Vault
Every piece of sensitive data, encrypted before it touches our database.
Stuut Shield tokenizes and encrypts PII — names, bank details, contact info — through a dedicated privacy vault built into the platform. Sensitive data never sits in plaintext. It's the same architectural approach as Salesforce Shield, purpose-built for accounts receivable security and compliance.
Control
You hold the keys. We literally can't see your data.
With Shield BYOK, your team manages the encryption keys — not Stuut. That means even our own engineers cannot access your PII without your explicit permission. Key rotation, access logs, and granular permissions are all in your hands.
Delete
Revoke the key. Data gone. Everywhere. Instantly.
When a customer requests data deletion — or when your policy requires it — revoke the encryption key. Every tokenized record becomes permanently unreadable. No manual scrubbing, no compliance gray areas, no hoping your vendor found every copy.
Comply
Security reviews answered before they're asked.
Shield gives your security team the answers procurement needs. SOC 2, GDPR, CCPA, HIPAA — instead of a 6-week back-and-forth, hand over the Shield architecture doc and watch the review cycle shrink. Key ownership closes the hardest questions upfront.




























