Listing Thumbnail

    Card Vault API

     Info
    Deployed on AWS
    Store, tokenize, and process card data without touching it. Never worry again about storing card data securely.
    4.5

    Overview

    Store, tokenize, and process card data without touching it. You will significantly reduce your security risk and PCI compliance scope by vaulting your customer card data with Card Vault, a PCI level 1 compliant card storage and protection solution. Your customers will use our hosted forms to enter their card data and then your application will receive a token. Your application will then provide the token with your existing payment gateway info over to Card Vault and will process the card on your application's behalf. Never worry again about storing and processing card data securely.

    All of Enigma Vault's services, including Card Vault, are PCI Level 1 compliant. AOC is available on request.

    Highlights

    • Minimize your security risk
    • Reduce your PCI scope
    • Simplify card data security

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Card Vault API

     Info
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (3)

     Info
    Dimension
    Description
    Cost/month
    Overage cost
    Lite
    1,000 requests per month
    $0.00
    Plus
    20,000 requests per month
    $49.99
    Premium
    250,000 requests per month
    $249.99

    Vendor refund policy

    Please contact support

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Masking/Tokenization
    Top
    10
    In Masking/Tokenization
    Top
    100
    In Storage, Data Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Card Data Tokenization
    Converts card data into tokens that can be used in place of actual card information, eliminating the need to handle raw card data directly.
    PCI Level 1 Compliance
    Maintains PCI Level 1 compliance certification for card storage and processing operations.
    Hosted Payment Forms
    Provides hosted forms for secure card data entry by customers, keeping card information isolated from the merchant application.
    Token-Based Payment Processing
    Processes card payments using tokens instead of raw card data, allowing applications to submit tokens with payment gateway information to complete transactions.
    Reduced PCI Compliance Scope
    Minimizes the scope of PCI compliance requirements by centralizing card data storage and handling through a dedicated vault service.
    Tokenization and Data Protection
    Enterprise-grade encryption and tokenization technology that secures sensitive payment card data and personally identifiable information at the collection point using a resilient cell-based architecture.
    Processor-Neutral Integration
    Platform operates independently from payment processors and service providers, enabling interoperability across card networks, PSPs, and third-party providers through a single API or pass-through proxy service.
    PCI Compliance and Reduced Scope
    Achieves PCI DSS v4.0 compliance with strict access controls and security measures that minimize PCI compliance liability by externalizing sensitive card data from merchant systems.
    Card Network Direct Connectivity
    Direct connections with card networks including Visa and Mastercard to provide access to value-added network services such as Network Tokens, Account Updater, and Card Attributes.
    Centralized Card Lifecycle Management
    Unified platform for managing card data lifecycle events, card collection, protection, and secure exchange with integrated endpoints, supporting card acceptance and issuance use cases across multiple payment scenarios.
    Encryption and Tokenization
    Polymorphic encryption and tokenization engine that encrypts, tokenizes, and masks sensitive data at rest, in transit, and in use.
    Data Isolation
    Segregated, privileged-access environment that isolates sensitive data and eliminates sensitive data replication across infrastructure.
    Access Control and Governance
    Policy-based, role-based, and attribute-based access control to manage data visibility, control who sees what data, when, and where, with centralized management from one location.
    Compliance Framework Support
    Built-in support for GDPR, Schrems II, BDSG, PCI, HIPAA, and data residency requirements.
    Data Residency and Deployment Flexibility
    Ability to deploy the vault in specific geographic locations to satisfy data residency requirements without replicating entire infrastructure across regions.

    Contract

     Info
    Standard contract

    Customer reviews

    Ratings and reviews

     Info
    4.5
    9 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    78%
    22%
    0%
    0%
    0%
    3 AWS reviews
    |
    6 external reviews
    External reviews are from G2 .
    Pranay Jain

    Secure data handling has transformed how our team protects PII and simplifies compliance

    Reviewed on May 02, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Enigma Vault  for two years.

    We use Enigma Vault  for securely handling sensitive data in our application. Whenever we need to store the data of candidates and enterprises, mostly for the enterprises side, we store it in Enigma Vault. The main use case is to tokenize and encrypt sensitive data, such as the card details of enterprise users, so that the application never stores or processes raw data, ensuring security and compliance.

    For a specific example, whenever an enterprise user gets added to the application and wants to add 100 or more candidates, they have to pay some minimum amount. For payments, the user will add card details on the front end, but the back end will not store it directly. Instead, it will store it to Enigma Vault. Enigma Vault will perform the encryption of the card data and store it there, then return a token. My database only stores the token, not the actual card number. This approach is especially useful in microservices architecture where multiple services can safely use tokens instead of sharing sensitive data.

