Skip to main content
If you need Zeotap to receive PGP-encrypted files from your side, see PGP encryption in sources instead — this page covers the outbound (destination) direction.

What this is

PGP encryption on a Zeotap destination secures batch file delivery to your systems. You generate an asymmetric key pair on your side, upload the public half to Zeotap, and Zeotap encrypts each outbound file with that public key before writing it to your storage. Your side decrypts the file with the private key that never leaves your systems. The encryption setting is scoped per destination — you can turn PGP on where it is required and leave other destinations unencrypted.

Prerequisites

Before you configure PGP delivery, confirm the following:
  • The destination is a GCS or SFTP destination — file-level PGP is available for these two destination types.
  • You have generated an asymmetric key pair (public + private) on your side. Zeotap recommends the RSA algorithm.
  • You have exported the public key as an ASCII-armored file with the .asc extension. This is the file you will upload to Zeotap. Keep the private key on your side; never share it with Zeotap.
  • Your side has a PGP client that implements RFC 4880 (OpenPGP Message Format). For compatibility references, see Phil Zimmermann’s PGP directory; for Java implementations, see the Bouncy Castle interoperability documentation.
A valid ASCII-armored public key looks like this — the file you upload must begin with -----BEGIN PGP PUBLIC KEY BLOCK----- and end with -----END PGP PUBLIC KEY BLOCK-----:

Configure PGP encryption on a GCS or SFTP destination

Enabling PGP is an in-form step of the standard destination-creation flow — you opt in to encrypted delivery and attach your public key as part of configuring the destination.
The public key you upload determines which private key decrypts the outbound files. If you replace the uploaded public key later, files delivered afterwards can only be decrypted with the new matching private key — coordinate any rotation with the team that holds the private key so decryption does not break.
  1. Open the destination configuration form for a new or existing GCS or SFTP destination.
  2. Opt in to encrypted delivery for this destination. When the option is enabled, an additional field appears for uploading the public key.
  3. Upload your public key file. The file must be ASCII-armored and carry the .asc extension. The upload is scoped to this destination — other destinations remain unencrypted unless you enable PGP on them individually.
  4. Save the destination. From the next delivery onward, Zeotap encrypts every outbound file for this destination using the key you uploaded, before writing it to your GCS bucket or SFTP location.

Verify the encrypted delivery

After the next scheduled delivery to this destination, confirm on your side:
  • The file that lands in your GCS bucket or SFTP location is a PGP message — the header line reads -----BEGIN PGP MESSAGE-----, not readable CSV content.
  • Your PGP client decrypts the file with the matching private key and reproduces the original CSV without errors.
If both are true, the destination is delivering under PGP as configured.

Troubleshooting

Use this table to map an observed symptom to the check that resolves it.

FAQ

File-level PGP is available on GCS and SFTP destinations. Other destination types are out of scope for this mechanism.
Zeotap implements RFC 4880 (OpenPGP Message Format). RFC 9580, released in July 2024, has limited adoption across PGP clients and libraries — Zeotap has stayed on RFC 4880 for interoperability. Zeotap recommends both sides align on RFC 4880.
No — for the destination direction, you generate the key pair on your side, upload the public key to Zeotap, and keep the private key. Zeotap never sees the private key. For the inbound (source) direction the model is different: Zeotap CDP generates the key pair. See PGP encryption in sources.
The encryption setting is per destination, not per file. To send some flows encrypted and others in cleartext, configure two destinations pointing at different storage locations and enable PGP on one of them.

Next steps

Last modified on October 6, 2026