What this is
PGP encryption on a Zeotap destination secures batch file delivery to your systems. You generate an asymmetric key pair on your side, upload the public half to Zeotap, and Zeotap encrypts each outbound file with that public key before writing it to your storage. Your side decrypts the file with the private key that never leaves your systems. The encryption setting is scoped per destination — you can turn PGP on where it is required and leave other destinations unencrypted.Prerequisites
Before you configure PGP delivery, confirm the following:
- The destination is a GCS or SFTP destination — file-level PGP is available for these two destination types.
- You have generated an asymmetric key pair (public + private) on your side. Zeotap recommends the RSA algorithm.
- You have exported the public key as an ASCII-armored file with the
.ascextension. This is the file you will upload to Zeotap. Keep the private key on your side; never share it with Zeotap. - Your side has a PGP client that implements RFC 4880 (OpenPGP Message Format). For compatibility references, see Phil Zimmermann’s PGP directory; for Java implementations, see the Bouncy Castle interoperability documentation.
-----BEGIN PGP PUBLIC KEY BLOCK----- and end with -----END PGP PUBLIC KEY BLOCK-----:
Configure PGP encryption on a GCS or SFTP destination
Enabling PGP is an in-form step of the standard destination-creation flow — you opt in to encrypted delivery and attach your public key as part of configuring the destination.- Open the destination configuration form for a new or existing GCS or SFTP destination.
- Opt in to encrypted delivery for this destination. When the option is enabled, an additional field appears for uploading the public key.
-
Upload your public key file. The file must be ASCII-armored and carry the
.ascextension. The upload is scoped to this destination — other destinations remain unencrypted unless you enable PGP on them individually. - Save the destination. From the next delivery onward, Zeotap encrypts every outbound file for this destination using the key you uploaded, before writing it to your GCS bucket or SFTP location.
Verify the encrypted delivery
After the next scheduled delivery to this destination, confirm on your side:- The file that lands in your GCS bucket or SFTP location is a PGP message — the header line reads
-----BEGIN PGP MESSAGE-----, not readable CSV content. - Your PGP client decrypts the file with the matching private key and reproduces the original CSV without errors.
Troubleshooting
Use this table to map an observed symptom to the check that resolves it.FAQ
Which destinations support file-level PGP encryption?
Which destinations support file-level PGP encryption?
File-level PGP is available on GCS and SFTP destinations. Other destination types are out of scope for this mechanism.
Which OpenPGP version does Zeotap implement?
Which OpenPGP version does Zeotap implement?
Zeotap implements RFC 4880 (OpenPGP Message Format). RFC 9580, released in July 2024, has limited adoption across PGP clients and libraries — Zeotap has stayed on RFC 4880 for interoperability. Zeotap recommends both sides align on RFC 4880.
Does Zeotap generate the key pair for me?
Does Zeotap generate the key pair for me?
No — for the destination direction, you generate the key pair on your side, upload the public key to Zeotap, and keep the private key. Zeotap never sees the private key. For the inbound (source) direction the model is different: Zeotap CDP generates the key pair. See PGP encryption in sources.
Can I encrypt only some files going to a destination?
Can I encrypt only some files going to a destination?
The encryption setting is per destination, not per file. To send some flows encrypted and others in cleartext, configure two destinations pointing at different storage locations and enable PGP on one of them.