CentsChat
Welcome to CentsChat, the podcast that's changing the game for ISVs, Payment Facilitators, and Marketplaces! From demystifying complex regulations like FinCen and PCI to the latest on Visa and Mastercard rules, our team breaks it all down with a dash of humor and a ton of insight. Whether you're looking to stay compliant, stay ahead, or just stay entertained, CentsChat is your go-to source for all things payments. Tune in and join the conversation – it's the most engaging and fun you’ll have learning about payments!
CentsChat
Card Present Isn’t Just Adding a Terminal
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Moving from card-not-present into card present sounds simple right up until a physical payment device enters the picture. For ISVs and PayFacs that have only processed online transactions—or that currently rely on a third party for their in-person payments experience—bringing card present in-house can mean taking on a completely different level of technical and operational complexity.
In this episode of Cents Chat, Kitty and Jason sit down with Lori Rainery to unpack what actually changes when a software company decides it wants more control over the card-present experience. Lori brings years of hands-on experience with EMV, POS implementations, payment technology, and ISV integrations from her time at TSYS and First American, giving the conversation a practical perspective on what happens beyond the API.
They get into the parts of card present that are easy to underestimate: EMV certification paths, increased PCI scope, device security, key injection, PIN data, tamper detection, interchange qualification, liability shift, and the downstream cost of getting transaction data wrong. The goal isn’t to turn this into an EMV engineering class, but to make clear just how many moving pieces show up when payments move from the browser to the countertop.
The conversation also digs into one of the less obvious strategic issues: device ownership and portability. Encryption keys, backend relationships, provisioning, and terminal architecture can all affect how easy—or painful—it is to change processors later. Add in the logistics of injecting, provisioning, shipping, installing, supporting, updating, and replacing physical devices, and “just add a terminal” starts looking a lot more like an infrastructure decision.
Lori also shares what she’s doing today with Polaris Crescent, where she’s helping companies use AI and automation to improve the way they operate. So while she may have moved on from the day-to-day world of EMV certifications, her perspective is still highly relevant for ISVs trying to simplify complex workflows, automate the messy parts of their business, and make smarter technology decisions before those decisions become expensive to unwind.
Welcome to Fents Chat, the podcast where payments meet personality. From TechTrends to Legal Twist. Compliance quirks to Marketplace Moves. Kitty's gear to keep ISVs, PayPal's, and marketplaces ahead of the curve. Get ready for insights, a few laps, and the occasional compliance gear. Let's dive in and make payments make sense.
SPEAKER_03If you're a software company processing payments online today, adding card present can sound pretty straightforward. Your customers want to keep payments in person, so you add a terminal. How hard could that be? Well, apparently it's pretty hard because once a physical payment device enters the picture, you're not just dealing with an API anymore. You've got hardware, EMV certifications, encryption keys, PCI scope, deployment, provisioning, interchange data, and an actual box that somehow has to make it from somewhere in the supply chain to your customer's countertop and work when they turn it on. So today we're talking about what really changes when an ISV or PayFac moves into the card present world. And Jason's joining me for this one because we're gonna get a little more technical than usual.
SPEAKER_01We could go way down the rabbit hole on this one. It could get really, really scary.
SPEAKER_03That's actually what I'm afraid of, Jason. Our guest Lori Rainery. Lori spent years working directly in EMV, POS, payment implementations, and card present technology, including leadership roles at Thesis and First American. And Jason, you and Lori actually go back a ways. Is that true?
SPEAKER_01Yeah, Lori actually was an EMV expert before I even cut my teeth in doing terminal certification. So I learned a tremendous amount from her probably what, 15 years ago, I think, at this point. And uh she can get about as far down in the technical weeds as anyone can, knows exactly how to turn a piece of hardware into something that a merchant can actually use.
SPEAKER_03Well, Lori, welcome to Sun's chat. Thank you. Thank you for the introduction. Absolutely. Before we drag you back into the world of terminals and EMV, give us the quick version of your payments background. You've been on the development side, the implementation side, product sales, you've seen card present from a lot of different angles. What do you have? Absolutely.
