Customer Vault

Secure Customer Vault: PCI-Compliant Storage for Customer Data

A secure customer vault is an encrypted system that collects and stores customer payment cards, IDs, documents and signatures, and replaces them with tokens so your staff and tools never hold the raw data in email or files.

AK Abhilash Kumar Oct 1, 2026 19 min read
On this page

    Contact us

    Stop shipping unprovable AI answers. Ground them in evidence.

    Request a demo

    A travel agency books a family trip to Lisbon. The client emails four passport scans, reads a card number over the phone and sends a signed waiver as a photo. By Friday, those files sit in two inboxes, a shared drive, a WhatsApp chat and the CRM notes field.

    Each item arrived through whatever channel the client found easiest, and each copy stays where it landed:

    • Four passport scans live in every inbox the email reached
    • One card number sits on a call note anyone in the office can open
    • A waiver photo stays on an agent's personal phone and its cloud backup

    Multiply that by a season of bookings, and the agency holds an archive of IDs and card data it never meant to keep. A secure customer vault gives that data one protected place to land.

    In this guide, we explain how a secure customer vault works, what it stores and how to choose one.

    What is a secure customer vault?

    A secure customer vault is a protected store that holds customer cards, identity documents and sensitive fields in encrypted form, links them to one profile and hands your systems tokens to work with.

    The idea started with payment gateways, which save a card once so merchants can charge it later. Modern customer vaults collect everything a regulated business asks its clients for, from cards to signed consent forms, and keep it out of the tools where it usually leaks.

    A secure customer vault does two jobs in one system:

    1. Collection: a branded, secure link replaces the email or phone call your client would otherwise use.
    2. Custody: the vault encrypts or tokenizes what arrives, stores it on one customer profile and controls who can see it.

    Here is what changes for one client record:

    ItemWithout a vaultWith a secure customer vault
    CardNumber in an email or call notesToken on the profile, card held encrypted
    PassportScan in a staff inboxEncrypted file on the profile
    Signed waiverPhoto in a chat appSignature captured and logged
    SSN or tax IDTyped into the CRMTokenized field, revealed only when needed

    How a customer vault stores payment data

    A card entered through the vault is tokenized at capture. The vault keeps the card number encrypted and returns a token that stands in for it on the customer's profile.

    • Tokens have no value outside the vault, so a stolen copy cannot be used to make a purchase
    • Staff see the card brand and last four digits by default
    • Authorized roles can reveal the full number for a specific task, and each reveal is logged
    • CVV is discarded after authorization, because PCI DSS prohibits storing the security code, even encrypted

    How it stores documents and sensitive fields

    Files and signatures are sealed with envelope encryption: each file gets its own data key, which is itself encrypted by a master key the vault manages. Sensitive fields, such as an SSN typed into a form, are tokenized the same way a card is.

    What this means for your team: a CRM export or a lost staff laptop holds references to the data, while the data itself stays in the vault.

    What is a customer vault ID?

    A customer vault ID is the unique reference a vault assigns to one customer record. Your CRM or billing system stores that ID, so later actions never need the card number or file itself.

    In practice, that looks like this:

    • Repeat charges reference the vault ID and the card token
    • Document lookups open the profile by its ID
    • API calls match the profile to your own system's customer number, often called an external ID

    What it stores

    Data typeExamples
    Payment dataCredit and debit cards on file
    Identity documentsPassports, driver's licenses, national IDs
    FilesTax returns, bank statements, contracts, medical forms
    SignaturesRetainers, waivers, authorization and consent forms
    Sensitive fieldsSSNs, dates of birth, tax IDs, policy numbers

    How does a secure customer vault work?

    A secure customer vault works by sending customers a branded intake link, encrypting and tokenizing what they submit, routing it to a staff inbox and keeping it on one profile for later use.

    Follow the travel agency's next booking through the five steps.

    Step 1: Create a branded intake link

    An agent creates a secure link for the Costa family's trip. The link carries the agency's logo and asks only for what this booking needs:

    • Passport scans for four travelers
    • One card for the deposit
    • A signed travel waiver

    Agents create links in the web app, or the booking system generates one automatically through the API.

