Vaultless Tokenization for LATAM Payment Systems
PCI DSS, LGPD, and ANPD SCC compliance for Pix, CoDi, and cross-border payment flows
Latin America has become the most government-built payment region in the world. Brazil’s Pix processes over 64 billion transactions per year and reaches 93 percent of Brazilian adults. Mexico’s CoDi is following the same instant-payment model on a slower curve. Across the region, neobanks expand multi-country sequentially from Brazil into Mexico, Mexico into Colombia, and Colombia into Argentina, with every border adding a new compliance regime.
LGPD changed the math for any platform handling Brazilian personal data. As of August 2025, Brazil’s Standard Contractual Clauses are mandatory for cross-border transfers. Vault-based tokenization architectures, which replicate sensitive data across jurisdictions to satisfy residency, now require an SCC for every replication path. Rixon’s vaultless, keyless architecture eliminates the underlying transfer entirely because there is no original data to move.
See how Rixon supports secure tokenization across multiple jurisdictions. Learn more →
Brazil — LGPD-aligned and SCC-ready
Rixon’s architecture is built for the regulatory reality LGPD created. The platform stores no sensitive data, holds no encryption keys, and operates in-region processing paths for Brazilian deployments. Detokenization is policy-bound, including by region, so original-data retrieval stays inside Brazil when required.
Rixon’s standard contractual clauses are aligned with ANPD Resolution CD/ANPD No. 19/2024 and the SCC template published in Annex II of that resolution. The architectural posture is that minimal cross-border transfer of personal data occurs in the first place: tokens move; original data does not.
LGPD + ANPD SCC
- No sensitive data stored
- No encryption keys
- Region-bound detokenization
What LGPD requires
Brazil’s Lei Geral de Proteção de Dados Pessoais (LGPD) governs the processing of personal data of individuals located in Brazil, regardless of where the operator is based. Key requirements that affect tokenization architecture:
Lawful basis for processing
Personal data may be processed only under one of ten legal bases. Payment processing typically relies on contract performance and legitimate interest.
Data subject rights
Access, rectification, deletion, portability, and information about international transfers. Vault architectures that replicate sensitive data across jurisdictions make these rights operationally harder to satisfy at scale.
International data transfer mechanisms
Following Resolution CD/ANPD No. 19/2024, transfers must rely on adequacy decisions, ANPD-approved SCCs, specific contractual clauses, or binding corporate rules. SCCs are currently the only practically usable mechanism for most operators. The compliance deadline was August 23, 2025.
Breach notification
ANPD and affected data subjects must be notified within a reasonable timeframe when a breach involves sensitive data. Rixon’s stateless model means there is no original sensitive data in Rixon’s environment to be breached.
How Rixon meets LGPD and ANPD SCC requirements
Rixon’s vaultless architecture changes the structure of the LGPD compliance problem. Three things follow from no stored data and no keys:
Minimal personal data transfer
Tokens are not personal data in the same operational sense as the original values they replace. Downstream systems that hold only tokens do not require direct access to original data and do not, by themselves, drive cross-border transfer obligations.
SCC posture is contractually simple
Where international transfer does occur, Rixon’s standard contractual clauses adopt the ANPD-approved SCC template in full. The clauses are not modified because ANPD does not permit modification, and they cover both controller-to-controller and controller-to-processor scenarios.
Audit trail satisfies accountability obligations
Every tokenization and detokenization request is logged with role, region, time, and policy context, supporting LGPD’s accountability principle and ANPD’s enforcement preferences.
Pix — the rail that defines Brazilian payments
Brazilian payments are no longer card-led. Pix processed 64 billion transactions in 2024, surpassing the combined Brazilian volumes of Visa and Mastercard. Roughly 175 million people, or 93 percent of Brazilian adults, use Pix. The Central Bank of Brazil mandated that all boletos include a Pix QR code, and Pix is expanding into Argentina through Mercado Pago for cross-border consumer use cases.
transactions in 2024
of Brazilian adults use Pix
Pix changes the tokenization model
The identifiers it uses, known as Pix keys, are CPF numbers, CNPJ numbers, email addresses, phone numbers, and randomly generated keys. These are personal data under LGPD. Protecting them is not optional. The card data tokenization model does not fully apply: Pix tokenization is about protecting the personal identifiers behind the rail, not Primary Account Numbers.
Common Pix key types
CPF
CNPJ
Phone
Random key
How Rixon handles Pix data
Rixon tokenizes Pix keys and the underlying personal identifiers using the same vaultless, keyless model that protects card data. Tokenization happens in real time at the point of capture, whether through an application API, payment workflow, or integration endpoint. Original values are not stored. Detokenization is policy-controlled so original Pix keys are revealed only at the points in a workflow that require them, such as settlement, reconciliation, or customer support, and only for the scope of that operation.