SPEAKER_02So starting at TSIS, I actually was the manager of our development team for Class B. And what that meant was truly working with those ISVs, implementing card payments or a POS into their payment solution. And then moving on to first American payment systems, I was not only the implementation director, but also shortly after that, I became senior director of sales. And inside of that, I worked with ISVs directly, making sure that their point of sales were hard brand approved to go out into the real world.
SPEAKER_03Now you've moved into a completely different chapter professionally. And before we make you spend the rest of the episode talking about your former life, tell us what you're building now with Polaris Crescent.
SPEAKER_02Just like EMB, AI is not defined. It is being rolled out in organizations that know they need to adapt to AI and to enable AI. And they really don't have that path to do so. And what we do is we solve that and that transformation for companies to bring AI into their organization in a safe and ethical way. And we're really standing beside them, helping them understand the governance piece, the compliance piece, all the different pieces and parts that they need to be able to enable so that they can have AI actually affect their bottom line.
SPEAKER_01It's really interesting how many payments companies that I talk to that are embracing AI and have yet to update their acceptable use policies to even have any AI governance whatsoever. They got source code flying everywhere.
SPEAKER_02Yes, subprocessor and EULAs are missed often. So we really start with that, with that assessment and say, hey, what do you have? And then we come in and help with that transformation.
SPEAKER_03All right. We've officially let you talk about what you're doing in 2026. Now we're gonna send you all the way back to terminals. I bet you're very excited for that one.
SPEAKER_02So excited.
SPEAKER_03EMB definitely is it was a huge part of my life for a very long time. Well, let's start with the assumption that gets companies into trouble. You're an ISV, you already process card not present payments. Your customers start asking to accept cards in person from the outside. The roadmap almost looks like ad terminal support, but that's not really what you're signing up for, is it? No, not at all.
SPEAKER_02Uh wow. I don't even the first thing you would should think about is PCI DSS, right? Is that full path of where that card information is starting from and then going to. And then also you need to look at your certifications. So EMV certifications are still a thing. Most companies, when we were doing the first EMV certifications, two plus year roadmap for ones that were really just going out there and doing it on their own. And then even when we had full-on experts, UL, Visa, all the issuers that, you know, were supporting this huge movement in the United States. It took, I think the the minimal certification time was like 10 months. And that was with a whole team of people.
SPEAKER_01Let's dive into EMV because it's probably one of the first places that software companies start realizing that things work different, right? Online integrations, pretty JSON-based, RESTful APIs. Then you start diving into terminal world. You've got semi-integrated models, fully integrated models, certification path everywhere that a transaction needs to go, uh fallback, right? I when I talk to a lot of software companies about uh expanding their stack into uh a card present world from a card not present world, especially the ones that are already using a third-party vendor for their card present piece, that have aspirations of making the the user experience slightly better or cutting their costs. I always say, hey, look, I'm gonna rattle off 10 terms that have to do with card present. And if you can define all of those, I'll give you the roadmap to doing this. But it's it's a magnitude of complexity greater than what you would experience in a card not present world. So, Lori, at the practice level, as somebody who's done this a million times, what is an IXV actually having to certify? And why does that become such a big deal and such a time-consuming headache for them?
SPEAKER_02Yeah, absolutely. So when we first found out EMV was going to be implemented, the first thing we thought was from the time that the card number hit the point of sale to the issuer through all the gateways, right? That's what we needed to certify. But then very quickly, we learned that you have to certify from the device all the way to the issuer. And what that means is if you change out that device, you say have an Ingenica one day and a PAX the other day, you now have to re-certify your entire point of sale system using that next device. So all of the tag, and then don't even get me started, I'm pinless debit and debit, right? So if you're going to be accepting those two, that's a whole nother level of certification that's not included in your EMB certification. And if 9F10, which is the tag that the issuers like to give everybody, if those aren't in alignment with the rest of the card message, it's it it'll just go in circles at that point. And you'll be QAing for probably two years.
SPEAKER_01You mentioned 9F10, and uh for those who don't know what that actually is, the card networks predominantly work under the hood on a spec called ISO8583. When we all adapted this uh this concept for EMV, there's a plethora of new data points that there weren't enough fields in the existing message format to support. So somebody came up with the a brand new format or recycled a format that was already out there for the payment space called TLV. And now we've got wonderful old field 55, which is a concatenation of God knows how many parameters on top of the initial ISO 8583 spec. So it's literally like we have a spec within a spec at this point when we're dealing with the card presence base space.
