The data & PII pillar of the WiKey trust boundary. Sensitive data is tokenized before it ever reaches the agent, and detokenization happens server-side, outside the agent's control. So a phished agent — as in the M365 Copilot EchoLeak attack — leaks tokens, not records. The agent does the work without ever being able to use the data.
Hand an autonomous agent access to your systems and it becomes a liability in two ways — the keys it holds, and the data it sees. A prompt injection or a compromised model turns either into an exfiltration path. WiKey Data Tokenizer removes both so the agent can do the work without ever being able to use the data.
To reach your systems an agent is handed credentials — API keys, OAuth tokens, even the keys to the MCP gateway itself. A compromised or prompt-injected agent can pass those secrets straight to an attacker, who then holds standing access to everything.
Authentication is hardware-rooted and keyless — even access to the gateway. No key or password ever sits in the agent's context, so there's nothing to hand over.
The agent reads real records — names, emails, account numbers — into a cloud model. A buried instruction or a leaky tool turns the agent itself into a pipe that sends that PII straight to bad actors.
The agent only ever sees tokens. Real values stay inside the gateway and are rehydrated solely on an authorized write — so even a fully hijacked agent exfiltrates nothing but tokens.
Same root cause, one answer — one trust boundary: the agent holds no keys and no data, so it can't be tricked into using or leaking either.
WiKey ships its own open-source PII gateway — and even logging into it is keyless, so there's no credential to phish, even at the front door. Each agent gets its own tokenization vault that spans every source it touches — CRM, ERP, spreadsheets, warehouses — and authorized agents can cooperate to re-identify data that none of them could unlock alone. The agent only ever sees tokens.
Agents reach the gateway with no password or stored key to phish — authentication is hardware-rooted, nothing sits there to steal.
Each agent gets its own vault. Records from every connected source are tokenized into that agent's own token space.
The agent plans and acts over tokens only — across every source and sink it touches.
Authorized agents can combine to rehydrate values none could unlock alone; writes restore real data to the target system.
Tokenization is commodity. The difference is who is allowed to reverse it, and how that reversal is fenced off from the model.
Each agent has its own token vault, so values are restored only for authenticated agents — who can cooperate to re-identify what none could unlock alone.
The decrypt is a private step inside the gateway, not a tool the agent can call — so an injected prompt can't pull plaintext back into the model.
The gate can refuse the write itself. Decryption is bound to a scoped, allow-listed action and destination — not a blanket capability.
Every value written must resolve to a token the gateway issued. An unknown token aborts the write, and every re-identification is logged.
Every other product roots authority in a stored secret — a synced token, a backed-up key, a vault and its copy. WiKey removes it. Authority is unlocked only by a key generated inside hardware on the device: non-exportable, no escrow, no cloud sync. The gateway holds only public material — and even logging into it is keyless, so there's no credential to phish, even at the front door.
The NIST SP 800-63B property: a non-exportable authentication key. No stored secret to phish, no vault to breach, no backup to crack offline.
On new hardware, a threshold of recovery helpers — each holding only a share — re-derive the key through multi-party computation. Nothing is ever stored, yet authority returns.
WiKey provides the PII gateway itself — code and data flows fully inspectable. You deploy one system end to end, not a control plane bolted onto someone else's vault.
WiKey Data Tokenizer isn't a control plane you bolt onto someone else's vault. It's the whole path — an open-source PII gateway and a keyless, vault-less root of trust — delivered as one system you deploy, not a kit you assemble. It's the data & PII pillar of one trust boundary; the keys pillar (Agent Protect) keeps secrets out of the agent the same way.
WiKey provides its own open-source PII gateway — code and data flows fully inspectable. You don't source the data plane from a third party or wire it together yourself.
Open-source gateway, includedA hardware-bound key — with no backup and keyless access — decides who may re-identify and whether a write proceeds. The two planes ship together as one system.
WiKey root of trust| Approach to authority | Where the secret lives — the target |
|
|---|---|---|
| Token-vault identity layer Okta for AI Agents + Auth0 Token Vault |
Tokens and keys in a cloud-synced vault; commonly AAL2. | Non-exportable AAL3 key; no sync, no escrow. |
| KMS / HSM-managed keys | A key in a managed store; backup and export are policy, not physics. | Generated in-device and non-exportable; no backup by design. |
| Self-hosted vault inside the PII gateway |
The token map and its backup, on your own infrastructure. | No token store to hold; recovery via threshold MPC. |
| Data-vault gateway Skyflow, Protecto |
The vault is the product — and the highest-value target. | WiKey holds none, so a breach finds nothing. |
Put WiKey in the path and a phished agent leaks tokens, not records. Nothing to steal. Nothing to phish. Nothing to reset. Let's map it to your stack.
Talk to us