The claimed subject matter relates to an architecture or arrangement that
can limit access to sensitive information by means of encryption. In
particular, data obtained from a payment instrument at, e.g., a
Point-Of-Sale (POS) location can be encrypted at an early stage such that
a POS (or another) application does not have access to the data in an
unencrypted form and/or does not have access to a means for decrypting
the data. For example, a Public Key Infrastructure (PKI) arrangement can
be employed such that a back-end payment processor can define encryption
algorithms, associate itself with a public key, and maintain a private
key for decryption. The public key can be delivered to the POS location
and employed for data encryption, and, moreover, the PKI can be regulated
by the more trusted parties.