    Step 2: Customer submits without an account

    Mrs. Costa opens the link on her phone. She uploads the passports and enters the card, then signs the waiver with her finger on the same page.

    What she does not need: an app download, an account, a password or a separate e-signature tool.

    The agency's name and logo on the page tell her who is asking, which matters when clients distrust unexpected requests for passport scans.

    Step 3: Data is encrypted and tokenized

    As she submits, the vault does the protective work:

    1. The card is tokenized at capture.
    2. Files and signatures are encrypted in transit and at rest.
    3. Sensitive fields, such as passport numbers, are tokenized.

    Nothing lands in an email inbox or on the agency's own server.

    Step 4: Staff review in a shared inbox

    The submission appears in the agency's secure inbox. An agent checks that all four passports arrived and assigns the submission to the Costa family's profile. If something is missing, a new link goes out in seconds.

    Shared review means no single agent's inbox becomes the archive, and colleagues can pick up work when someone is on leave.

    Step 5: Use or share data from one profile

    When the agent books flights, the passport details are revealed for that task and the reveal is logged. When the hotel needs a copy of the signed waiver, it goes out through an expiring link with an optional password.

    Every step is written to the audit log. Next year, the agency starts from the same profile and requests only new or expired documents.

    What are the key benefits of a secure customer vault?

    The key benefits of a secure customer vault are reduced PCI scope, lower breach exposure, faster repeat billing and onboarding, an end to email attachments and a full audit trail of who accessed what.

    BenefitWhat changes for your team
    Reduced PCI scopeCard numbers stay out of your inboxes, CRM and servers
    Lower breach exposureA stolen laptop or hacked inbox holds no passports or cards
    Faster repeat billingCards on file stay ready as tokens
    Faster onboardingOne link collects everything, with fewer follow-ups
    No more attachmentsFiles are requested and shared through secure links
    Full audit trailEvery view, reveal and share is recorded

    Reduced PCI scope

    PCI DSS applies to every system that stores, processes or transmits card data. When cards are tokenized at capture, these systems typically stop touching card numbers:

    • Staff email and shared inboxes
    • CRM and booking software
    • Call notes and spreadsheets

    Fewer systems in scope means fewer controls to evidence. Your acquirer or QSA confirms the final scope.

    Lower breach exposure

    Most leaks start with an ordinary account, such as a phished inbox or a laptop left in a taxi.

    Before a vault: a phished inbox exposes years of passport scans and card details.

    After a vault: the same inbox holds intake notifications and nothing an attacker can use.

    Faster repeat and recurring billing

    A tokenized card is ready the next time the client books or renews.

    Example: a catering company serving the same corporate client every month keeps that card on file and bills each order without another call to the client's finance team.

    Faster client onboarding

    One link replaces the back-and-forth of "please also send…" emails.

    • Each client gets a link with only the fields they need to complete
    • Clients finish on a phone in one sitting
    • Staff see at a glance which submissions are complete and which need a follow-up

    No more email attachments

    Documents arrive through the vault and leave through expiring links. That removes the forwarded attachment, one of the easiest ways for files to reach the wrong person.

    Both directions: a tax firm collects W-2s through the vault and sends the completed return back through a protected link.

    Full audit trail

    Every action is logged with the user ID, action type, time and affected record, so hard questions become quick lookups:

    • Who revealed this client's card number last quarter?
    • Was the signed retainer downloaded, and by whom?
    • Which staff accounts opened this profile before it was deleted?

    What can you store in a secure customer vault besides cards?

    Besides cards, you can store government IDs and passports, legal and tax files, medical intake forms, e-signatures and consent records, and custom sensitive fields such as SSNs and policy numbers.

    This is where you will see the biggest difference between a customer vault and a payment gateway vault, which stops at cards.

    Government IDs and passports

    Travel agencies and property managers collect ID scans almost daily. In a vault, each scan is an encrypted file tied to the right person, and the passport number can sit in its own tokenized field for quick, logged reveals.

    Common uses: identity checks for rental applicants, passport details for international bookings and ID verification before a law firm opens a new matter.

    Legal and tax files

    Typical files: tax returns, W-2s and 1099s, bank statements, evidence bundles, signed engagement letters

    Why it matters: these documents carry account numbers and income details, and they tend to pile up in inboxes during busy seasons.

