The Root of Trust for Secure Payment Infrastructure
CHARGE Anywhere operates a PCI-Validated Certificate Authority and Registration Authority (CA/RA), forming the foundation of its encryption and key management infrastructure.
This CA/RA environment serves as the root of trust across the entire payment ecosystem—enabling secure device authentication, certificate issuance, and trusted encryption key lifecycle management.
What This Enables

Secure Device Authentication
Ensures only authorized payment devices are provisioned and trusted within the network
Certificate Issuance & Validation
Establishes a verified chain of trust for all cryptographic operations

Encryption Key Lifecycle Management
Supports secure generation, distribution, rotation, and deprecation of keys.

Trusted Device Onboarding
Enables secure, scalable deployment of payment terminals across global environments.
Full Control of the Trust Layer
Unlike providers that rely on third-party security infrastructure, CHARGE Anywhere owns and operates its CA/RA environment in-house, delivering:
- Greater security integrity
- Faster deployment and provisioning
- Reduced dependency on external providers
- Complete control over the encryption trust chain
Part of a Complete PCI Security Ecosystem
The CA/RA operates in conjunction with CHARGE Anywhere’s full suite of PCI-validated security capabilities, including:
- Key Injection Facility (KIF)
- Encryption Service Organization (ESO)
- Remote Key Injection (RKI) via Customer Vault platform
- Point-to-Point Encryption (P2PE) via Customer Vaultâ„¢
Built for Modern Payment Platforms
Whether supporting OEM device manufacturers, ISVs, or enterprise payment environments, CHARGE Anywhere’s CA/RA infrastructure enables organizations to:
- Deploy secure payment devices at scale
- Maintain full PCI compliance
- Accelerate time-to-market without building internal cryptographic infrastructure
Backed by U.S.-Based FIPS-Validated HSM Infrastructure
Charge Anywhere’s CA/RA and key management platform is secured by FIPS 140-2 Level 3 Hardware Security Modules (HSMs) deployed within geographically redundant, U.S.-based data centers—ensuring the highest levels of cryptographic protection, compliance, and operational control.
Own the Trust Layer
CHARGE Anywhere’s PCI-validated CA/RA ensures that every device, transaction, and encryption key is rooted in a secure, trusted, and fully controlled environment—powering the next generation of payment infrastructure.
CA/RA
Establish and manage a PCI-validated Certificate Authority and Registration Authority to securely issue, control, and lifecycle-manage encryption keys across your payment environment.
KIF
Enable secure key injection workflows to provision devices with encryption keys safely and efficiently, supporting compliant deployment at scale.
ESO
Deliver secure key management and transaction processing through a browser-based environment, eliminating the need for on-premise infrastructure while maintaining strict security controls.
HSMs
Leverage certified Hardware Security Modules to generate, store, and protect cryptographic keys within a tamper-resistant, PCI-compliant environment.