    My system never stores the raw card data, but even if my database is hacked, it will only contain the token. An attacker will only get the useless token. We have reduced our PCI DSS scope significantly.

    What is most valuable?

    The best features Enigma Vault offers are tokenization. It is one of the best features that it provides. Whenever we give any data to it, it has the capability to tokenize combined with strong encryption, which allows our application to operate without even storing the sensitive data. The second valuable feature is data isolation. The actual data is stored only inside the vault and not inside our databases, which is very beneficial because there can be different attacks that an attacker can do to get the data from the database. If database data is accessed by the attacker, it can be very harmful for us. The third feature is the built-in compliance. It helps us achieve PCI DSS, SOC 2, even without building complex security systems. The main thing fundamentally changes the architecture from storing and protecting data to never storing sensitive data at all, which is a much more secure approach.

    Tokenization is the feature I rely on the most during my day-to-day work because I don't need to store sensitive data, such as card numbers and PII numbers. Instead, I just need to store the random token, which is great for our application because tokens have no exploitable value. Even if the database is leaked, the data is safe.

    This feature fundamentally changes the architecture from storing and protecting data to never storing sensitive data, which is excellent. Another valuable capability is the ability to search and operate on encrypted data. If data is encrypted, you normally cannot search it, but Enigma Vault allows searching such as name, email, and phone without exposing the raw data.

    Enigma Vault has impacted my organization positively because right now we don't need to store the actual PII and credit card details of the enterprise users. The impact has been significant in terms of security, compliance, and development efficiency because we stopped storing sensitive card data and PII. We work in a European region where there are GDPR compliance requirements. The data of the enterprise users should not be shared with anyone and should be protected very carefully. Even in the case of a breach, only a token should be exposed. Reducing risk drastically is one of the major benefits. The second benefit is easier compliance. PCI DSS scope was reduced and audit effort is lessened. In our application, we have auditing logs, so every time there is a movement of anything, we need to audit that because we need to maintain all the history of the events that have happened. Auditing is reduced in this case because of the features that Enigma Vault provides. It saves time and has lower compliance costs. The third benefit is faster development. We don't need to build the encryption logic ourselves because it is already provided by Enigma Vault. We only need to focus on the business feature rather than security implementation.

    After using Enigma Vault, our security metrics have improved drastically. The exposure of sensitive data has reduced by 90 to 95 percent at the application level. The number of systems handling raw PII is reduced from multiple to zero. We don't need to store anything in our database. There are also improved compliance metrics. PCI audit scope reduced by 60 to 70 percent, and audit preparation time reduced from weeks to a few days. We have reduced sensitive data exposure almost completely, cut compliance effort by over 60 percent, and improved development speed by around 30 to 40 percent.

    What needs improvement?

    There are some improvements that can happen. Enigma Vault is strong in security and compliance, but there are a few areas that can be improved. Better observability and monitoring would be helpful. There is limited deep insight into tokenization failure and API latency breakdown. It can be improved by detailed dashboards, logs, and alerts, which can help in faster debugging and production monitoring. Another area is lower latency for high-scale systems. Every request goes through the vault APIs, which adds latency. In our application we have 1 million users at the candidate side and around 100,000 at the enterprise side. We have latency issues which we need to consider. Lower latencies for higher scale systems would be beneficial. Improvements could be made through edge-caching for the token. AWS  provides these kinds of services such as CloudFront, so we can use these to store the tokens in the caches. There could also be regional vault deployment, similar to what AWS  does.

    The APIs are good, but the development SDK support can be expanded a little because better documentation and examples would be helpful, especially for newer clients who are getting onboarded.

    Developer experience can be improved, and observability is another area. As a developer, I will get the APIs and everything which is provided by Enigma Vault, but the documentation that they have is a little too overwhelming for a newer developer. They are not able to understand it easily. Documentation is one thing that can be improved if a developer wants to start working on it.

    What do I think about the stability of the solution?

    I don't think there is much downtime or any reliability issues. Enigma Vault maintains 90 to 95 percent availability and is working fine for our application.

    What do I think about the scalability of the solution?

    Scalability-wise, Enigma Vault is very scalable. Because it is a pay-as-you-go structure, the more tokenization we need to generate, the more price we need to pay. It is an API-first SaaS platform that can handle increasing data volume and request load.

    How are customer service and support?

    Up until now we haven't needed customer service from a code perspective. We haven't used customer support because the APIs and tokenization are working quite well. The support was not needed so far.

    Which solution did I use previously and why did I switch?

    I did not use any different solution previously.

    How was the initial setup?

    The setup was pretty simple. The pricing is subscription-based because it is a SaaS model. It depends upon the usage that we have. Every time we make an API call and the tokens that are being created, that is the setup structure. Initially, the setup cost is very low because it is a pay-as-you-go structure. Initially, you don't need to pay a big sum. The licensing is tier-based licensing, such as basic, limited, and enterprise. We use the enterprise high-volume pro add-on feature, which has SLA guarantees, dedicated support, and compliance features.