    How a vault helps: each client gets their own link, staff see which files have arrived, and finished work goes back through a protected, expiring link.

    Medical intake forms

    Clinics collect these before the first visit:

    • Medical history forms
    • Insurance card images
    • Signed consent

    A vault keeps them encrypted and away from scheduling tools that only need the appointment time, and patients finish at home, which shortens check-in.

    E-signatures and consent

    Signatures captured on the intake page are stored encrypted, with a record of when they were given. Typical documents:

    • Retainers and engagement letters
    • Card authorization forms
    • Leases and event contracts
    • Waivers and consent forms

    Custom sensitive fields

    Some of your most sensitive data is a single number. A good vault offers presets and custom fields, with validation that stops a client from submitting an eight-digit SSN.

    FieldTypical use
    SSNTax preparation, tenant screening
    Driver's licenseRental applications, vehicle hire
    Passport numberInternational travel bookings
    Date of birthPatient records, insurance quotes
    Tax IDBusiness clients, vendor onboarding
    Custom patternPolicy, member or loyalty numbers

    Each field is tokenized on save, with the same reveal, hide and delete controls as a card.

    Why do businesses need a secure customer vault?

    Businesses need a secure customer vault because cards and IDs arrive through email, phone and chat, sit in inboxes and shared drives, get chased manually and leave no record of who accessed them.

    If you run an intake desk, you will likely recognize at least three of these six problems.

    Card details arrive by email, phone and fax

    An agent writes a number on a sticky note during a call, a fax lands in a shared tray and an email with "card details" sits unencrypted in three mailboxes.

    Each copy is in PCI scope, and none can be deleted with confidence.

    IDs and passports sit in staff inboxes

    Nobody decided to build an archive of identity documents, yet most offices have one.

    Where a single passport scan ends up:

    • The receiving inbox and sent folder
    • Every colleague's inbox it was forwarded to
    • Mail apps on each person's phone
    • Backups of all of the above

    Staff chase missing documents manually

    The usual loop: request, wait, remind, receive half, remind again.

    Each round trip delays onboarding and adds another thread of sensitive files. In tax season, the chasing alone can take hours every week.

    Every copy widens PCI and privacy risk

    Where the copy livesWhy it matters
    Inboxes and archivesKept for years, searchable by anyone with access
    Laptops and phonesDownloaded attachments travel with the device
    Shared drivesLinks get forwarded, and permissions drift
    CRM notesBroad staff access, exports and backups

    Sharing files means sending attachments

    When a lender or co-counsel needs a document, staff attach it to an email. That copy never expires and can be forwarded by anyone who receives it.

    What staff need: a way to send the file that expires on its own, with a record of who downloaded it.

    No record of who accessed customer data

    Email and shared drives were never designed to answer "who opened this passport?"

    Without that record, incident reviews become guesswork, and a deletion request under laws such as the CCPA turns into a manual search of every inbox.

    Secure customer vault vs email, forms and shared drives

    A secure customer vault encrypts, tokenizes and logs every submission in one controlled place, whereas email, generic forms and shared drives spread copies that are hard to track, expire or delete.

    Each channel below moves the file. The risk starts once it arrives, so here is how each compares with a secure customer vault.

    Secure customer vault vs email attachments

    Every email recipient holds a permanent copy, and one wrong autocomplete can send a passport to a stranger.

    FactorEmail attachmentsSecure customer vault
    EncryptionDepends on both mail servers, files sit readable in mailboxesEncrypted in transit and at rest
    ForwardingAnyone can forward to anyoneFiles leave only through controlled links
    RetentionCopies stay in inboxes and backups for yearsOne copy, deleted from the profile when no longer needed
    AuditNo record of who opened the fileEvery view, reveal and download logged

    Secure customer vault vs fax

    A faxed page sits in a tray until someone collects it, and many fax lines now land in a shared inbox anyway.

