---
title: How Vaultless Tokenization Works in Practice, to Transform Your Business
description: Learn how vaultless tokenization can transform PCI DSS 4.0 compliance into a business enabler while enhancing security and operational efficiency.
image: https://insights.comforte.com/hubfs/comforte%20AG_How%20Vaultless%20Tokenization%20Works%20in%20Practice%20to%20Transform%20Your%20Business_24.07.2025.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG - How Vaultless Tokenization Works in Practice, to Transform Your Business](https://insights.comforte.com/hubfs/comforte%20AG_How%20Vaultless%20Tokenization%20Works%20in%20Practice%20to%20Transform%20Your%20Business_24.07.2025.png)](https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business)

[Samuel Smalling](https://insights.comforte.com/author/samuel-smalling) l Jul 24, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss), [Compliance](https://insights.comforte.com/tag/compliance)

# How Vaultless Tokenization Works in Practice, to Transform Your Business

In last month’s [blog post](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en) we explained how vaultless tokenization can transform PCI DSS 4.0 compliance from a regulatory burden into a business enabler. Not only does vaultless tokenization reduce the scope and cost of compliance, but it also preserves data utility to support monetization, customer engagement and fraud prevention efforts. Furthermore, vaultless tokenization delivers a secure foundation for building new payment products, enriched GenAI models, and new revenue channels.

Now it’s time to understand how to make these business goals a reality. This is how comforte’s vaultless tokenization operates across a hybrid environment within a payments network:

**1- Ingestion and Entry**  
Cardholder data arrives over TLS (to confirm with PCI DSS 4.0) from web/mobile front-ends (e.g. Apache, Nginx). It then travels via client backend APIs and is stored in various datastores.

**2- On-Premises Tokenization & Storage**  
Comforte’s vaultless SecurDPS cluster integrates directly into the client’s data pipelines. It then issues format-preserving tokens for primary account numbers (PANs) through different transparent integrators such as SDKs (Java/.NET/C++), filesystem filters, REST APIs, Kafka connectors, and Virtual File System—minimizing the number of required code changes and data touchpoints.  
Operational & PII databases hold order logs and customer data. Although these are not directly subject to PCI DSS requirements, they would still need to be architected to meet specific compliance and security controls—like encryption at rest, network segmentation, and identity and access management (IAM). The client could consider deploying additional tokenization across these two database environments on a case-by-case basis to further reduce the risk of data exposure.

**3- Controlled Detokenization for Gateways**  
Detokenization calls let the client send cleartext PANs to payment gateways (e.g. ACI Worldwide) while adhering to strict IAM and audit policies. Once the data is received by the payment gateway, the gateway provider (e.g. ACI Worldwide) is responsible for protecting the PAN under PCI DSS 4.0.

**4- Protection Cluster Components**  
The Protection Cluster is the main component of SecurDPS—a centrally managed, scalable, and fault-tolerant cluster of virtual appliances that performs the actual protection operations. It consists of:

- The **Management Console** **(MC)** forms the heart of the Protection Cluster’s administration capabilities. It’s a hardened software node that securely houses all cluster configuration, encryption keys, and tokenization secrets. Upon startup, the MC injects this sensitive data into each Protection Node’s RAM (never to disk) to ensure that no secrets remain if a node is powered off. This design enforces in-memory-only key handling and all cluster operations—from policy updates to key rotations—flow through the MC under strict security controls.
- **Protection Nodes (PNs)** are the in-memory, stateless workers at the heart of the SecurDPS Protection Cluster. They provide high-performance, format-preserving tokenization or encryption for enterprise applications via transparent integrations or the SecurDPS API. Any number of PNs can be deployed across servers, data centers, cloud availability zones, and is even co-located with applications for optimal performance and minimal latency. This can all be done without writing data to disk. If a PN fails, the cluster automatically fails over to remaining nodes and self-heals by reinitializing the offline node to ensure uninterrupted protection and true fault-tolerance by design. SecurDPS’s Protection Cluster can be tightly integrated with a client’s existing Enterprise IAM to centralize user management, enforce granular Role-Based Access Control (RBAC), and produce end-to-end audit trails; the latter includes the actual user identity behind every tokenization or detokenization request.
- The **Audit Console (AC)** is an independent, scalable component—which can be run as a standalone or as its own cluster. It centralizes all usage metrics and audit streams from the Protection Nodes and Management Console. It ingests real-time log data via Kafka (as a message broker), then processes and forwards it through Logstash into OpenSearch (for storage and analytics) to present dashboards through OpenSearch Dashboards. Meanwhile, Rsyslog on each node captures and redirects syslog messages into this pipeline. By integrating seamlessly with the client’s existing SIEM, the AC delivers detailed, user-level visibility—showing counts of protection and reveal operations, failed authentications, and sensitive-data access patterns. This empowers security teams to monitor system health, detect anomalies, and satisfy compliance reporting requirements.

