Vaults & data isolation
A dedicated home for every type of sensitive data — with policies that follow it everywhere.
Purpose-built vault types
Dedicated vaults for PII, PHI, PCI, and credentials. Each ships with sensible defaults so you do not have to design isolation from scratch.
Logical & physical tenancy
Choose multi-tenant for speed, single-tenant for compliance, or hybrid for regulated workloads — without rewriting your integration.
Field-level schemas
Declare which fields are sensitive, what tokenization preserves, and how to redact for analytics. The schema enforces it everywhere.
Data residency
Pin a vault to a region — US, EU, UK, Canada, or APAC — so GDPR, DPDP, PIPL, and data-sovereignty rules are satisfied at the storage layer.
Workspace-scoped policies
Inherit policies from the workspace, override at the vault, refine at the field. Auditable from the bottom up, easy to reason about from the top down.