    FactorFaxSecure customer vault
    Who can see itAnyone near the machine or with inbox accessOnly staff with the right role
    Card handlingCard number on paper or a scanned PDFCard tokenized at capture
    FilingManual scanning and namingAssigned to the customer profile from the inbox
    Client effortFind a fax machine or appOpen a link on a phone

    Secure customer vault vs generic web forms

    A form can use HTTPS and still create an unsafe workflow. Submissions often get copied into notification emails and spreadsheets the moment they arrive.

    FactorGeneric web formsSecure customer vault
    Card dataStored with other form answers unless a payment add-on is usedTokenized the moment it is entered
    CopiesNotification emails, spreadsheet exports, connected appsOne encrypted record on the profile
    Sensitive fieldsFree text with little validationSSN, passport and tax ID presets with validation
    Access controlAnyone with the form account loginRole-based access with logged reveals

    Secure customer vault vs shared drives

    Over time, shared links get forwarded and access piles up, so a folder of client IDs can stay visible to people who left the project months ago.

    FactorShared drivesSecure customer vault
    Link lifetimeLinks often stay live until someone revokes themLinks expire on their own, for example after 24 hours
    PasswordsRarely set on shared linksOptional password on each link
    TrackingLimited view of who downloaded whatDownload tracking on every link
    OrganizationFolders built by hand for each clientOne profile per customer

    Secure customer vault vs CRM notes and spreadsheets

    A card or SSN typed into a CRM notes field is visible to every user with record access and copied into every export.

    FactorCRM notes and spreadsheetsSecure customer vault
    VisibilityEvery user with access to the recordMasked by default, revealed by role
    Exports and backupsRaw values copied into each oneOnly tokens leave the vault
    PCI scopeThe CRM joins your cardholder data environmentThe CRM holds tokens and can often stay out of scope

    A cleaner pattern: keep the customer vault ID in the CRM, and open the profile when someone needs the real value.

    Secure customer vault vs messaging apps

    Clients like sending photos by chat. Those images then live on staff phones and personal backups that the business cannot manage or wipe.

    FactorMessaging appsSecure customer vault
    Where data livesStaff phones and personal cloud backupsYour own isolated tenant in the vault
    Business controlNone once the photo is sentReveal, hide and delete controls
    Staff offboardingPhotos leave with the employee's phoneAccess ends when the staff account is removed
    Client experienceQuick and unbrandedJust as quick on a phone, under your brand

    What features should a secure customer vault include?

    A secure customer vault should include branded intake forms, customer profiles, a staff inbox, secure file sharing, e-signatures, passkeys and MFA, tenant isolation, audit logs and an API.

    Here is what we would look for in each feature before shortlisting a vendor.

    FeatureWhat to look for
    Branded intake formsYour logo and colors, no customer account needed
    Customer profilesCards, files, signatures and fields on one record
    Shared staff inboxReview, assign and follow up on submissions
    Secure file sharingExpiring links, passwords and download tracking
    Electronic signaturesCaptured on the form and stored with an audit trail
    Passkeys and MFAPhishing-resistant staff sign-in that admins can require
    Tenant isolation and audit logsYour data kept apart, every action recorded
    API and webhooksCreate customers and links, get notified on new submissions

    Branded intake forms

    Clients trust a link that looks like your business, and branding eases phishing worries.

    • Your logo and brand colors on every link
    • Public links that need no customer account
    • One form that mixes cards, file uploads, signatures and sensitive fields

    Customer profiles

    One profile per client ends the search across inboxes. From a single dashboard, staff can search and page through customer records and see each one's stored data and recent activity at a glance. Every sensitive value on a profile should carry three controls:

    • Reveal: shows the full value to an authorized user, and the reveal is logged
    • Hide: masks it again when the task is done
    • Delete: removes it once you no longer need it

    Shared staff inbox

    New submissions land in one place, where the team assigns them to profiles and spots what is missing.

    Why it matters: if the agent who sent the link is out, a colleague picks up the submission.

    Secure file sharing

    When a file has to leave, it should leave on your terms:

    • Links that expire, for example after 24 hours
    • Optional passwords
    • Download tracking

    Files should be encrypted with a strong standard such as AES-256-GCM, and every download should be logged.

