PCI Compliance and Card Tokenization
Getnet Web Checkout is designed with security at its core, ensuring PCI-DSS compliance by encrypting sensitive card information from the very beginning of the transaction.
Instead of transmitting card data throughout the payment flow, the system uses secure tokens, minimizing risk and maintaining data protection at every stage. Transactions processed through this solution use tokenization by default.
Card tokenization
Card tokenization is a service that replaces the PAN (Primary Account Number) with a token, which is provided directly by the card brands. Although each brand has its own token model to generate unique tokens, they all follow the same format, adhering to the structure of a standard PAN, including the BIN and a verification digit.
This ensures that the token is interoperable and can be processed by any acquirer that supports network tokenization, while maintaining the same level of security as the original card data.
Additionally, every transaction involving a card brand token requires the generation of a cryptogram, adding an extra layer of security and ensuring that the token is valid and can be processed.
Both the token and the cryptogram must be generated by the same provider to complete the transaction successfully.
This approach allows merchants to handle payments without ever storing or transmitting raw card data, reducing PCI scope and operational risk while providing a secure, payment experience.
See Also
- For implementation details and request parameters, refer to the Generate Token endpoint in the API specification.
- To understand compliance requirements when handling payment data, see PCI Compliance (PCI DSS).