Switch processors easily
Bring your saved cards in from your current processor, add another, or leave one behind. The tokens stay the same, so no customer is asked for their card again.
Own your customers' tokens in a secure vault. This lets you control your processor experience: orchestrate or switch processors without losing your customers' valuable card information.
A workflow. A customer types a card into Fern & Field's checkout, and the number travels into the Cedar vault, turning into the token tok_7gq2x9 as it crosses the vault's edge. The vault, PCI DSS Level 1 and SOC 2, keeps the card and passes the token to your servers. Each charge runs from your servers as the token, through the vault, and out to Stripe as the card. Then Adyen is plugged in and charges go to it. Then Stripe is unplugged, and charges keep going to Adyen, with your servers holding the same token all along.
Like a coat check: you keep the ticket, we keep the card.
Customers type their card into Cedar's fields on your page or in your app. The card number goes straight to the vault, never through your servers.
We encrypt the card and store it in our PCI DSS Level 1 vault, and hand you a token to keep in its place.
Charge the token with Cedar Payments, or send it to any processor. We swap in the card on the way, so only the processor sees it.
Network tokens and account updater keep saved cards working when a bank reissues them, so the token you hold keeps paying.
Keep card numbers out of your systems and out of any one processor's hands, on their own or as part of a bigger build.
Bring your saved cards in from your current processor, add another, or leave one behind. The tokens stay the same, so no customer is asked for their card again.
We charge saved cards as network tokens, which banks approve more often than raw card numbers, and account updater keeps them working when a bank reissues the card.
Send each payment to the processor with the lowest fee or the best approval rate for that card, and retry a decline through the next one, all from the same token.
When a shopping agent pays for a customer with a network token, we recognize it as an agent payment and charge it like any other card. The customer's limits are checked by the card network.
await cedar.vault.forward({
token: "tok_7gq2x9",
to: "https://api.stripe.com/v1/payment_methods",
});Your server sends"card": "tok_7gq2x9"
Stripe receives"card": "**** **** **** 4242"
Send the token anywhere you'd send a card. We swap in the card number on the way, so it reaches the processor and nowhere else.
Four places to keep card numbers, and what each one ties you to.
| Yours to take anywhereCedar | Locked to one processorYour processor's vault | All the PCI workBuild your own | One more vendorA standalone vault | |
|---|---|---|---|---|
| Responsible for PCI DSS compliance | Included | Included | Not included | Included |
| Card numbers kept off your servers | Included | Included | Not included | Included |
| Charge through any processor | Included | Not included | Included | Included |
| Switch processors without asking for cards again | Included | Not included | Included | Included |
| Network tokens | Included | Included | Not included | $Extra cost |
| Account updater | Included | Included | Not included | $Extra cost |
| Routing by price, approval rate and retries | Included | Not included | Not included | $Extra cost |
| Permissions and audit logs | Included | Included | Not included | Included |
| Same system of record as your payments and books | Included | Not included | Not included | Not included |
Included$ Extra cost
Follow one payment from the checkout to your books. It passes through six blocks, and they fit together on one system of record.
A customer pays on Hosted checkout. The card goes into Token vault and comes out as a token. A second customer pays with another card, saved as a token of its own. Payments orchestration picks a processor: the first payment goes to Cedar for the highest approval rate, the second to Processor A for the lowest fee. Both are approved, and Accounting and Tax book each one with its fee and sales tax.
tok_7gq2x9Visa •••• 4242Mastercard •••• 4444Anything else? Book a call with us.
A stand-in for a card number, like a coat check ticket. You keep the token and we keep the card. The token only works through your Cedar account, so it's worthless to anyone who steals it.
Mostly. Cards typed into Cedar's fields go straight to the vault, so your pages and servers never see a card number, and most businesses qualify for the short questionnaire, SAQ A, instead of the full SAQ D. You still complete it each year, and we give you what you need to.
Yes. Collect and store cards with Cedar, then charge them through any processor you use. Add Cedar Payments or Payments orchestration later and the same tokens work there too.
Yes, both ways. We import saved cards through a secure transfer with your current processor or vault, and if you ever leave, we export them to whoever you choose. Your customers never type a card again.
A vault token stands in for the card inside Cedar. A network token is issued by Visa or Mastercard for a card and a merchant, and the networks keep it current when the card is reissued. We create network tokens for your saved cards and use them when you charge, which helps more payments go through.
Yes. When a shopping agent pays for a customer with a network token, through Visa Intelligent Commerce or Mastercard Agent Pay, we recognize it as an agent payment and charge it like any other card. The limits the customer set for the agent, like an amount or an end date, are checked by the card network.
Cedar is certified PCI DSS Level 1, the highest level for companies that store cards, and SOC 2. Cards are encrypted in the vault, access is set with permissions, and every time a card is used, revealed or sent on, it's recorded in an audit log.
Book a call and we'll move your saved cards into the vault, from any processor.
Prefer email? Write to hello@usecedar.co.