    Electronic signatures

    Signing during intake saves a second tool and a second email. Look for:

    • Canvas-based capture, so clients sign with a finger or mouse on the intake page
    • Encrypted storage linked to the right customer record
    • A timestamp and audit entry for every signature

    Passkeys and MFA

    Staff accounts are the keys to the vault. Passkeys on WebAuthn and FIDO2 replace the password with a cryptographic key on the staff member's device, so there is no password for an attacker to phish.

    Also check for:

    • Authenticator app (TOTP) codes as a second sign-in option
    • An admin setting that requires MFA on every staff account

    Tenant isolation and audit logs

    Your data should be separated from every other customer of the vault, with clear limits inside your own team.

    ControlWhat to look for
    Tenant isolationData, credentials and branding scoped to your organization
    Role-based accessReveal rights limited to the roles that need them
    Audit logUser ID, action type, timestamp and affected record for every action

    API and webhooks

    Engineering teams can create customers and intake links through an API and receive webhooks for events such as:

    • File uploaded
    • Card submitted
    • Signature captured
    • Field saved

    Each payload should be signed, commonly with HMAC-SHA256, so your system can verify it.

    Who needs a secure customer vault? Industries and use cases

    Businesses that need a secure customer vault are intake-heavy teams such as clinics, law firms, tax practices, clubs, hospitality, travel, property and insurance firms that collect client data daily.

    IndustryWhat clients sendTypical first use
    Health clinicsIntake forms, insurance cards, consentPre-visit intake without email or fax
    Law firmsIDs, evidence, signed retainersNew-matter intake before a workspace exists
    Accounting and tax firmsTax returns, SSNs, bank statementsSeasonal document requests
    Membership clubsCards on file, waivers, family detailsMember onboarding and renewals
    Restaurants and hospitalityDeposits, event contractsPrivate events and group bookings
    Travel agenciesPassports, cards, traveler detailsBooking intake for groups and families
    Property managementRental applications, IDs, income proofApplicant screening
    Insurance agenciesApplications, claims evidence, signaturesNew policies and claims

    Health clinics: patient intake, insurance cards and consent

    Patients complete history forms and sign consent before they arrive, with insurance cards uploaded alongside. PHI stays out of email.

    Share back: test results and care summaries go back to patients through expiring, password-protected links. Confirm a Business Associate Agreement with the vendor first.

    Law firms: client IDs, evidence and signed retainers

    Prospective clients often send documents before a conflict check, so a vault keeps them restricted until the matter is accepted. Typical new-matter intake:

    • Signed retainers and engagement letters
    • Sensitive case documents and evidence
    • Payment details for the retainer

    Filings go out through expiring links, with a download record for each.

    Accounting and tax firms: tax returns, SSNs and bank statements

    Client-specific links collect each document once, and staff can see which clients are complete.

    Collect: W-2s, 1099s, bank statements and prior-year returns

    Deliver: completed returns through protected, expiring links

    Membership clubs: cards on file, waivers and family details

    Clubs keep a card for dues and paperwork for every family member. One onboarding link can carry:

    1. The dues card, stored as a token
    2. A signed membership agreement
    3. ID documents
    4. Waivers for each family member

    Restaurants and hospitality: deposits and event contracts

    Private events need a deposit card and a signed contract, and both arrive through one link.

    Catering: a corporate client's card stays on file for recurring orders, and invoices go out through secure links.

    Travel agencies: passports, cards and traveler details

    Group trips mean many passports and at least one card.

    • Booking: passport numbers are revealed only when tickets are issued
    • Travel documents: itineraries and visas go out through time-limited links

    Property management: rental applications, IDs and income proof

    A vault keeps applicant files out of leasing agents' inboxes and makes deletion simple once screening ends.

    • Rental applications and ID copies
    • Signed leases
    • Deposit payments
    • Renewal documents, kept on the tenant's profile

    Insurance agencies: applications, claims evidence and signatures

    New policies bring signed disclosures, IDs and payment cards.

    Claims: correspondence goes out through auditable links, so the agency can show who received what and when.

    If the first step of your process is asking a client to send something sensitive, a secure customer vault belongs at that step, whatever your industry.

    Payment gateway vault vs secure customer intake vault

    A payment gateway vault stores cards so one processor can charge them again, whereas a secure customer intake vault collects cards, documents, signatures and sensitive fields on one profile.

