Tokenisation
Replacing a sensitive value with a meaningless surrogate, where the mapping back is held in a separate, tightly controlled vault.
Tokenisation is often confused with encryption, and the distinction has a direct architectural consequence. Encryption is a mathematical transformation reversible with the key, so the ciphertext still carries the data and anyone holding the key can recover it. A token carries no mathematical relationship to the original, so recovery is only possible through a lookup in the vault.
The consequence that makes it valuable is scope reduction. Under PCI DSS, systems handling card numbers fall in audit scope; systems handling tokens generally do not, because compromising them yields nothing without the vault. An architecture that tokenises at the edge can therefore shrink the audited estate from hundreds of systems to a handful, which is a very large cost and risk reduction and is the usual business case.
Format-preserving tokens matter more than they sound: a token that looks like a card number passes existing field validation and schema constraints, so downstream systems do not need rewriting.
The trade-offs to design around: the vault becomes a critical dependency with its own availability and disaster recovery requirements, and it is now the highest-value target in the estate. Analytics also becomes constrained — you cannot join or analyse on a randomly tokenised field unless the tokenisation is deterministic, and deterministic tokens are vulnerable to correlation and frequency analysis. That trade needs deciding per field rather than globally.