Secure
Mask, encrypt and secure data in motion; keep an encrypted, checksummed archive.
What you will do: protect sensitive fields before they leave PortX and keep a tamper-evident archive.
Telemetry carries secrets: user identifiers, addresses, tokens, payment data. PortX treats protection as part of routing, so the same policy that sends data to a destination decides what that destination is allowed to see.
Controls
- Mask — replace part or all of a field with a fixed pattern, so the value is unreadable but the event keeps its shape.
- Encrypt — encrypt a field or a whole event in motion, so only destinations holding the key can read it.
- Tokenize — replace a value with a token that can be mapped back under control, so analytics still group by the original value.
- Secure in motion — transport encryption between agents, gateways, nodes and destinations.
- Checksum archive — every archived chunk carries a checksum so changes are detectable; the archive itself can be encrypted.
Steps: protect a field
- Open the routing policy for the stream.
- Add a protection step, choose the field and the action: mask, encrypt or tokenize.
- For encryption and tokenization, select the key or token vault:
Key management: <placeholder>
- Preview on live events, then save. Destinations downstream of the step receive the protected value; the archive can keep the original if the policy says so.
Where to apply protection
Apply it as early as the policy allows — at the gateway for remote sites, at the node for everything else — so protected data is what travels and what is stored outside your control.
Related
Data handling across the platform, including replay of protected data, is described under Security and compliance: Data handling.
Next: Use cases
Verify with XPLG engineering before publishing.