SPEAKER_02Absolutely. And if Saratoga isn't as complicated as it already is, right? Like understanding that in my implementation team when I was leading it, we actually created that app that would help parse out, right? Group three version 55, because otherwise you were tapping your arrow on your keyboard, going one, two, three, four, five, six, seven, eight, right? How many characters are supposed to be a nine F10 based on a spec that we were given by paper, right? So we quickly realized that we had to create an app, an internal app that would help us debug those things because 9F10 was our biggest concern as we were going through the MV certifications.
SPEAKER_03So when somebody says we want to support three terminals and maybe two processing relationships, they may hear flexibility and you hear projects. Yes.
SPEAKER_02Oh my goodness, that would probably take a team of about 15. You would have to have the relationship because you cannot just walk into Visa and say, I would like to EMV certify. That's not a thing. But overall, I think just going to an expert is super helpful because the expert has already done it multiple times. They have the lessons learned and they're able to guide you in the way that you need to be guided because that that is just a plethora of projects.
SPEAKER_03And we don't need to turn this into an EMV certification school, but the important part for the software company is that there's a difference between technically integrated and ready to safely process transactions in production.
SPEAKER_01Yeah, and this is where architecture decisions start having a very real cost. If you add another device, another processor, another route, depending on how that solution's designed, you're most likely just adding additional certification work.
SPEAKER_02Exactly. So when you're when you're looking at your point of sale and you say, okay, I like this specific gateway because it's going to give my merchant that I know is going to bring me an X amount of dollars over the next five years, is going to give me less points per merchant. I'm now going to have to recertify that entire path from the device to the issuer. So you're just in constant EMV certification.
SPEAKER_03All right, let's talk about security. An ISV that's been card not present may already have a PCI program and feel like they understand their environment. Then physical devices arrive. What changes then?
SPEAKER_02Oh wow. There are so many things. Where the device is sitting, how the device is secured, how often the device gets firmware update. So if you have a software development kit between the device and your point of sale, and you're not going directly from the device to the issuer, then that also has to make sure that you have no vulnerabilities.
SPEAKER_01Yeah, and on top of that, you know, for ISVs that are going from a card not present to a card present world, there's controls around it inspecting the device for tampering. You're dealing with pin blocks that you're not inherently dealing with in a card not present. Great segue into one of the most important business decisions when it comes to uh EMV certifications and card present devices. There's key management protocols that really bind that device to a particular processor on a whole slew of expanded scope that goes along with how you're dealing with cryptography.
SPEAKER_03Let's get into something every executive understands, and that is money. The payment went through, the customer got approved, everything looks successful, and you can still have processed that transaction badly.
SPEAKER_02When you're looking at liability from an ISV's perspective, there's multiple ways that you can get you could think that everything is working just fine, and then at the end of the month, you could see fines or fees from the card brands. And what I mean by that is there's technical fallback, but then there's also another type of fallback that the data will go to the card brands, it will appear to have processed, but then on the back end it didn't get the correct tags in that group three version 55 that we were just talking about. So when the card either tapped or inserted, then something went awry. The other thing is if you have two or three technical fallbacks, I believe, you then have to swipe, which is a whole nother process of that certification. Because when you swipe, you have to make sure that the issuer knows that it's coming from a technical fallback and not just a swiped card who doesn't already have a chip. And every single card pretty much has chips nowadays. So, like even more now today, that would be even harder to not get hit with fines.
