Network tokenization by default
Visa Token Service and Mastercard MDES from day one. The PAN never reaches the PMS, the booking engine, or the revenue manager's email. Tokens only.
Retrypay reduces your property's PCI scope by up to 80% through network tokenization, encrypted vault, and operation outside the certified environment. Your staff keeps operating as they do today; critical scope is no longer yours.
Visa Token Service and Mastercard MDES from day one. The PAN never reaches the PMS, the booking engine, or the revenue manager's email. Tokens only.
Cardholder data lives exclusively in Retrypay's vault. Annual shared AoC, signed responsibility matrix, documented SAQ reduction for the hotel.
Fleets of certified P2PE terminals (Ingenico, PAX) for even greater scope reduction at check-in and F&B. Hardware included in the premium module.
Policies, flow diagrams, control matrix, quarterly ASV scan evidence, and annual pentest ready to hand to your hotel or chain's QSA.
PCI DSS v4.0.1 came into force on March 31, 2025 with significantly stricter requirements: Req 6.4.3 (inventory and continuous monitoring of scripts on payment pages), Req 11.6.1 (detection of changes in HTTP headers and scripts), Req 8.3.10.1 (mandatory multi-factor authentication for admin access to CDE), Req 12.3.1 (documented risk analysis for each customized control). For individual hotels and mid-sized chains, complying with v4.0.1 in a PMS + booking engine + physical terminal + concierge mail + sales WhatsApp environment is operationally unfeasible without specialized architecture.
1. Sales and revenue management email: daily reception of credit cards by email from OTAs, travel agents, and corporate buyers. Every message containing plaintext PAN enters the hotel's PCI scope: the mail server (on-prem or Office 365 / Google Workspace), the revenue team's endpoints, the folder where the mail is archived, the mail server's backup. Traditional remediation requires end-to-end S/MIME encryption that neither OTAs nor corporate buyers implement.
2. The PMS and its database: Opera Cloud, Cloudbeds, Mews, SiteMinder, and Stayntouch store tokens in most cases, but there are flows where PAN does touch the PMS database (mass uploads from OTA, manual folios at front desk, multi-card split payments). That transient PAN puts the PMS DB, its backups, and its replicas in scope.
3. Front desk terminals: if terminals are not P2PE certified, the PAN decrypts inside the hotel's perimeter, exposing the LAN, the staff WiFi, the domain controller, and front desk workstations.
4. The booking engine and the website checkout: if checkout does not use direct tokenization (hosted fields or PSP iframe), the PAN passes through the booking engine's web server, its logs, its CDN, its WAF. With v4.0.1's Req 6.4.3 and 11.6.1, any third-party script loaded on the payment page (analytics, chatbots, marketing pixels) enters mandatory inventory.
5. Sales WhatsApp and direct communication: the direct sales channel where the concierge or revenue agent requests card details by message is the most hidden vector. Every screenshot, every exported chat history, every backup of the agent's mobile device contains plaintext PAN.
Retrypay reduces the hotel's critical scope to a minimal perimeter:
180-key boutique hotel, independent group. Pre-Retrypay scope: 14 systems in CDE, 4 network segments, 45 endpoints with justifiable access. Annual SAQ-D. Post-Retrypay (6 months):
Retrypay delivers your QSA a complete audit-ready package:
In 30 minutes we understand your current scope and deliver the specific reduction map for your property or chain.
Book PCI consultation arrow_forward