Control access to sensitive data: Ensure only authorized people, applications, service accounts, workloads, APIs, and AI agents receive the original value.
Protect sensitive data and control who can see it
Control what sensitive data each person, application, service account, workload, API, and AI agent receives based on identity and policy.
Request a DemoAccess request
Protected employee record
- Employee ID
- EMP-3X9Q-1182
- Name
- Maria Chen
- maria@acme.com
- Salary
- $142,800
Real-time evaluation
Runtime data outcome
HR app
CleartextAuthorized to process the full employee record
Support analyst
MaskedNeeds to confirm the record, not read all fields
Analytics API
TokenizedAuthorized for analysis without exposing original identifiers
AI agent
MaskedReceives only the fields and detail needed for its task
Same sensitive data. Different identities. Different outcomes.
Why use Ubiq Runtime Data Protection
Key Benefits
Reduce unnecessary cleartext exposure: Return masked, tokenized, format-preserving protected, or encrypted data when a user, service, or AI agent does not need cleartext.
Standardize protection across the enterprise: Apply one consistent protection model across applications, APIs, databases, data warehouses, analytics, and AI.

Two ways to protect sensitive data
Ubiq supports two methods for protecting sensitive data: protect it before it is stored, or protect it when it is accessed.
Protect before storage
The database stores protected data
Protect on access
The database stores cleartext data
How it works
Before write: Ubiq encrypts or tokenizes selected fields before they are written to the database. Only the protected values are stored.
On read: Ubiq uses identity and policy to return cleartext, masked, tokenized, or encrypted values.
Before write: Data is written to the database unchanged.
On read: Ubiq uses identity and policy to return cleartext, masked, tokenized, or encrypted values.
Security impact
Protect before storage
Protects the underlying data
If database credentials are stolen, an administrator accesses the tables directly, or a backup or export is exposed, the original protected values are not revealed.
Protect on access
The underlying data remains exposed
Anyone who accesses the database directly, including a compromised administrator account or malicious insider, may still see the original sensitive data.
Operational impact
Protect before storage
Because protected values are stored in the database, stored procedures, searches, joins, reports, analytics, and downstream systems may need to be updated.
Protect on access
The stored data does not need to change. Existing stored procedures, searches, joins, reports, analytics, and downstream systems can continue operating on the original values.
Supported integrations
Protect before storage
Protect on access
How identity-driven runtime data protection works
When sensitive data is requested by a person, application, service account, workload, API, or AI agent, the customer’s identity system establishes the requester. Ubiq applies the policy defined for the requested data and returns the authorized representation.

Identity-driven data outcomes: Return original, masked, tokenized, format-preserving protected, or encrypted data based on the person, application, service account, workload, API, or AI agent making the request.
Multiple protection methods: Apply dynamic masking, tokenization, format-preserving encryption, and field-level encryption to sensitive fields and records.
Flexible enforcement points: Protect data before storage or when it is accessed through applications, APIs, databases, data warehouses, analytics, and AI workflows.
Protect sensitive data used by AI and RAG workflows.
Protect before indexing: Ubiq protects sensitive source content and metadata before it enters the AI or RAG workflow.
Keep data protected: Stored vectors and associated data remain protected inside the customer’s environment.
Preserve search effectiveness: Vector similarity search continues to work in the protected space.
Apply policy before return: Ubiq uses identity and dataset policy to control the representation returned to the requesting AI system.
Protected vector data for RAG
Source content and embeddings remain protected
Sensitive source content
Images
Documents
Video
Audio
Protected embeddings
Similarity search works on protected data
Policy controls what the model receives
How it works
Answers
Runtime data protection questions
How Ubiq applies identity and dataset policy at the moment sensitive data is requested.
What is runtime data protection?
Runtime data protection controls the representation of sensitive data when it is requested. It is distinct from application runtime security, which focuses on protecting running software and workloads from threats.
How does Ubiq decide what data a requester receives?
The customer’s identity system establishes the requester. Ubiq evaluates the applicable dataset policy and returns the permitted representation of the data.
Which protection methods does Ubiq support at runtime?
Ubiq can return authorized cleartext, dynamically masked data, tokenized data, format-preserving protected data, or encrypted data based on identity and policy.
Can Ubiq protect data before storage and on access?
Yes. Ubiq can encrypt or tokenize selected data before it is stored, or apply masking, tokenization, format-preserving protection, or encryption when cleartext data is accessed through a supported integration.
Can Ubiq control what sensitive data AI agents receive?
Yes. AI agents can act as requesting identities. Ubiq applies the policy defined for the requested dataset or field and returns the authorized representation, such as masked, tokenized, format-preserving protected, encrypted, or authorized cleartext data.
Explore the Ubiq platform

Platform
Platform Overview
See how Sensitive Data Discovery & Classification, Access Intelligence, and Runtime Data Protection work together in one identity-driven platform.
Learn more
Product
Sensitive Data Discovery & Classification
Inventory supported sources, discover and classify sensitive data, record each finding’s location, and track changes over time.
Learn more
Product
Access Intelligence
Resolve effective permissions across human and non-human identities, groups, roles, policies, permissions, resources, and data.
Learn moreTokenize, mask, and encryptsensitive data based on identity.
See how Ubiq applies identity-driven protection across applications, APIs, databases, warehouses, analytics, streaming, and AI workflows.
Request a Demo