Tokenization vs Encryption for Card Data
Every few months a product manager or a board member asks me some version of the same question: "We encrypt the card numbers, so we are PCI compliant and safe,...
8 articles tagged #security.
Every few months a product manager or a board member asks me some version of the same question: "We encrypt the card numbers, so we are PCI compliant and safe,...
Every fintech founder I have worked with eventually has the same uncomfortable conversation with an auditor, a regulator, or a partner bank's risk team. The...
Almost every fintech integration I have shipped eventually grows a webhook surface. Card networks, payment processors, KYC vendors, ledger systems, and...
Fraud detection is one of those problems that looks deceptively simple from the outside. Someone makes a payment, you decide whether it is legitimate, and you...
Every engineer who touches a payments system eventually runs into PCI DSS, usually at the worst possible moment: a few weeks before a deadline, when someone in...
Every breach post-mortem I have read in the last decade has a secrets problem buried somewhere in it. A connection string in a config file checked into source...
Every payment platform I have helped build eventually runs into the same uncomfortable truth: the request you cannot afford to drop and the request you must...
Security in a fintech API is not a feature you bolt on at the end, just before launch, when someone in compliance asks the uncomfortable question. It is a set...