Tokenisation changes what systems need to hold
The point is not encryption, it is removal.
An encrypted card number in your database is still a card number in your database, with the key somewhere nearby. A token is not the value at all and cannot be reversed without the vault. That is why tokenisation reduces compliance scope in a way encryption does not, and why the two keep being discussed as if they were alternatives to the same problem.
More on Data security
- Classification should change handlingThe label throws the points
- Data lineage explains where sensitive data travelsFollow the dye
- Data residency is not automatic securityThe line goes round the building
- Retention is a security controlWhat you no longer hold
- Data access logs need object contextRead a record. Which one?
- DLP can match data patterns but cannot reliably infer the business purpose of a transferIt reads the shape, not the reason