    What was our ROI?

    Development cost has been reduced because we don't need to build our own encryption model. PII data that we need to store for European clients are very specific about GDPR compliance because if the data gets leaked, it is very hard for us to move that application into further stages. Encryption systems must be very good because the data cannot be accessed by attackers. We needed to protect our data significantly. For that, Enigma Vault has reduced the development cost. Approximately 30 percent of development cost can be reduced because we don't need to think about encryption designing. Compliance cost is also reduced.

    What's my experience with pricing, setup cost, and licensing?

    There is no big initial setup cost as it is a subscription-based SaaS model.

    Which other solutions did I evaluate?

    Previously, we did not use any other options, but I think HashiCorp Vault  was the one that our team discussed before using Enigma Vault.

    What other advice do I have?

    There are pros as well as cons, but the pros are highlighted more prominently. The strengths are top-level security, tokenization, and encryption. Enigma Vault has strong PCI DSS and SOC 2 compliance support. It has an API-first design, which is very beneficial for developers to understand and easy to integrate. It reduces the data risk almost completely. I would not give a perfect score because there are latency issues that have occurred previously and a dependency on external vault availability. A regional vault is not provided, so that can be an issue.

    If your product or application is in a country where PII information is very protected and the attacking is very brutal, for example, European clients have a structure where you cannot share the PII information with anyone. If that PII information gets shared by mistake, your application will be turned down by the government instantly, and you will not know what happened because their laws are very harsh in this situation. You need to protect your application from attackers. You need to store the data in some different place. Otherwise, it will cause so many issues at different levels that you will not know before the application is just turned off by the government. For that kind of situation, Enigma Vault is a great use. It has great usage and you can directly include it in your application to store the PII information. I would rate this product a 9 out of 10.

    reviewer2745723

    Customizable payment forms support complex transaction scenarios and impress with quick response times

    Reviewed on Jul 27, 2025
    Review from a verified AWS customer

    What is our primary use case?

    I use the solution to collect card data and forward it to a third-party payment processor.

    How has it helped my organization?

    The solution allowed us to implement a complex payment scenario.

    What is most valuable?

    The payment form can be customized in many ways.

    What needs improvement?

    I have nothing to say about areas for improvement.

    For how long have I used the solution?

    I have used the solution for one month.

    Which solution did I use previously and why did I switch?

    I did not use any previous solutions.

    What's my experience with pricing, setup cost, and licensing?

    The free tier allowed us to deeply test our integration.

    Which other solutions did I evaluate?

    I considered PCIVault. However, they do not offer a free trial or a free tier.

    What other advice do I have?

    Their support is great. They added my home language, Italian, in one hour and answered my questions almost immediately, even though I did not have a paid account.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Ivan M.

    Support is incredible. They added our domestic card and languages in less than 24h - ultra good.

    Reviewed on Mar 12, 2025
    Review provided by G2
    What do you like best about the product?
    Enigma Card Vault is far the best option for card tokenization we found. API is simplistic and easy to understand. There are no surprises regarding PCI-DSS de-scoping and you really end up with having responsibility for things you really use and need. They are also way more affordable than others. They added our domestic card and languages in less than 24h
    What do you dislike about the product?
    Their service perfect. We have no complains.
    What problems is the product solving and how is that benefiting you?
    PCI DSS Descoping. We have less responsibilities to meet in order of staying PCI DSS compliant when we use proxy vault token providers
    HOLEST

    Ultra good support and excelent product

    Reviewed on Mar 12, 2025
    Review from a verified AWS customer

    Support is incredible. They added our domestic card option and languages in less than 24h - ultra good.

    They are open to all suggestions.

    Also this is far the best option for card tokenization we found. API is simplistic and easy to understand. Thare are no surprises regarding PCI-DSS de-scoping and you realy end up with having responsibility for things you realy use and need.

    Aashir S.

    Best for Encryption and Tokenizing data

    Reviewed on Jun 13, 2023
    Review provided by G2
    What do you like best about the product?
    What I like the most about Enigma Vaults is encrypting and tokenizing data, Also I've had the best experience with my payment cards, and on top of that it encrypts and stores files from kilobytes to gigabytes in size I think that's quite impressive
    What do you dislike about the product?
    I would not say I have come across anything that I dislike about Enigma Vault so only a thumbs up from my side!
    What problems is the product solving and how is that benefiting you?
    These days with the type of online scams happening, I feel safer encrypting important details like my personal card data with Enigma vault. Plus I also find it quite user-friendly.
    View all reviews