SPEAKER_01Yeah, and this this is one of my favorite examples of hidden cost and scope creep when it comes to payments. A lot of organizations will look at how much they think the project is going to cost them, and they pay a team to get the integration done, and the team come back and says, Hey, it works, right? We're we're good to deploy. And months later, you've got the finance folks saying, Hey, this is costing us way more money than what we what we modeled from an interchange perspective, from a downgrades perspective. I think there's a a drastic misunderstanding and oversimplification about the amount of data that is actually going along with the card-present transaction compared to a card not present transaction. And if if that messaging format isn't correct, it it opens up all of the scary things that you were uh you know scratching the surface on. The other thing I just wanted to jump back to, because I I think it it it really deserves a little bit more time in this conversation, is the the key injection process and what that actually looks like because it's it's it's one of those topics you know that doesn't come up until you've perhaps done your emv certification, right? Your your initial device is injected with a test key on and now it comes time to deployment on hardware fulfillment on the table. Let's let's just focus on the key injection side of things because every one of these devices that's going out the door is injected with a unique key for that specific device that is derived from what's called the base derived key. And he who holds the base derived key is the only one who can do the mathematical calculations to decrypt that encrypted payload. I I feel like ISVs and people who are doing this for the first time don't understand that complexity and B also don't understand the the shortcoming of the who owns that BDK uh uh key decision. Let's say they've got 5,000 devices deployed and they want to change from processor A to processor B. You know, what does that look like? So, you know, Lori, if you could, if you could shed some light on some of those topics. Oh my goodness, that brought back such a crazy memory, Jason.
SPEAKER_03I don't know if you saw my face, but I did. I was waiting for it. I was like, what is she thinking about right now? Oh my goodness.
SPEAKER_02Okay. So there were, do you remember deja vu? Deja vu devices. We had put they had put them in, I don't remember if it was laundry mats or car washes. And the BDK changed. And some somehow we figured out how to update that with Monty specifically. He was like the C level at deja vu. And he he and I, and I believe there was one other gentleman on my development team. We came up with a way that he could go to every individual device and update that key physically. So he had to go to seven states because otherwise they would have had to remove all those devices, bring them back in-house, update that BDK, and then redeploy them. I actually, it was a funny thing. He sent me a picture of my picture hanging up in their lobby because after we were able to solve for that, he he blew up my LinkedIn picture and put it up in their lobby in their office to to show his appreciation. Absolutely. Yeah, because you're so right, Jason. Oh my gosh, I had totally forgotten about the fact that that was a test key when you're certifying, and then you have that immediate production key. But then if you skip that whole step, and then when you certify, you have, oh my goodness, there's so much paperwork too. It's all coming back to me now.
SPEAKER_03Now let's talk about the least glamorous part of card present, and that's the box. Software companies are used to deployment, meaning you push code, enable a feature, or tell somebody to download an app. But now you've got a physical device. Walk us through what has to happen between an ISV saying this merchant needs a terminal and that merchant actually taking their first payment.
SPEAKER_02That's that's a great subject to talk about because when EMB first hit the country, you know what the least glamorous conversation I had was do you have a power strip near where we can put a device? Right? Because many ISVs have these like very beautiful tablets, they have software on them, they can tap and go, we can move on with our lives, right? But now you have a device, now you need a power cable. Now you need internet access. Do you have that? And I I feel like once we started that conversation, we then went down the rabbit hole of when you purchase devices from a device company, a payment device company, such as a Pax or an Genico, then you would have a chain of custody. So from the time that it leaves the manufacturer to the time it hits your hand. And then once you get the device plugged in, you have everything where you think you're set up, you now have to do test transactions.
SPEAKER_03I was gonna say, I was like, you get your box, that arrives, and you know, that's not gonna work perfect forever. You're gonna have to troubleshoot, you're gonna have to set up, you're gonna have to make sure you know what you're doing and everything reflects what it should. Exactly.
SPEAKER_01Let's not discount that the average merchant, right, depending on on what vertical they're in, might not be technologically sophisticated. You know, uh on on top of them opening the box, there's a support team that needs to answer the phone when they say it's not working. Somebody has to support that. Somebody has to support the Bluetooth pairing of the device to the iPad or or whatever device the ISV is deploying for the you know, the POS solution. So there's there's there's a tremendous amount operationally that that again, much like key injection, I feel is underestimated and understated when when groups say, hey, we're gonna go do this EMV thing and deploy your own terminals.
SPEAKER_02There's just so many boxes you have to check, right? When you go from card not present to card present, you really need a team to support you.
SPEAKER_03Well, let's end it there because I'm sure we've absolutely scared a few software companies already with that one. The point of this episode isn't that an ISV shouldn't bring card present in-house. There's some very good reasons to want more control over the experience. But if a founder, a product leader, or payments leader is listening and considering it right now, what would you want them to figure out before they make that decision for themselves? Know your customer.
