The trust layer between your data and AI.

Protect your data. Ground your AI answers.

Enigma Vault provides AI data security through PII tokenization, secure storage and answers grounded in your evidence.

TRUST, MADE VISIBLE.
ClarityControlConfidence
Built on the Enigma Vault PCI DSS Level 1 SOC 2 Type II 99.99% uptime SLA AWS Partner

AES-256 encryption standard. Millions of secrets encrypted. Zero plaintext stored.

One foundation. Three products.

Protect the input. Trust the output.

Secure everything in between.

The Vault

Collect data. Keep it private.

Tokenize payment details, files and customer records before they reach your systems.

  • Secure payment capture
  • Custom intake forms
  • Tokenized files and records

NoPII

Use AI. Protect PII.

Tokenize and protect PII in your AI application before it reaches an LLM, while preserving the context it needs.

  • PII stays outside the model
  • Works with your existing LLM
  • One-line integration

Triplets

Answers backed by evidence.

Ground every answer in compiled evidence, with conclusions that update as sources change.

  • Whole-corpus grounding
  • Refuses unsupported answers
  • Updates with your evidence

The Vault

Secure your cards, files, and data. Without the heavy burden of compliance.

Enigma’s Vault is a PCI DSS Level 1 Service Provider and SOC 2 Type II audited platform for encryption, tokenization, and secure customer data management

PCI DSS Level 1 SOC 2 Type II

For developers

Enigma Vault API

A developer-first REST API for encrypting, tokenizing, and managing sensitive data. Three purpose-built vaults for cards, data, and files.

  • Card Vault: tokenize payment cards and proxy to gateways
  • Data Vault: AES-256 field encryption, searchable, batch up to 5,000
  • File Vault: encrypted cloud storage up to 5 GB with presigned URLs
  • OAuth2 M2M authentication
  • Available on AWS Marketplace
  • Twilio Pay integration for IVR card capture

For your team

Customer Vault

A secure web application for managing customer data, capturing intake submissions, sharing files, and collecting electronic signatures.

  • Branded public intake forms, no customer account needed
  • Customer profile management with cards, files, and signatures
  • Shared inbox where staff assign submissions to customer profiles
  • Secure file sharing with expiring links and password protection
  • Passkey or TOTP sign-in, with MFA tenants can require

Three layers of trust. One foundation.

Every AI feature has three places where trust can break: the answer it gives, the prompt it sends, and the data underneath. Each layer is a product you can buy on its own. Together, they share one foundation, one set of keys, and one audit trail.

01Triplets

Triplets: evidence-grounded AI answers.

Confidently wrong ends here. Triplets checks every AI answer against evidence you approve, and refuses when the evidence cannot support one. A confident wrong answer never reaches your user, because it never gets generated.

How it works, in one line:compile, verify, refuse when unsupported. Explore Triplets

02NoPII

NoPII: PII protection for LLMs.

What the model never sees, it can never leak. Every prompt is scanned for sensitive data and tokenized before it reaches the model provider, then restored in the response. The model reasons normally. The provider never sees a real identifier.

How it works, in one line:detect, tokenize, restore. Explore NoPII

03The Vault

The Vault: data tokenization and encryption.

Take sensitive data off your books. Cards, fields, files, and customer records are tokenized and encrypted on certified infrastructure. Your systems hold tokens that still work. The real values live in the vault.

How it works, in one line:capture, vault, reference. Explore the Vault

Need secure customer intake instead? Customer Vault

REQUEST · INPUT 01 02 03 ONE FOUNDATION
output at the top · data at the foundation

Proof

Proof, not promises.

Each layer earns trust with a hard fact, measured on your own data.

Triplets

Everyanswer checked against your compiled evidence

Triplets checks whether answers are supported by your compiled evidence and flags conflicts or missing support. Refusals and gaps are logged and reported. Evidence support does not establish universal truth, medical correctness or regulatory approval.

NoPII

30+configurable entity types tokenized

Before prompts reach the model provider, validated in a published 109-test report, across 9+ LLM providers. Live in under five minutes.

The Vault

AES-256encryption with per-customer keys

Full audit logging, on PCI DSS Level 1 and SOC 2 Type II infrastructure. Free to start on AWS Marketplace.

Built for teams shipping AI they have to stand behind.

For the people who own the consequences when AI gets it wrong:

Heads of AI and platform, whose product cannot give a confident wrong answer.
Engineering and compliance, who cannot let customer data leak.
CISOs, who answer for every record at rest.

The same three exposures, in every regulated industry.

Healthcare, financial services, legal, insurance, and every other regulated sector carry the same three liabilities: wrong answers, leaked identifiers, and stored data. The acronyms change. The exposures do not.

You can’t build your way out of this. Or prompt your way out of it.

The build trap.

Stitch together a reliability library, a redaction proxy, a token vault, and the glue between them. Three integrations, three audits, three bills, and the seams are where trust leaks.

The prompt trap.

Prompt it, fine-tune it, force it deterministic. A prompt is a request, not a constraint, and a model cannot police its own output.

↳

Trust has to be enforced as infrastructure, outside the application and outside the model. That is what the trust layer is.

Start with the layer you cannot afford to get wrong.

Pick the exposure that is most urgent today. Add the next layer when you need it. The foundation, the keys, and the audit trail are already there.