01
Capture
Application API, payment workflow, or integration endpoint
02
Tokenize
Real-time vaultless, keyless tokenization. Original values are not stored.
03
Controlled use
Policy-controlled detokenization for settlement, reconciliation, or customer support.
For payment platforms expanding Pix support, the practical outcome is reduced data residency scope. Systems that previously held Pix keys can hold only tokens. CPF and CNPJ exposure is eliminated from downstream processing, analytics, and storage. The LGPD attack surface shrinks measurably.
Mexico — the growth story
Mexico is the second-largest LATAM payments market and the natural expansion step for Brazilian neobanks. CoDi, the Bank of Mexico’s QR-based instant payment system, follows the Pix model on a slower adoption curve. Mexico also has the region’s deepest US cross-border payment relationship, which creates particular compliance complexity around personal data flowing both north and south.
What LFPDPPP requires
The Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) governs personal data processing in Mexico. Practical implications for payment tokenization:
Privacy notice and consent
Operators must publish a privacy notice describing data uses, retention, and transfer mechanisms. Consent is required for sensitive data.
Security obligations
Operators must implement administrative, technical, and physical security measures appropriate to the data they process. Tokenization is a recognized technical safeguard.
International transfer
Transfers to third parties, whether domestic or international, require consent or one of a defined set of exceptions. Architectures that minimize the transfer of original data reduce the operator's exposure to consent-failure scenarios.
INAI enforcement
Mexico's National Institute for Transparency, Access to Information and Personal Data Protection (INAI) enforces LFPDPPP and has issued meaningful fines for security and consent failures.
How Rixon supports Mexico deployments
Rixon supports in-region processing paths in Mexico and policy-controlled detokenization scoped to Mexican-residency requirements. For neobanks operating Brazil-to-Mexico expansion, the same Rixon integration covers both LGPD and LFPDPPP obligations. There is no need to deploy separate vault infrastructure per country, and no need to manage separate key lifecycles per jurisdiction.
What vaults break in LATAM
Vault-based tokenization was designed for a world where data could sit in a single central location. LATAM’s payment reality breaks that assumption in three specific ways:
Cross-border transfer compliance
Every vault replicated across borders is now an international data transfer under LGPD. Each transfer requires a complete ANPD-approved SCC, and the SCCs cannot be modified by the parties. Multi-country neobanks running vault-based tokenization face SCC documentation for every replica, every onward transfer, and every sub-processor. Rixon has no vault to replicate. Original data does not cross borders in the first place.
Pix and CoDi were not built for vaults
Instant payment systems run at scale that vault lookups cannot match. The Central Bank of Brazil's Pix infrastructure settles transactions in seconds, around the clock, with no business-hours dependency. Vault round-trips add latency that erodes the Pix value proposition. Rixon's tokenization and detokenization run at sub-millisecond latency without any vault round trip.
Multi-country expansion drag
A Brazilian neobank expanding into Mexico, Colombia, and Argentina under a vault-based model deploys per-country vault infrastructure, per-country key management, per-country audit boundaries, and per-country SCCs for every cross-border flow. Compliance overhead compounds with each market entry. Rixon's single integration covers the full LATAM expansion path.
Vaultless architecture
Traditional vault architecture
Sensitive data stored
Regional vault instances
Encryption keys + HSMs
Cross-border replication
SCC obligations
Rixon vaultless architecture
Tokenize in real time
No stored sensitive data
No encryption keys
Region-bound detokenization
Original data stays where required
Rixon removes all four. There is no vault to replicate, no key to manage, no round trip to a central store, and no sensitive data crossing borders as part of normal tokenization operations. The architecture is stateless by design. Tokenization happens at the application layer, and detokenization is governed by policy, including region, role, purpose, and time.
Compliance coverage across LATAM
Rixon’s architecture aligns with the principal LATAM data protection regimes affecting payment systems.
BRAZIL
LGPD with ANPD SCC alignment. In-region processing, region-bound detokenization, ANPD-approved SCC template adopted for international transfer scenarios.
MEXICO
LFPDPPP. In-region processing supported, privacy-notice compatible, consent-controlled detokenization paths, INAI-aligned audit trail.
ARGENTINA
Personal Data Protection Law (Ley 25.326). Sensitive data minimization through removal, consent-controlled processing.
COLOMBIA
Statutory Law 1581/2012 and Law 1266/2008. Habeas data principles supported through policy-controlled detokenization and audit trail.
CHILE
Law 19.628 and the new data protection framework. Removal of sensitive data from processing systems aligns with the modernized framework’s accountability requirements.
PERU
Law 29733. Same model: minimize storage, control access by policy, log everything.