SPEAKER_02Right? Make sure that your customer is on the same page as you and has the same education as you. That was a huge lesson learned. We were shipping devices, ISVs were shipping devices out to customers, and customers had no clue what they were doing. They were going from tapping on an iPad to now having a complete device sitting on their counter, which you couldn't take to a table. Understanding the certification responsibilities, understanding your security responsibilities. You have chain of command, you have firmware updates, you have security updates. Not only does your point of sale have to have all of that, but now your devices have to have that. Designing for long-term flexibility, you're not always wanting to go through the same gateway. Other gateways are going to have better incentives for those specific customers. And when you think about that, you're going to now go through that an entire program of EMD certification from the time that the car touches the device till it gets to the issuer. And it doesn't matter if there's seven gateways in between, you have to call all of them. So you have to think about before you jump into the This world, how much you're willing to take on, how much you're actually able to take on, and then how that cadence is going to work year over year.
SPEAKER_01Yeah, and Lori, I'll add one thing. The thing I hear the most when somebody approaches me about the consideration of doing this in-house is hey, I heard from XYZ that if I convert these in-person transactions from a card not present rate to a card present rate, I'm gonna save 50 basis points over what I'm paying today. And that may be totally accurate, but you've got to be processing you know tens of millions, hundreds of millions of dollars for that 50 basis point savings, and you have to be able to convert all of that volume from card not present to card present for that 50 basis points of savings to actually offset what the cost of doing this in-house is. So, you know, my message to the to the ISV community would be really put a lot of thought into understanding this decision uh before you get married to it, because card present has a way of turning a business decision that that looks like a project into lifetime infrastructure.
SPEAKER_02Agreed. Infrastructure is key to that too, right? You have to build for the future. You can't just build for now.
SPEAKER_03And I think that maybe the big takeaway from this whole conversation when everything's online, payments can feel like software. And cart present reminds you very quickly that payments are actually infrastructure. There are devices, there are keys, there are certifications, there are security requirements, there are so many logistics. And if you want to own the customer experience, you need to understand which pieces of that infrastructure you're signing up to own it with. Now, Lori, before we let you go, I want to bring this back to what you're doing now. A lot of the ISVs listening are also trying to figure out where AI and automation can actually make their business better, not as a shiny new demo, but in the workflows that eat up time every day. Where does Polaris Crescent come in? And how are you helping companies make that practical?
SPEAKER_02That's a great question. Currently, we're helping companies understand what AI is so that education of understanding what agentic AI is versus machine learning versus autonomous AI, there's there's multiple buzzwords roaming around. And many companies are very like, they're like, oh, well, I'm just gonna layer AI over top of my unstructured data. We have to look at that infrastructure, we have to look at that enterprise architecture, and then help transform that data into something the AI can use. So really Polaris Crescent is looking at that transformation piece and really sitting alongside of organizations to help build that foundation to then layer AI in and see if AI is what is necessary, right? Just like car brand or card present versus not card present. Is it necessary? Do your customers expect you to have AI in your product? If yes, why? Is there a machine learning? Is there a bot that we can, you know, an agentic bot, but not truly AI, bring into house? So that's really where we're helping them to identify those high friction workflows. Does it make sense to layer AI? And then how do we layer AI?
SPEAKER_03So if you're an ISV trying to automate the messy parts of your business, give Lori a call. And if you're trying to get your EMV certification done, maybe don't call her for that anymore.
SPEAKER_01Yeah, I'm pretty sure she's retired from that chaos.
SPEAKER_03We dragged her back for this one episode, and I want to say thank you both so much for being on SenseChat with us today. It was awesome having you guys as guests. Thank you.
SPEAKER_01I'm just disappointed I didn't get to bust out the cryptography diagrams.
SPEAKER_03I I know you're disappointed, but I think everybody else at home is gonna be thanking me for it. Thank you so much, Lori, and everyone, thank you for listening to SenseChat. We'll see you guys soon. Thank you.
SPEAKER_00Thanks for tuning in to SenseChat. Got questions? Got ideas? Got payment problems keeping you up at night? We've got you covered. Head over to our website to take our quick survey. You might just land a guest spot on the pod. Don't forget to subscribe, share this episode with your favorite ISB, and follow us on all social for the latest trends, tips, and debates. We promise no boring slideshows. At FenseChat, we're here to make payments make sense and make it fun while we're at it. See you next time.