    FactorPayment gateway vaultSecure customer intake vault
    Main jobSave cards for repeat chargesCollect and protect all sensitive client data
    What it holdsCardsCards, IDs, files, signatures, sensitive fields
    Who uses itBilling and financeIntake, operations and client services teams
    Customer experienceCard form at checkoutBranded link for cards, files and signatures
    Sharing files outOutside its purposeExpiring, password-protected links
    Tied toOne payment processorYour workflow, across channels

    Gateway vaults: stored cards for repeat charges

    A gateway vault saves a card and gives you a customer vault ID for future charges through that processor.

    Works well for: subscriptions and saved cards at checkout.

    Limits to know:

    • It holds cards only
    • Cards often stay with that processor, so switching can require a migration
    • IDs, contracts and signatures need a separate home

    Intake vaults: cards, documents and signatures in one profile

    An intake vault solves the step before billing: collecting what clients send, safely, and keeping it organized for your staff.

    Picture a law firm onboarding a new client. The retainer is signed, the ID is uploaded and the card for the retainer fee is tokenized, all through one link and all on one profile.

    Which one your business needs

    • Only recurring card charges? A gateway vault may be enough.
    • Cards plus documents, signatures and IDs? You need an intake vault.
    • Both? Many teams use an intake vault for collection and a gateway or card vault for charging.

    Our quick test: list everything your team asks clients to send. If the list has more than cards on it, a gateway vault alone will leave the rest in email.

    Is a secure customer vault PCI and HIPAA compliant?

    A secure customer vault supports PCI DSS and HIPAA requirements through tokenization, encryption and audit logs, while compliance still depends on vendor certifications, contracts and your own use.

    No tool makes a business compliant on its own. Here is how we see the split between the vault and your team.

    PCI DSS Level 1 infrastructure

    Look for PCI DSS Level 1 certified infrastructure, the highest tier for service providers, assessed annually by a Qualified Security Assessor. Ask for the current Attestation of Compliance.

    What tokenization changes for you:

    • Staff tools no longer store card numbers
    • Card data is captured directly into the vault
    • Reveals are limited to authorized roles and logged

    That can shrink your own scope. Your acquirer or QSA confirms which SAQ applies to your setup.

    HIPAA and health data

    If you are a covered entity or business associate, any vendor that stores PHI for you must sign a Business Associate Agreement.

    Encryption and audit logs support the HIPAA Security Rule's safeguards, and collecting only the minimum necessary fields supports its privacy expectations.

    Questions to ask before storing PHI:

    • Will you sign a BAA?
    • Where is the data stored, and who at the vendor can access it?
    • How are access logs kept and exported?

    Your remaining responsibilities

    The vault providesYour team provides
    Encryption and tokenizationChoosing which fields to collect
    Role-based access controlsDeciding who gets reveal rights
    Audit loggingReviewing logs and acting on them
    Delete controlsRetention and deletion schedules
    Certified infrastructureStaff training and vendor agreements

    The program around the tool, from training to incident response, stays yours.

    Turnkey app or API: how to deploy a secure customer vault

    You can deploy a secure customer vault as a turnkey web app your operations team uses the same day, or embed it in your own systems through an API and webhooks, and many teams use both.

    Turnkey web app for operations teams

    A turnkey app needs no developer, migration or database changes, so it runs standalone from day one.

    What a same-day rollout looks like:

    1. Set up your branding and staff accounts
    2. Require MFA for every user
    3. Send the first intake link to a real client
    4. Assign the submission to a profile

    Best for: clinics and small firms without an engineering team, or any team that wants results this week.

    Embedded via API and webhooks

    Engineering teams can wire the vault into their own software. A full API lets you:

    • Create a customer and receive their intake URL in one call
    • Receive signed webhooks when a file, card, signature or field arrives
    • Poll status for quick counts or full detail, using your own external ID
    • Set the webhook URL and signing secret, with the secret kept write-only

    Best for: SaaS platforms and larger firms that want intake to start automatically from their CRM or client portal.

    Using both

    We usually suggest starting with the web app, then adding API calls. A property manager might send links by hand in its first leasing season, then connect its applicant portal so every application triggers a link.

