Payment vaults are the layer where merchants effectively hand control of their credential sets to a vendor. Whoever runs the vault owns the canonical token record, and migrating that record when switching orchestration providers is disruptive enough that merchants typically avoid it. Spreedly, headquartered in Durham, N.C., broke that bundle on July 15 by releasing its vault as a standalone product, letting merchants control their own payment credentials without committing to its orchestration stack.
How vault custody creates lock-in
A payment vault ingests raw primary account numbers (PANs), stores them inside a PCI DSS-scoped environment, and issues surrogate tokens that travel through routing, authorization, and settlement. The merchant's systems see the token. The PAN stays in the vault. When vault and orchestration are sold as a single product, a merchant who wants to change routing vendors must migrate its entire token set as part of the same project. That migration is expensive and operationally disruptive, which inflates switching costs across the stack and keeps most merchants with the incumbent.
Spreedly's standalone product separates those decisions. Per the announcement, merchants can run a single provider per region using the vault today and layer in orchestration on their own schedule.
The portability case
Credential portability is the commercial argument. A merchant who holds its own vault can evaluate orchestration vendors strictly on routing and pricing terms. With vault and orchestration bundled at the same provider, the cost of moving the credential set is embedded in every vendor negotiation, which systematically advantages the incumbent.
The standalone vault is available now from Spreedly.