Protect before storage
The database stores protected data
Use identity and dataset policy to return cleartext, masked, tokenized, FPE-protected, or encrypted data across applications, APIs, databases, warehouses, BI tools, and streaming environments.
Request a DemoAccess request
Protected employee record
Real-time evaluation
Runtime data outcome
Authorized to process the full employee record
Needs to confirm the record, not read all fields
Authorized for analysis without exposing original identifiers
Receives only the fields and detail needed for its task
Protected once. Resolved differently at runtime for each identity.
Ubiq supports two methods for protecting sensitive data: protect it before it is stored, or protect it when it is accessed.
The database stores protected data
The database stores cleartext data
How it works
Before write: Ubiq encrypts or tokenizes selected fields before they are written to the database. Only the protected values are stored.
On read: Ubiq uses identity and policy to return cleartext, masked, tokenized, or encrypted values.
Before write: Data is written to the database unchanged.
On read: Ubiq uses identity and policy to return cleartext, masked, tokenized, or encrypted values.
Security impact
Protect before storage
If database credentials are stolen, an administrator accesses the tables directly, or a backup or export is exposed, the original protected values are not revealed.
Protect on access
Anyone who accesses the database directly, including a compromised administrator account or malicious insider, may still see the original sensitive data.
Operational impact
Protect before storage
Because protected values are stored in the database, stored procedures, searches, joins, reports, analytics, and downstream systems may need to be updated.
Protect on access
The stored data does not need to change. Existing stored procedures, searches, joins, reports, analytics, and downstream systems can continue operating on the original values.
Supported integrations
Protect before storage
Protect on access
When data is requested, the customer’s identity system establishes the requester. Ubiq evaluates the applicable dataset policy, transforms the data locally, and returns the permitted representation.
Use human or non-human identity as the policy input
Return cleartext, masked, tokenized, FPE-protected, or encrypted data
Apply the same policy model across supported integrations

Protection activity: Track protection and reveal operations across sensitive datasets.
Identity activity: See which human and non-human identities are accessing which data.
Security operations: Monitor anomalous activity and export audit data to existing security tools.
Protect before indexing: Ubiq protects sensitive source content and metadata before it enters the AI or RAG workflow.
Keep data protected: Stored vectors and associated data remain protected inside the customer’s environment.
Preserve search effectiveness: Vector similarity search continues to work in the protected space.
Apply policy before return: Ubiq uses identity and dataset policy to control the representation returned to the requesting AI system.
Protected vector data for RAG
Source content and embeddings remain protected
Sensitive source content
Images
Documents
Video
Audio
Protected embeddings
Similarity search works on protected data
Policy controls what the model receives
How it works

Answers
How Ubiq applies identity and dataset policy at the moment sensitive data is requested.
Runtime data protection controls the representation of sensitive data when it is requested. It is distinct from application runtime security, which focuses on protecting running software and workloads from threats.
The customer’s identity system establishes the requester. Ubiq evaluates the applicable dataset policy and returns the permitted representation of the data.
Ubiq can return authorized cleartext, dynamically masked data, tokenized data, format-preserving protected data, or encrypted data based on identity and policy.
Yes. Ubiq can encrypt or tokenize selected data before it is stored, or apply masking, tokenization, format-preserving protection, or encryption when cleartext data is accessed through a supported integration.

Platform
See how Sensitive Data Discovery, Enterprise Access Mapping, and Runtime Data Protection work together in one identity-driven platform.
Learn more
Product
Find sensitive data and see which identities and permissions are connected to it.
Learn more
Product
See how identities, IdP groups, Ubiq access groups, API keys, and sensitive datasets connect.
Learn moreSee how Ubiq applies identity-driven protection across applications, APIs, databases, warehouses, analytics, streaming, and AI workflows.
Request a Demo