Spreedly unbundles its vault: own your card credentials
Spreedly now sells its payment vault standalone, with tokens portable across 100+ providers. Your card-on-file data is the real processor lock-in.
Ask any operator why they haven't switched payment processors and you'll get a version of the same answer: the cards on file. Spreedly just made that answer harder to justify. It's now selling its payment vault as a standalone product, decoupled from the orchestration platform it used to require — which means the stored credentials that quietly lock you to one processor can live somewhere neutral.
What actually happened
Spreedly announced on July 15, 2026 that merchants can buy the vault by itself. The specifics:
- PCI DSS Level 1 tokenization, so raw card data never touches your systems
- Tokens portable across 100+ payment providers, with no re-vaulting when you switch
- Network tokenization and Account Updater included, which keeps expired and reissued cards from silently failing
- Stored-credential transactions are now 40% of volume on Spreedly's platform, up from 34% in 2022
CTO Mike Rivers put the pitch bluntly: a vault shouldn't lock you into anyone's roadmap, including Spreedly's. That's an unusual thing for a vendor to say out loud, and it's the part worth taking seriously.
Why payment credential portability matters for your business
Processor lock-in is rarely about contract terms. It's about data gravity. Your processor holds the tokens, the tokens only work with that processor, and migrating means either a bulk credential export negotiation or asking every subscriber to re-enter a card. The second option costs you real customers, so most merchants just don't switch — and they pay a rate they'd never accept if switching were easy.
Decoupling the vault turns that from a migration project into a routing decision. Same tokens, different downstream processor, chosen per transaction if you want. It's the same architectural move as putting a gateway in front of your AI models: the expensive, sticky asset sits in a layer you control, and the interchangeable vendor sits behind it.
The honest caveat: you're not eliminating dependency, you're relocating it. Spreedly becomes the thing you'd have to migrate off instead. That's still a better trade — a vault vendor competes on tokenization and uptime, while a processor competes on rates it has no pressure to lower once your cards are stuck. Ask any vault provider you evaluate the same question: what does bulk export look like, in writing, on the day we leave.
Key takeaways
- Spreedly began selling its PCI DSS Level 1 vault standalone on July 15, 2026, no orchestration platform required
- Tokens are portable across 100+ payment providers without re-vaulting card data
- Stored credentials are 40% of platform volume, up from 34% in 2022 — the vault is the real switching cost
- You're relocating dependency, not removing it: get bulk-export terms in the contract before you migrate
We build payment layers you can walk away from. Vendor-agnostic integrations, your credentials in a layer you control, processors swappable behind it. See how we architect commerce systems.
Sources: Spreedly press release, PYMNTS.
- #payment-vault
- #payment-orchestration
- #processor-lock-in
- #tokenization
- #ecommerce
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Agentic AI spending: $944B now, $3.35T by 2030 — read it right
A new PHD/WARC forecast puts agent-facilitated consumer spending at $944B in 2026, rising to $3.35T by 2030. That's 3.8% of consumer spend. Here's the operator read.
Read itInstacart buys Arpalus: who owns your shelf data?
Instacart acquired computer-vision startup Arpalus to turn 600,000 shoppers into a shelf-intelligence sensor network. If they run in your stores, they know your inventory better than you do.
Read it