Secure

Mask, encrypt and secure data in motion; keep an encrypted, checksummed archive.

What you will do: protect sensitive fields before they leave PortX and keep a tamper-evident archive.

Telemetry carries secrets: user identifiers, addresses, tokens, payment data. PortX treats protection as part of routing, so the same policy that sends data to a destination decides what that destination is allowed to see.

Controls

  • Mask — replace part or all of a field with a fixed pattern, so the value is unreadable but the event keeps its shape.
  • Encrypt — encrypt a field or a whole event in motion, so only destinations holding the key can read it.
  • Tokenize — replace a value with a token that can be mapped back under control, so analytics still group by the original value.
  • Secure in motion — transport encryption between agents, gateways, nodes and destinations.
  • Checksum archive — every archived chunk carries a checksum so changes are detectable; the archive itself can be encrypted.

Steps: protect a field

  1. Open the routing policy for the stream.
  2. Add a protection step, choose the field and the action: mask, encrypt or tokenize.
  3. For encryption and tokenization, select the key or token vault:
Key management: <placeholder>
  1. Preview on live events, then save. Destinations downstream of the step receive the protected value; the archive can keep the original if the policy says so.

Where to apply protection

Apply it as early as the policy allows — at the gateway for remote sites, at the node for everything else — so protected data is what travels and what is stored outside your control.

Data handling across the platform, including replay of protected data, is described under Security and compliance: Data handling.

Next: Use cases

Verify with XPLG engineering before publishing.