The VGS Vault platform exists independently from payment processors and service providers to tokenize and securely store sensitive data in a way that allows companies to retain full control over it - without expanding PCI compliance scope or disrupting internal systems. Our tokenization and vault technology supports virtually any payment use case - acceptance or issuance - for merchants, merchant enablers, fintechs, gaming apps, subscription providers, online marketplaces, travel agencies, and more. <br><br>VGS also connects directly with card networks like Visa and Mastercard to provide safe, centralized access to value-added network services like Network Tokens, Account Updater, and Card Attributes from full PANs. Our universal vault platform enables merchants with the ability to safely access and manage card data and consumer information for strategic initiatives around loyalty rewards, payment optimization, customer service, fraud prevention, marketing, and scalable infrastructure.
The VGS Vault is a universal tokenization platform that enables merchants to scale securely and quickly, free to operate on sensitive payment data without exposing their systems to it. With robust encryption, tokenization, and secure access controls, the VGS Vault ensures that all sensitive data remains safe and accessible for merchants to control across card networks, payment processors, and service providers. The VGS Vault helps companies externalize card data without losing data autonomy or utility.
VGS's founding principle is to give control back to merchants, enabling them to seamlessly manage their own payments stack as a universal token layer that interoperates across all third-party providers, processors, and card networks.
How it works: The VGS Vault features a single API integration, which exists alongside a merchant's existing payments ecosystem. This provides valuable vault redundancy from a processor-neutral location from which to manage cards by collecting card data, protecting it with tokenization, and exchanging it securely with any integrated endpoint (third-party service provider). Companies can use the VGS Vault as their own, which provides them with a place for centralized management of things like card lifecycle events. Managing card data centrally in a PCI-compliant, universal vault enables merchants, merchant enablers, fintechs, and financial institutions to optimize payments using:
- A Single-API Platform: A payments acceptance and issuing enablement platform that protects sensitive information and offsets PCI compliance liability for merchants, merchant enablers, banks, and financial institutions. VGS Vault customers use their vault to collect, protect, and send sensitive information to various PSPs for payment processing, issuing, risk mitigation, identity verification, and fraud monitoring.
- Comprehensive Data Security and Simplified Compliance: The VGS Vault employs advanced encryption and tokenization to protect sensitive data and achieve PCI DSS v4.0 compliance. Our universal vault minimizes the risk of data breaches and unauthorized access by securing data at the collection point, implementing a resilient cell-based architecture, and maintaining strict access controls.
- Scalable Integration: Designed with scalability in mind, the VGS Vault platform supports customers' increased data volumes and evolving security needs. VGS offers direct API and pass-through Proxy services for seamless onboarding and ease of integration with existing systems. Customers benefit from rapid deployment, reduced time to market, and the ability to quickly adapt to changing requirements without compromising security.
Highlights
The VGS Vault is processor-neutral, working across all platforms, PSPs, and networks to help companies avoid vendor lock-in and control when they send card information to third parties.
Companies can use the VGS Vault alongside their integrations via the pass-through VGS proxy or a direct connection using our single-API integration.
VGS's Vault manages over 4 billion tokens for more than 300 companies worldwide, using enterprise-grade encryption and tokenization technology to collect, protect, and exchange sensitive PCI and PII data from a secure cell-based architecture.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
VGS's Card Management Platform (CMP) provides merchants with direct access to value-added account updater, network token, and card attribute network services. CMP can be implemented alongside a merchant's existing payments ecosystem with a sing-API integration, working across all card networks, processors, and service providers for secure, centralized management of card data and payment workflows.
$12,000.00
MFT Platform
VGS offers multiple options for ingesting and processing batch data using the Managed File Tokenization (MFT) suite. This flexibility ensures that customers can securely and efficiently manage data transfers using standard protocols such as SFTP and FTPS as well as cloud technologies such as S3 cross-account replication and similar technologies. The adaptability of VGS's system allows for data to be received through any chosen method, validated for correctness before processing, processed in accordance with a pre-determined Service Level Agreement (SLA), verified to ensure no accidental data loss or leakage, and then delivered seamlessly to any designated destination. Please note that as a managed service, the annual price for MFT is subject to change based on projected annual volume, number of files protected, file type(s) and delivery frequency.
$50,000.00
SFTP Proxy
The protocol supports the full security and authentication functionality of SSH, and is widely used to exchange data between business partners. SFTP servers are often used to reconcile payment transactions and such documents often contain highly sensitive data. Documents are pre-processed by VGS during SFTP GET and SFTP PUT operations, and by configuring filtering rules in the VGS Dashboard, customers can filter sensitive data within documents sent via SFTP.
$24,000.00
PCI L1
A PCI L1 Compliance Subscription with VGS includes access to a set of tools, resources, and subject matter experts to help large merchants and service providers achieve PCI DSS v4.0 Level 1 compliance. The subscription includes regular updates and feature releases that help organizations maintain compliance with the latest PCI DSS mandated security controls.
$25,000.00
PCI L2-L4
Access to all the VGS standards, policies, and templates needed to successfully complete a Self-Assessment Questionnaire (SAQ), as well as completion of 3rd-party due diligence requests.
This contract lists 14 independent dimensions you combine to build your setup. Several bill by usage in units: Provisioned Network Tokens, Network Token Lifecycle Events, Card Attributes, and Account Updater. Account Updater also splits into card-network-specific units for Visa, Mastercard, Discover, and American Express, letting you pay per network you use. Platform dimensions cover the Card Management Platform, MFT Platform, and SFTP Proxy for data ingestion and processing. Two compliance subscriptions apply by merchant level: PCI L1 for large merchants and service providers, and PCI L2-L4 for smaller assessment needs. You select only the dimensions your workflow requires.
Top-of-mind questions for buyers
What does one Account Updater unit represent, and why are there separate units per card network?
Account Updater refreshes stored card credentials, like expiration dates, through secure network connections. The general Account Updater unit meters that refresh activity. Separate Visa, Mastercard, Discover, and American Express units let you pay per card network you actually update, since each network runs its own updater service.
How do the token-based dimensions combine to make up my bill?
Each usage dimension bills independently by units. Provisioned Network Tokens count tokens you issue to replace card numbers. Network Token Lifecycle Events count updates or changes to those tokens. Card Attributes count metadata lookups. Account Updater dimensions count refresh activity. Your invoice adds each metered dimension separately, so cost tracks the mix of services you use.
What is the difference between the PCI L1 and PCI L2-L4 compliance subscriptions?
PCI L1 targets large merchants and service providers pursuing PCI DSS v4.0 Level 1 compliance. It includes tools, experts, and ongoing updates for that level. PCI L2-L4 supports smaller assessment needs, giving you standards, policies, and templates to complete a Self-Assessment Questionnaire and third-party due diligence requests.
www.verygoodsecurity.com+1
Helpful?
Vendor refund policy
If you cancel your subscription within 48 hours of purchase, you will receive a full refund via AWS Marketplace. Otherwise all fees are non-cancelable and nonrefundable, except as expressly specified in the EULA or herein. All fees are exclusive of taxes, levies, or duties imposed by taxing authorities, and you will be responsible for payment of all such taxes, levies, or duties (excluding taxes based on Very Good Security's income), even if such amounts are not listed on an Order or Invoice.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.