    Records collected by hand are already waiting behind the API, so the switch needs no retraining.

    How to choose a secure customer vault

    Choosing a secure customer vault is a process of checking its certifications, supported data types, payment compatibility, migration path, trial options and pricing against your intake workflow.

    These are the questions we would ask before signing:

    CheckQuestion to ask the vendor
    Security certificationsCan we see your PCI DSS Level 1 Attestation of Compliance and SOC 2 report?
    Supported data typesCan one link collect cards, files, signatures and custom fields?
    Payment provider compatibilityHow can stored cards be used with our processor?
    MigrationCan you receive cards from our current vault through a PCI DSS compliant transfer?
    Trial, sandbox or demoCan our team test a real intake flow before we commit?
    Pricing modelIs pricing per user, per submission or by engagement?

    Security certifications

    Ask for documents your auditors will accept:

    • PCI DSS Attestation of Compliance
    • SOC 2 Type II report, if the vendor has one
    • A written summary of encryption and key management

    Supported data types

    Map one real client journey, such as onboarding a new tax client, and check each item against the vault:

    1. Cards and payment details
    2. Files and ID scans
    3. Signatures
    4. Custom fields such as SSN or policy number

    Anything it cannot handle will drift back into email.

    Payment provider compatibility

    Some vaults work only with their own gateway, while others pass cards to the processor you already use.

    Ask directly:

    • Can stored cards be used with the processor we have today?
    • Are there fees or contract terms tied to using our own gateway?

    Migration from your current vault

    Cards move provider to provider through an encrypted transfer that follows PCI DSS. Ask both vendors how they handle it.

    Plan for three things:

    1. The export format your current provider supports
    2. Who handles the encrypted transfer
    3. A cut-over date after which new cards go to the new vault

    Free trial, sandbox or demo

    Run one real workflow end to end: send a link, submit as a client, review in the inbox and share a file out.

    Test with real staff: the people who answer the phone and chase documents will spot gaps that a polished demo hides.

    Pricing model

    Model your busiest month, especially if you are a seasonal business.

    • Seat-based: predictable for small teams with steady headcount
    • Per submission: suits low or uneven volume
    • By engagement: quoted around your workflow and volume

    Enigma Customer Vault: collect and share customer data securely

    Enigma Customer Vault replaces email, fax and shared drives with branded intake links your clients use without an account. Cards are tokenized at capture, files and signatures are encrypted with AES-256-GCM, and everything lands in a shared staff inbox and one customer profile, with every reveal logged. Staff sign in with passkeys and enforceable MFA, files go out through expiring links, and it all runs on PCI DSS Level 1 infrastructure with tenant isolation and a full audit log. Your team can go live the same day, and when engineering is ready, the same records are available through the API and signed webhooks. Request a demo of Enigma Customer Vault and stop collecting sensitive data through email.

    AK
    Abhilash Kumar Chief Growth Officer

    Abhilash Kumar is Chief Growth Officer at Enigma Vault, where he leads growth strategy, market positioning, and partnership development. He brings experience across B2B SaaS marketing, product marketing, brand building, and demand generation, with a career spanning technology companies and communications agencies.

    View full profile

    Frequently asked questions

    What is a customer vault ID?
    A customer vault ID is the unique reference a vault gives each customer record. Your systems store the ID and use it for later actions, so the card number or document never has to be stored or sent again.
    Can a customer vault store CVV?
    No. PCI DSS does not allow the card security code to be stored after authorization, even encrypted. A compliant vault stores the card number as a token and discards the CVV.
    Do customers need an account to submit data?
    Not with a well-designed intake vault. Customers open a secure link, submit what you asked for and leave, with no login to create.
    Can stored cards work with different payment providers?
    It depends on the vault. Gateway vaults usually tie cards to one processor, while independent vaults can forward card data to the processor you choose. Ask the vendor how cards reach your gateway.
    Can I move cards from another vault?
    Usually, yes, through a provider-to-provider transfer that follows PCI DSS. Both the current and new vendors must support it, so confirm the process before switching.
    Is a customer vault the same as a payment vault?
    Not always. A payment vault stores cards for charging, while a secure customer vault also collects IDs, documents, signatures and sensitive fields on one profile.