PCI DSS 4.0.1 applies across the region for any payment card data handling. Rixon can reduce PCI scope by up to 70 percent by removing card data from in-scope systems
- NO VAULT
- NO KEYS
- NO STORED DATA
- POLICY-BOUND
Vaultless vs. encryption and FPE in LATAM
Encryption and Format-Preserving Encryption protect data by making it unreadable without a key. That is useful, but it does not remove the data from scope. Encrypted personal data is still personal data under LGPD. Encrypted cardholder data is still in PCI DSS scope. And encryption keys create their own management, rotation, and residency obligations.
ENCRYPTION • FPE • VAULT-BASED TOKENIZATION
Protected or tokenized, but still dependent on infrastructure
Encryption keys required
Sensitive data remains present
Key rotation and HSM infrastructure
Residency obligations remain
Vault-based tokens require stored original data
PCI DSS and LGPD scope remain
RIXON VAULTLESS TOKENIZATION
Remove the data from the problem
No encryption keys
No stored sensitive data
No vault infrastructure
No key rotation
Policy-controlled detokenization
Rixon takes a different approach. There is no encryption key because there is no encrypted sensitive data. The token is not a ciphertext. It is a non-reversible, format-preserving substitute generated without a stored mapping.. There is nothing to decrypt, nothing to rotate, and no key to compromise.
Under PCI DSS 4.0.1, tokens generated by a properly implemented vaultless tokenization system are out of scope for most cardholder data environment (CDE) controls, provided the tokenization system itself meets the standard’s requirements.
What that means in practice
BRAZIL / LGPD
For Brazil, this distinction matters. FPE-protected CPF data is still personal data and still subject to LGPD transfer requirements. A Rixon token representing a CPF does not contain the CPF, cannot be reversed without Rixon’s policy-controlled detokenization path, and can move across systems without moving the underlying personal data.
PIX
For Pix, the same applies to Pix keys. Tokenized CPF, CNPJ, email, and phone identifiers can move through payment workflows without exposing the original values to every system in the chain.
PCI DSS
For PCI DSS, vaultless tokens remove cardholder data from downstream systems entirely, reducing the cardholder data environment rather than merely encrypting it.
Architecture at a glance
Sensitive data enters Rixon through API endpoints, application integrations, or payment workflows. This includes card data, Pix keys, CPF and CNPJ identifiers, and any other personal data the operator chooses to protect. The tokenization operation produces an irreversible token in real time without storing the original value.
01
Data enters
API, application, or payment workflow
02
Tokenize
Irreversible token generated in real time
03
Token moves
Downstream systems use the token
04
Detokenization
Original value requested when required
05
Policy check
Request evaluated against security policy
06
Controlled return
Original value returned for one operation
When a downstream system needs the original value to submit a Pix transaction, settle a card payment, run a fraud check, or service a data subject access request, it requests detokenization through Rixon. The request is evaluated against the configured security policy: role, device, region, time window, and any other policy attribute. If permitted, the original value is returned for the scope of that single operation. The original value is never persisted in Rixon’s environment.
POLICY-CONTROLLED DETOKENIZATION
ROLE
DEVICE
REGION
TIME WINDOW
OTHER POLICY ATTRIBUTES
Cloud-native, auto-scaling, 99.999 percent uptime. No HSMs to provision. No vault clusters to operate. No key lifecycle to manage. No per-country vault replication to document under SCCs.
99.999%
UPTIME
NO HSMs
NO VAULT CLUSTERS
NO KEY LIFECYCLE
When LATAM payment teams should evaluate Rixon
Rixon fits payment platforms, fintech infrastructure providers, neobanks, mobile wallets, payroll platforms, and merchants operating in LATAM where any of the following are true:
Brazilian operations need a vaultless architecture that minimizes cross-border data transfer subject to ANPD SCC obligations
Pix integration requires real-time protection of CPF, CNPJ, and Pix key data without slowing the rail
Multi-country expansion (Brazil → Mexico → Colombia → Argentina) is creating per-country compliance overhead
PCI DSS scope reduction is a measurable budget priority alongside LGPD obligations
Existing tokenization is vault-based, with replication paths now requiring SCC documentation for every jurisdiction
- PAYMENT PLATFORMS
- FINTECH INFRASTRUCTURE
- NEOBANKS
- MOBILE WALLETS
- PAYROLL PLATFORMS
- MERCHANTS
Regional partners and managed service providers
LATAM payment buyers increasingly procure compliance architecture through regional MSPs, system integrators, and managed security partners. The reasons are practical: a single regional MSP can support the same neobank as it expands from Brazil into Mexico, Colombia, and Argentina, eliminating per-country vendor sprawl. Rixon is built to embed inside those partner stacks.
Why Rixon fits the LATAM MSP model
Vault-based tokenization makes MSP economics worse with every new market the partner’s client enters. Each new jurisdiction means another vault, another key lifecycle, another SCC bundle. The MSP’s margin shrinks while the operational burden grows. Differentiation against the next regional MSP disappears.
