ZeroPII .
TM
Patent pending
A stack where nothing sensitive leaves your premise.
The problem
Every enterprise conversation opens the same way: “Can we orchestrate SMS, email, and WhatsApp without ever exposing our customers’ PII to your cloud?” And right behind it: “Can you deploy it on our premise?”
The market has two answers, and both are bad.
Approach 1 · Custom middleware
Build and maintain your own glue code.
Approach 2 · Plain-text callback
Host an API that returns PII on demand.
Your team writes middleware that fetches the email or phone, transforms payloads,and handshakes with every messaging provider for last-mile delivery. That defeats the entire point of buying a platform with hundreds of native integrations.
Meet ZeroPII
A lightweight agent that lives inside your boundary
Your PII never leaves your system. We build the agent, you only host it.
Zero PII Agent
We built it, you host it
Your PII API
SIngle or batch
Service Providers SMS, email, Whatsapp
Trust boundary — PII never crosses back to WebEngage
PII-free flow — all WebEngage ever sees
Carries PII — stays customer-side / goes to providers
ZeroPII in action
How a personalized send happens with ZeroPII
Say you’re a bank sending card-expiry reminders. With ZeroPII, see what leaves your network and what never does.
WebEngage
Segmentation, triggering and reporting
userId #8f2c41d9
trigger card_expiry_30d
event delivered 11:04
✓ no name, number or card, at any point
Zero PII Agent
Deployed and run by the bank. Holds nothing.
WAITING
Discarded
Removed from the event. Never stored.
+44 7700 900782
The bank's data store
Queried in place. Never replicated.
Emma
+44 7700 900782
482106
30 Nov 2026
The bank's SMS provider
The bank's existing provider. No new vendor.
Emma's phone
Hi Emma, your card ending 482106 expires on 30 Nov 2026. Renew in the app.
Emma
482106
30 Nov 2026
Template · built here
Hi {{first_name}}, your card ending {{last_6_digits}} expires on {{expiry_date}} . Renew in the app.
delivered 11:04
· to +44 7700 900782
+44 7700 900782
Build the campaign with personalization tokens
WebEngage creates the campaign for userId #8f2c41d9. Personal fields remain unresolved, so no personal data is held.
Three
zeros.
Infinite
Intelligence.
Full CDP intelligence, without your PII ever leaving your environment.
Built for Banking
Built for Insurance
Built for Healthcare
Built for Government
...and every sector where cloud CDPs are prohibited by law
One Agent In. Zero PII Out. Infinite Possibilities Open.
Raw PII lives on your premise and never crosses the line. What reaches WebEngage Cloud is only what the platform actually needs.
ZeroPII Engagement
The agent resolves an opaque ID to contact details locally, inside your firewall, at the moment of delivery.
Stays on your premise
- Email addresses and phone numbers
- The ID-to-contact mapping
- Last-mile handoff to your providers
Reaches WebEngage Cloud
- Campaign logic and scheduling
- Opaque IDs only
- Delivery status, PII stripped
ZeroPII Personalization
Balances, health codes and private IDs are fetched from your own User API and merged just-in-time, agent-side.
Stays on your premise
- Account balances and private identifiers
- Your User API responses
- The fully rendered message body
Reaches WebEngage Cloud
- Template structure
- Merge tag names, never their values
ZeroPII Retargeting
Audiences reach ad platforms as hashed identifiers, so your customer database is never exposed to build them.
Stays on your premise
- The raw customer database
- Plain-text identifiers
Reaches WebEngage Cloud
- Hashed identifiers
- Audience membership
ZeroPII Segmentation
The agent runs query logic on-premise against your entities and returns only the resolved result.
Stays on your premise
- PII-bearing records
- Query execution against your store
Reaches WebEngage Cloud
- Query definitions
- Resolved segment results, no PII records
ZeroPII Ingestion
Stays on your premise
- Raw PII-bearing events
- Fields you flag as sensitive
Reaches WebEngage Cloud
- Scrubbed, non-PII events
- The attributes you allow through