Overview
Payment tokenization replaces sensitive card data, like the primary account number, with a randomly generated token that has no value outside the system that issued it. Unlike encryption, a token cannot be mathematically reversed — the real card number sits in a secure vault, and only that vault can map a token back to it.
Why It Matters
If a database full of tokens is breached, the attacker gets nothing they can spend, which is also why tokenization shrinks the amount of a system that falls under PCI DSS. It also makes features like saved cards and recurring billing possible without the product ever holding raw card numbers.
How Dotcode Applies It
We use tokenization for stored payment methods and subscription billing as a default, treating it as part of the data-protection design described in our Data Privacy and Data Protection glossary entry rather than a late security patch.