How Air Canada Vacations Adds New Partners Without Expanding Its PCI Audit Scope
A subsidiary of Air Canada integrates new third-party booking partners without growing its PCI compliance audit scope.
Download the Case StudyAir Canada Vacations already had a PCI-compliant payment card tokenization provider in place. But when a new third-party booking partner needed to be integrated, they faced a technical dilemma: how to quickly add a new partner to their payment ecosystem without expanding their PCI compliance audit scope.
Air Canada Vacations chose DataStealth to provide additional solutions to secure this new partner integration. DataStealth was deployed between Air Canada Vacations and each new partner, tokenizing real payment card data before any cardholder data reaches their internal environments, and detokenizing it only after it leaves for the payment processor. Because tokenization occurs before cardholder data reaches the environment, and detokenization happens after it leaves, PCI compliance scope remains unchanged even as new partners are added.
It worked so well that Air Canada Vacations now looks to DataStealth to secure all of its future integrations. What started as a tactical initiative evolved into a strategic approach to growth, with new capabilities, reduced friction, and no additional audit burden.
Get the Full Case Study
Download the complete PDF for the full breakdown of challenge, solution, and results.