VAULT
KEY LIFECYCLE
SCC BUNDLE
Rixon’s vaultless, keyless architecture removes that burden. MSPs deploy a single tokenization layer that operates across LGPD, LFPDPPP, Argentine law, Colombian habeas data principles, and PCI DSS 4.0.1 simultaneously, without standing up per-country vaults. The partner keeps the operational margin. The downstream client gets a compliance posture that scales with its expansion.
What partnering with Rixon looks like in LATAM
Integration model.
API-first, drops into existing payment and security stacks without architectural rework. No vault clusters or HSMs to deploy on the partner's side.
Multi-country by default.
One integration covers LGPD in Brazil, LFPDPPP in Mexico, and the data protection regimes of Argentina, Colombia, Chile, and Peru.
SCC and compliance coverage as a sales tool.
Partners can present LGPD-aligned, SCC-ready architecture as part of their own value proposition without engineering it themselves.
Margin model.
Partner economics built for resale and embedded use cases. Pricing is volume-scaled rather than vault-infrastructure-scaled, which preserves margin as the partner's client base grows.
Pix and CoDi handled natively.
Partners can deliver Pix key protection and CoDi tokenization without separate engineering work per rail.
Who this fits in LATAM
Rixon is built for the partners helping financial institutions, fintechs, and payment providers expand across Latin America. These are the teams that benefit most from a single, scalable tokenization architecture.
Regional MSPs
Regional MSPs serving neobanks in multi-country expansion paths (Brazil → Mexico → Colombia → Argentina)
Brazilian system integrators
Brazilian system integrators with banking and fintech clients moving to vaultless architectures
Mexican + Colombian MSPs
Mexican and Colombian managed security providers expanding into payment infrastructure work
Payment infrastructure operators
Payment infrastructure operators looking to embed tokenization as a value layer for downstream fintechs across LATAM
FAQ
Yes. Rixon stores no sensitive data and holds no encryption keys, which removes the most common LGPD exposure surfaces. The platform supports in-region processing paths for Brazilian deployments and policy-controlled detokenization scoped to Brazilian residency requirements. Rixon’s standard contractual clauses adopt the ANPD-approved SCC template from Resolution CD/ANPD No. 19/2024 without modification.
Rixon’s contractual posture incorporates the ANPD-approved SCC template published in Annex II of Resolution CD/ANPD No. 19/2024. The architectural posture is that minimal cross-border transfer of personal data occurs in the first place — tokens move, original data does not — which reduces the operational scope of SCC obligations. Token classification under LGPD and applicable SCC scope should be confirmed with local legal counsel for a specific deployment.
Yes. Rixon tokenizes Pix keys, CPF numbers, CNPJ numbers, email-based Pix keys, phone-based Pix keys, randomly generated Pix keys, and any other personal data the operator chooses to protect. Tokenization happens in real time at the point of capture and detokenization is policy-controlled.
Yes. Rixon supports in-region processing paths in Mexico and policy-controlled detokenization scoped to Mexican-residency requirements. The same Rixon integration covers both LGPD in Brazil and LFPDPPP in Mexico, which simplifies multi-country neobank expansion.
A single Rixon integration covers LGPD, LFPDPPP, and the data protection regimes of Argentina, Colombia, Chile, and Peru. There is no need to deploy separate vault infrastructure per country, no per-country key lifecycle to manage, and no per-replica SCC documentation overhead, because Rixon has no vault to replicate.
Rixon removes cardholder data from systems that previously stored or processed it. Systems that no longer touch cardholder data can move out of the cardholder data environment for PCI assessment. Deployments have achieved up to 70 percent scope reduction.
No. Encryption and format-preserving encryption transform data using a key that can be stolen, rotated, or mismanaged. Encrypted personal data is still personal data under LGPD. Rixon’s vaultless tokenization generates an irreversible token without keys and without storing the original value. Detokenization is policy-controlled retrieval, not key decryption.
Rixon’s platform processes up to 2.5 million transactions per second at sub-millisecond latency with 99.999 percent uptime. There are no vault lookups in the transaction path, so performance does not degrade under peak load — including Pix-scale instant payment volume.
Yes. Rixon is built to embed inside managed service providers, system integrators, and managed security partners serving neobanks, fintechs, and banks across LATAM. A single Rixon integration covers LGPD, LFPDPPP, and the principal LATAM data protection regimes simultaneously, without requiring partners to operate jurisdiction-specific vault infrastructure.
See how Rixon handles LGPD, ANPD SCCs, and Pix in a single architecture.
A 20-minute call with a Rixon engineer. We will walk through your residency, throughput, scope-reduction, and SCC posture requirements.