The credit reporting agency had a problem that sounded almost absurd: it needed to generate about 300 million tokens every minute. Its records covered more than 400 million consumers and roughly 180 billion credit card numbers. A Visa project required protection of sensitive information, but protecting it could not bring the machinery to a halt. The agency tried building a tokenization system itself. It could not meet the performance requirement.
- Protegrity replaces sensitive values with usable stand-ins, then governs who can reveal the originals.
- Its customers need protection across old systems, cloud warehouses and increasingly AI pipelines.
- The practical lesson: test performance, data relationships and permissions together.
According to Protegrity’s published case study, the agency evaluated vendors and selected its vaultless tokenization. The attraction was specific: meet the throughput requirement, reduce the infrastructure within PCI compliance scope, and establish protection that future analytics projects could use. The change of mind came from a failed performance test. Security had to work at the speed of the business.
That episode is a useful introduction to Protegrity. The company works on a peculiarly modern inconvenience: organizations possess information they would like to use, but distributing the original values creates obligations and exposure. A customer identifier might be indispensable for connecting records and entirely unnecessary for the analyst reading them. Protegrity makes that distinction operational.
The name can disappear. The relationship must survive.
Tokenization substitutes a different value for a sensitive one. Properly configured, the substitute retains enough consistency or structure for the surrounding software to keep working. A system can connect two records belonging to the same customer while the analyst sees a token instead of the customer’s identifier. Recovering the original becomes a separate, governed action.
Illustration, not an actual customer record. Consistency depends on configuration.
Protegrity’s distinctive implementation avoids the ever-growing lookup vault that stores pairs of original values and their tokens. Instead, its vaultless approach uses small, static token tables. The distinction matters when a protection service must scale across many systems: a growing vault adds storage, replication and lookup work. Removing that particular burden gives architects a different set of trade-offs.
There is useful flexibility in the details. Protegrity’s documentation describes token types for numbers, dates, email addresses and other formats. A configuration can preserve portions of an original value, such as the last four digits. These choices affect both usefulness and exposure. Preserving a familiar shape is convenient; deciding how much familiarity to retain is part of the design.
The grocer who wanted the cloud
Albertsons presents a less theatrical version of the same dilemma. The retailer wanted to move critical data to Microsoft Azure for personalized marketing, analytics and AI/ML initiatives. Its customer information included personally identifiable, health and payment data. Moving those records required a way to preserve their usefulness while controlling access to the originals.
The published architecture combined Protegrity tokenization with Denodo’s data virtualization. Sensitive values were protected upstream. Snowflake could hold tokenized data with the relationships needed for analysis, while Denodo helped provide role-based access to protected or detokenized information. Analysts could prepare result sets without granting everyone a general invitation to inspect cleartext.
“Protecting our customers’ PII data is essential.”Steve Etchelecu · Solution Architect, Albertsons
The interesting unit of progress is the workflow. Different participants can work on the same business problem with different views of the data. Albertsons’ example suggests a pattern other teams can copy: apply protection before downstream distribution, preserve the relationships the analysis needs, and make reveal permissions explicit. A cloud migration becomes easier to assess when these decisions are settled before the records travel.
A privacy problem older than the AI boom
Protegrity’s roots precede today’s model pipelines by decades. A 1999 Forbes account traced the business to Ulf Dahl’s work in Sweden in 1994 on software for municipal personal records. Names could be separated from sensitive information. By 1996, Protegrity had established itself in Stamford, in an office above a restaurant overlooking a marina. It is an unexpectedly agreeable setting for a company concerned with disagreeable disclosures.

Mattsson’s background included two decades at IBM. His public biography describes work in software development, research, architecture and security. That heritage helps explain the company’s attention to existing systems. Enterprise data protection has to meet databases, applications and infrastructure already in service, including systems whose replacement is a much larger undertaking than the security project.
The buyer owns a complicated estate
Protegrity occupies the enterprise data security market. Its customers include organizations in financial services, insurance, retail, healthcare and travel. Albertsons is a named example; the company also features Accelya. In a July 2024 interview, then-CEO Paul Mountford named Truist and Blue Cross Blue Shield and described a focus on Fortune 1000 and Fortune 2000 businesses.
The platform combines discovery, policies and protection methods including tokenization, encryption and masking. Its integrations extend to applications, cloud warehouses, analytics platforms and legacy infrastructure. Denodo and Cloudera partner pages provide concrete examples of that ecosystem. The expertise being sold includes knowing where protection belongs in a data architecture, and how access should behave after protection is applied.
Buyers can also consider products such as Thales CipherTrust and Fortanix Data Security Manager, alongside native platform controls. Protegrity’s case rests on field-level protection across a mixed estate and its vaultless approach. A fair comparison follows the actual data: which systems need coverage, which transformations preserve useful analysis, and where policy enforcement must occur. A feature list alone has limited predictive value.
The invoice has colleagues attached
Protegrity sells commercial software and associated services, support and training. A 2022 Forrester study commissioned by Protegrity modeled one large financial-services organization’s internal protection service. Its three-year, risk-adjusted present-value costs were approximately $8.57 million: $5.76 million for licensing and professional services, $2.11 million for development and ongoing management, and $697,000 for infrastructure and training.
2022 commissioned Forrester model. Risk-adjusted present values; rounding applies.
Forrester modeled 126% ROI and an eight-month payback. Those results belong to the study’s assumptions and customer situation, rather than a standard buyer outcome. The operating work matters: deployment, testing and staff. This was a service the organization had to run.
Now the records are talking to agents
The current range has three editions: AI Developer, AI Team and AI Enterprise. Developer Edition arrived in September 2025; Team Edition was announced as a technology preview that November. The free developer offering provides a containerized sandbox, SDKs and sample workflows for trying discovery and protection. The commercial editions address broader policy and deployment requirements.

The AI additions widen the job. Semantic guardrails evaluate prompt and output risks; discovery identifies sensitive entities in unstructured text. Anonymization and synthetic-data tools support preparation and testing. These capabilities let developers examine protection inside the workflow, where an identifier might appear in a message or log rather than a neatly labeled database column.
September 2026 updates concentrated on the journey from pilot to production: representative data, governance and the permissions of increasingly autonomous workflows. That is a plausible extension of the older business. As more software can retrieve and act on records, the question of which values it actually needs becomes harder to postpone.
Try the awkward case first
A useful evaluation starts with a small, representative pipeline. Test joins, identifier handling, allowed reveals, denied reveals and logs. Measure throughput where protection will actually run. Protegrity’s developer documentation makes experimentation accessible, while distinguishing its sandbox from a full production deployment. Tokenization and encryption API access require registration; several other experimental features can run without it.
The approach suits workflows where protected values retain the information needed for the task. It becomes a poor fit if transformation destroys essential meaning, if a downstream service requires original values but has no governed reveal path, or if integration and operating costs outweigh the intended use. Discovery and guardrails also need evaluation on realistic inputs. A successful sample prompt cannot establish coverage for an entire business.
The credit agency tested speed. Albertsons worked out who could see what. Together, they provide a more useful buying question than whether data is simply “secure”: can the people and systems doing the work finish their task with the protected version? Protegrity earns its place when the answer is yes.