Skip to content
Rush Commerce
Commerce & Retail Tech2 min read

Spreedly unbundles its vault: own your card credentials

Spreedly now sells its payment vault standalone, with tokens portable across 100+ providers. Your card-on-file data is the real processor lock-in.

Ask any operator why they haven't switched payment processors and you'll get a version of the same answer: the cards on file. Spreedly just made that answer harder to justify. It's now selling its payment vault as a standalone product, decoupled from the orchestration platform it used to require — which means the stored credentials that quietly lock you to one processor can live somewhere neutral.

What actually happened

Spreedly announced on July 15, 2026 that merchants can buy the vault by itself. The specifics:

  • PCI DSS Level 1 tokenization, so raw card data never touches your systems
  • Tokens portable across 100+ payment providers, with no re-vaulting when you switch
  • Network tokenization and Account Updater included, which keeps expired and reissued cards from silently failing
  • Stored-credential transactions are now 40% of volume on Spreedly's platform, up from 34% in 2022

CTO Mike Rivers put the pitch bluntly: a vault shouldn't lock you into anyone's roadmap, including Spreedly's. That's an unusual thing for a vendor to say out loud, and it's the part worth taking seriously.

Why payment credential portability matters for your business

Processor lock-in is rarely about contract terms. It's about data gravity. Your processor holds the tokens, the tokens only work with that processor, and migrating means either a bulk credential export negotiation or asking every subscriber to re-enter a card. The second option costs you real customers, so most merchants just don't switch — and they pay a rate they'd never accept if switching were easy.

Decoupling the vault turns that from a migration project into a routing decision. Same tokens, different downstream processor, chosen per transaction if you want. It's the same architectural move as putting a gateway in front of your AI models: the expensive, sticky asset sits in a layer you control, and the interchangeable vendor sits behind it.

The honest caveat: you're not eliminating dependency, you're relocating it. Spreedly becomes the thing you'd have to migrate off instead. That's still a better trade — a vault vendor competes on tokenization and uptime, while a processor competes on rates it has no pressure to lower once your cards are stuck. Ask any vault provider you evaluate the same question: what does bulk export look like, in writing, on the day we leave.

Key takeaways

  • Spreedly began selling its PCI DSS Level 1 vault standalone on July 15, 2026, no orchestration platform required
  • Tokens are portable across 100+ payment providers without re-vaulting card data
  • Stored credentials are 40% of platform volume, up from 34% in 2022 — the vault is the real switching cost
  • You're relocating dependency, not removing it: get bulk-export terms in the contract before you migrate

We build payment layers you can walk away from. Vendor-agnostic integrations, your credentials in a layer you control, processors swappable behind it. See how we architect commerce systems.

Sources: Spreedly press release, PYMNTS.

  • #payment-vault
  • #payment-orchestration
  • #processor-lock-in
  • #tokenization
  • #ecommerce
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.