Tokenize, mask, or encrypt data based on identity

Use identity and dataset policy to return cleartext, masked, tokenized, FPE-protected, or encrypted data across applications, APIs, databases, warehouses, BI tools, and streaming environments.

Request a Demo

Access request

HR app
Support analyst
Analytics API
AI agent

Protected employee record

Employee ID
EMP-3X9Q-1182
Name
Maria Chen
Email
maria@acme.com
Salary
$142,800

Real-time evaluation

Ubiq
Identity
Context
Policy

Runtime data outcome

HR app

Cleartext

Authorized to process the full employee record

EMP-3X9Q-1182Maria Chenmaria@acme.com$142,800

Support analyst

Masked

Needs to confirm the record, not read all fields

EMP-••••-1182Maria Chenm••••@acme.com$•••,•••

Analytics API

Tokenized

Authorized for analysis without exposing original identifiers

EMP-7K2M-4830Qenva Xltpx7kq2m9p@t4v8x.com$618,492

AI agent

Masked

Receives only the fields and detail needed for its task

EMP-••••-1182M•••• C•••m••••@acme.com$•••,•••

Protected once. Resolved differently at runtime for each identity.

Two ways to protect sensitive data

Ubiq supports two methods for protecting sensitive data: protect it before it is stored, or protect it when it is accessed.

Protect before storage

The database stores protected data

Name
SSN
Secret passphrase
Maria Chen
9@8-%4-57!6
A7K9-Q2M4-X8P1
David Garcia
6#1-3$-24^5
M5R2-T9L8-B3C7
Natalie Brooks
2*4-6!-95&1
X4N7-P1D6-K9V2
Jason Wells
7?5-1+-46=9
Q8W3-Z6H1-R4M9
Melissa Moore
1/6-5_-80~4
L2C8-Y5T1-N7F4

Protect on access

The database stores cleartext data

Name
SSN
Secret passphrase
Maria Chen
415-82-1182
blue-ocean-harbor
David Garcia
312-74-6034
maple-river-stone
Natalie Brooks
646-57-8246
silver-forest-light
Jason Wells
202-24-1907
ember-cloud-garden
Melissa Moore
718-63-4189
autumn-lake-moon

How it works

Before write: Ubiq encrypts or tokenizes selected fields before they are written to the database. Only the protected values are stored.

On read: Ubiq uses identity and policy to return cleartext, masked, tokenized, or encrypted values.

Before write: Data is written to the database unchanged.

On read: Ubiq uses identity and policy to return cleartext, masked, tokenized, or encrypted values.

Security impact

Protect before storage

Protects the underlying data

If database credentials are stolen, an administrator accesses the tables directly, or a backup or export is exposed, the original protected values are not revealed.

Protect on access

The underlying data remains exposed

Anyone who accesses the database directly, including a compromised administrator account or malicious insider, may still see the original sensitive data.

Operational impact

Protect before storage

Because protected values are stored in the database, stored procedures, searches, joins, reports, analytics, and downstream systems may need to be updated.

Protect on access

The stored data does not need to change. Existing stored procedures, searches, joins, reports, analytics, and downstream systems can continue operating on the original values.

Supported integrations

Protect before storage

ApplicationsDatabasesData warehousesAPI gateways

Protect on access

ApplicationsAnalytics / BIAPI gateways
Explore all integrations

How identity-driven runtime data protection works

When data is requested, the customer’s identity system establishes the requester. Ubiq evaluates the applicable dataset policy, transforms the data locally, and returns the permitted representation.

  • Use human or non-human identity as the policy input

  • Return cleartext, masked, tokenized, FPE-protected, or encrypted data

  • Apply the same policy model across supported integrations

Ubiq runtime data evaluation workflowFive stages connect access requests through local data access points and Ubiq runtime evaluation to cleartext, tokenized, or masked data outcomes.1Access requestinitiated2Request reacheslocal data access point3Ubiq validates identity,context, and policy4Ubiq transformsdata locally5Policy-appropriateresult is returned andrecordedACCESS REQUESTDATA ACCESS LAYERRUNTIME DATA OUTCOMEHR appAnalytics APIAI agentApplicationUDatabaseUMCP /AI WorkflowUUbiqRuntime evaluationIdentityContextPolicyHR appCleartextAuthorized to processthe full employee recordEMP-3X98-1182Maria Chenmaria@acme.com$142,000Analytics APITokenizedAuthorized for analysiswithout exposingoriginal identifiersEMP-7K2M-4830Qenva Xitpx7K2mPng@ub1k.com$618,492AI agentMaskedReceives only the fieldsand detail needed forits taskEMP-0•••-1182M••• C•••m••••@acme.com$•••,•••Identity contextOkta, Entra, application,or workload identityDataset policyField- anddataset-level policy
Ubiq dashboard showing protected data activity, identities, datasets, and anomalous events
Key Features
  • Protection activity: Track protection and reveal operations across sensitive datasets.

  • Identity activity: See which human and non-human identities are accessing which data.

  • Security operations: Monitor anomalous activity and export audit data to existing security tools.

Advanced Feature

Protect sensitive data used by AI and RAG workflows.

  • Protect before indexing: Ubiq protects sensitive source content and metadata before it enters the AI or RAG workflow.

  • Keep data protected: Stored vectors and associated data remain protected inside the customer’s environment.

  • Preserve search effectiveness: Vector similarity search continues to work in the protected space.

  • Apply policy before return: Ubiq uses identity and dataset policy to control the representation returned to the requesting AI system.

Explore RAG security

How it works

Six-stage Ubiq AI and RAG data protection workflow with protected vector and data lanes, identity and policy evaluation, and approved outcomes

Answers

Runtime data protection questions

How Ubiq applies identity and dataset policy at the moment sensitive data is requested.

What is runtime data protection?

Runtime data protection controls the representation of sensitive data when it is requested. It is distinct from application runtime security, which focuses on protecting running software and workloads from threats.

How does Ubiq decide what data a requester receives?

The customer’s identity system establishes the requester. Ubiq evaluates the applicable dataset policy and returns the permitted representation of the data.

Which protection methods does Ubiq support at runtime?

Ubiq can return authorized cleartext, dynamically masked data, tokenized data, format-preserving protected data, or encrypted data based on identity and policy.

Can Ubiq protect data before storage and on access?

Yes. Ubiq can encrypt or tokenize selected data before it is stored, or apply masking, tokenization, format-preserving protection, or encryption when cleartext data is accessed through a supported integration.

Tokenize, mask, and encryptsensitive data based on identity.

See how Ubiq applies identity-driven protection across applications, APIs, databases, warehouses, analytics, streaming, and AI workflows.

Request a Demo