PCI DSS requires strict control over how cardholder data is stored, transmitted, and processed. Tokenization replaces this data with tokens that cannot be reversed without a separate, secured mapping. But when secrets like tokenization keys, vault credentials, or API tokens slip into code repositories, the entire control model fractures.
Secrets-in-code