**5- Enterprise Analytics & ETL (On-Premises)**  
Enterprise on-premises applications such as SAP ECC, Power BI/Tableau, Salesforce, and Dynamics consume a blend of tokenized and cleartext data. By leveraging comforte’s tokenization and transparent integration capabilities, data protection and deprotection can occur in-flight across all flows—letting business applications run without friction while enforcing strong security where it’s needed most.

**6- Cloud Landing & Consumption**  
Tokenized (and encrypted) cardholder data and PII enter client cloud data stores (e.g. blob/S3/data lakes) via ETL pipelines. Any cloud-side detokenization routes back to on-premises SecurDPS under the same centrally defined IAM/audit guardrails.  
Downstream services could include Mailchimp for marketing, Looker/Tableau for BI, Sift/Riskified for anti-fraud, or Snowflake/Databricks/Vertex/SageMaker for AI/ML. They work exclusively on tokens or partially detokenized data, but any cleartext PAN needs to invoke the SecurDPS cluster and strict access controls.

**7- Hybrid & Deployment Flexibility**  
The comforte approach to vaultless tokenization has been designed to work seamlessly across a wide range of enterprise environments. Specifically, it:

- Supports SecurDPS clusters in both on-premises and cloud environments (Kubernetes, VMs, physical servers)—harmonizing tokens everywhere
- Features 10+ connectors/integration options—including SDKs, VFS, interpose, CASB, file/stream filters, Kafka, MQ, proxy, etc.
- Is deployable on-premises or via Kubernetes/Helm (hybrid or full-cloud) with minimal changes to application code or database schemas
- Offers cloud-native support for deployment on EKS, GKE, and AKS managed Kubernetes services

![comforte AG_CORPORATE DATA CENTER ON-PREM_Blog](https://insights.comforte.com/hs-fs/hubfs/comforte%20AG_CORPORATE%20DATA%20CENTER%20ON-PREM_Blog.png?width=785&height=439&name=comforte%20AG_CORPORATE%20DATA%20CENTER%20ON-PREM_Blog.png)

## Time to Transform

PCI DSS 4.0 compliance is often viewed by business leaders as a necessary evil. However, when done right, it can open the door to tremendous new business opportunities and revenue growth while simultaneously mitigating regulatory risk. The comforte approach to vaultless tokenization helps unlock the door to these opportunities, while offering a robust yet flexible architecture designed to work with a range of enterprise payment environments.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Learn how to discover, classify, and protect all sensitive data.

Click the button below to download the solution brief for our Data Security Platform:

[![Download Solution Brief](https://no-cache.hubspot.com/cta/default/4026697/65e094b1-44ae-496e-be17-1678a1876675.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/65e094b1-44ae-496e-be17-1678a1876675)

### Related posts

![Is PCI DSS 4.0 Slowing You Down? Here’s How comforte Can Accelerate Your PCI Compliance Journey](https://insights.comforte.com/hubfs/comforte%20AG_Is%20PCI%20DSS%204.0%20Slowing%20You%20Down_%20Heres%20How%20comforte%20Can%20Accelerate%20Your%20PCI%20Compliance%20Journey%20.png)

 Jun 26, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance)

### [Is PCI DSS 4.0 Slowing You Down? Here’s How comforte Can Accelerate Your PCI Compliance Journey](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en)

With the latest version of PCI DSS, the Payment Card Industry Security Standards Council (PCI SSC) aims to elevate the standards for cardholder data (CHD) security with themes like stronger cryptography, multi-factor authentication, and continuous...

[Read more](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en)

![The PCI DSS 4.0 Deadline Has Passed, But There’s Still Time to Play Catchup](https://insights.comforte.com/hubfs/comforte%20AG_The%20PCI%20DSS%204.0%20Deadline%20Has%20Passed_%20But%20There%E2%80%99s%20Still%20Time%20to%20Play%20Catchup.png)

 Apr 17, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance)

### [The PCI DSS 4.0 Deadline Has Passed, But There’s Still Time to Play Catchup](https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup?hsLang=en)

The deadline for PCI DSS 4.0 has been and gone. But it’s never too late to advance compliance plans. It’s not just about avoiding potentially large fines and other penalties. Following the standard to the letter helps ensure organizations are...

[Read more](https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>