any other card. The limits the customer set for the agent, like an amount or an end date, are checked by the card network.

How is the card data protected?

Cedar is certified PCI DSS Level 1, the highest level for companies that store cards, and SOC 2. Cards are encrypted in the vault, access is set with permissions, and every time a card is used, revealed or sent on, it's recorded in an audit log.

Start building.

Book a call and we'll move your saved cards into the vault, from any processor.

Prefer email? Write to hello@usecedar.co.