Data handling
Mask, encrypt and tokenize sensitive data in motion; keep a checksummed archive; replay on demand.
What you will do: decide how each class of sensitive data is treated before it leaves your control, and know how the archive and replay keep it recoverable.
The platform lets you decide, per field and per destination, whether sensitive data travels as is, masked, encrypted or tokenized, and keeps a verifiable full copy under your control.
Three treatments for sensitive data
- Mask — the value is replaced by a fixed pattern. Use it where the destination only needs to know that a value existed, for example a card number in a payment log sent to observability.
- Encrypt — the value is encrypted with a key you manage; only destinations holding the key can read it. Use it where a destination must be able to recover the value under control.
- Tokenize — the value is replaced by a consistent token, so analytics can still count and group by it without seeing it. Use it for user identifiers in shared platforms.
The treatment is applied in motion by a routing policy, as early as the topology allows; see Secure.
Checksum archive
The archive/cold tier keeps the full-fidelity copy of every stream in low-cost storage. Each archived chunk carries a checksum, so any change after writing is detectable. The archive can be encrypted at rest with your keys.
Checksum algorithm: <placeholder> Archive encryption: <placeholder>
Replay on demand
Archived data can be replayed into any destination for a chosen stream and time range — for an investigation, an audit request or to fill a gap after a destination outage. Replayed events pass through the same policy, so protected fields stay protected unless an operator with the right to do so changes the policy for that replay.
Steps: classify and apply
- List the fields in your streams that contain personal data, secrets or regulated information.
- For each, pick mask, encrypt or tokenize per destination class: observability, SIEM, archive, third parties.
- Implement the choices in the routing policies and preview on live events.
- Record the decisions; the policy history and the workspace audit log provide the evidence.
Data sent to dock
A registered deployment sends metadata and usage counters to dock — product, version, environment, GB/day, streams, XMC AI tokens — not the content of your streams.
Next: How licensing works
Verify with XPLG engineering before publishing.