Migration
This Migration Guide walks you through planning, execution, and post-migration monitoring to help you navigate the transition beteen providers smoothly and avoid common pitfalls.
Pre-Migration Discovery
Identify Source
Confirm the current provider holding the vault data. Please provide the name of the current Gateway or Third-Party Vault.
Request Export Schema
Request a sample export file or a data dictionary (CSV/XML) from the legacy provider so we can prepare our import scripts.
Field Mapping
Notify us if you use custom fields (e.g., Member IDs, specific metadata) in your current vault.
Subscriptions
Are you using vault records for active subscriptions?
- Data Only: We migrate the payment info, you keep the billing logic.
- Full Migration: We migrate both the payment info and the recurring schedules/intervals.
Record Count
Confirm the total number of records expected in the export to ensure no data loss during the transfer.
Authorized Contacts
Please introduce us to a technical contact at your current gateway. This allows us to coordinate the PGP key exchange and SFTP credentials directly.
Timing
Provide your target "Go-Live" date. We recommend a "blackout period" where no new vault entries are made in the old system during the final export to prevent data desync.
Technical Execution
Formal Release Request
You must submit a formal "Data Release Request" to the legacy gateway. Ask your current provider if they charge an "Export Fee" to avoid surprises.
Secure SFTP Upload
The legacy gateway will upload the PGP-encrypted file directly to our secure SFTP server. You must not touch this file.
Validation & Import
Our team will perform a "dry run" to validate formatting, identify expired cards, and ensure data integrity before the final production import.
Token Mapping File
Upon completion, we will provide a secure cross-reference file mapping your Old Record IDs to our New Record IDs.
Post-Migration & Go-Live
Testing
Run USD 1.00 transactions to test your migrated Customer Vault records.
Database Update
Update your internal CRM, ERP, or e-commerce platform with the new token values provided in the Mapping File.
Subscription Synchronization
Coordinate the "switch-over" moment where your billing engine begins hitting our API instead of the legacy gateway.
Decommissioning
Once you have verified X consecutive days of successful processing, notify the legacy provider to securely purge your data to stop recurring storage fees.
PCI-DSS Compliance: Payment data migrations must be performed Server-to-Server. Merchants must never handle, download, or email raw credit card data or unencrypted CSVs. If a provider asks you to download the data yourself, please stop and contact us immediately.