As the Token Payments solution enables merchants to store encryption keys the following key management principles must be taken into consideration:Strong encryption keys should be generated (pseudo-random data of high entropy)
Encryption keys must only be transmitted via a Secure Socket Layer (TLS 1.2+) encrypted tunnel
Encryption keys must be stored securely, only accessible by necessary staff and applications
Staff with access to encryption keys should acknowledge (in writing or electronically) that they understand and accept their key-custodian responsibilities
The same cryptographic keys should not be used in production and test environments
Modified at 2026-07-08 07:49:24