Skip to main content

What this is

PGP (Pretty Good Privacy) encryption is an option available when you create a batch file-based Zeotap CDP source — flat file sources such as Zeotap Google Cloud Storage and SFTP (Push). When enabled, Zeotap CDP generates a public/private key pair for your account: you encrypt files locally with the public key, upload them to the source’s storage location, and Zeotap CDP decrypts them with the matching private key before queuing them for ingestion. This page explains how the flow works, how to turn it on for a source, and how to confirm that encrypted uploads are being decrypted and ingested.

Prerequisites

Before turning on PGP encryption for a source, confirm:
  • You have permission in Zeotap CDP to create or edit a Source.
  • The source you are creating is a batch file-based type that exposes the PGP Encrypted option at creation (for example, Zeotap Google Cloud Storage or SFTP Push).
  • Your PGP client follows the OpenPGP standard (RFC 4880), with session keys enabled.
  • For SFTP (Push) sources, your Zeotap Admin has whitelisted the IP you will upload from.

How PGP encryption works in Zeotap CDP

Zeotap CDP follows RFC 4880 (OpenPGP Message Format) for PGP encryption. Both Zeotap CDP and your systems must adhere to this standard for the integration to work. RFC 9580 is not supported, because adoption across PGP clients is limited. Zeotap CDP’s control plane generates an asymmetric public/private key pair per account. The public key is exposed to you through the source’s Implementation Details tab (and through the admin portal) so you can encrypt files locally. The private key is retained by Zeotap CDP and is used server-side to decrypt files at ingestion time. When an encrypted file lands in the source’s storage location (for example, a GCS bucket or SFTP folder), a cloud function decrypts it with the private key and moves the plaintext data to the raw data bucket for ingestion. For pull-based sources such as BigQuery or SFTP (pull), Zeotap CDP places the file in the appropriate bucket for you. The PGP public key you download looks like this:

Enable PGP encryption on a source

Turn on PGP at source creation, then download the account’s public key from the source’s own detail page.
  1. Create the source from the Sources application under Integrate, choosing a batch file-based type (for example, Zeotap Google Cloud Storage or SFTP Push). In the creation form, set the PGP Encrypted field to True.
  2. Complete the remaining source fields (name, file format, delimiter, region, data entity), then create the source.
  3. Open the newly created source and download the PGP public key from the Implementation Details tab. The account-level public key is also available in the admin portal.

Encrypt and upload your files

Encryption happens on your side, using the downloaded public key. Zeotap CDP never sees the plaintext file until after decryption inside its own infrastructure.
  1. Encrypt each source file with the downloaded public key, using an RFC 4880-compliant PGP client with session keys enabled. Encrypted files must carry the .pgp extension.
  2. Upload each encrypted .pgp file to the source’s storage location. For SFTP (Push), place the file under the encrypted-folder structure pgpencrypted/sourceid/raw/yyyy/mm/dd (for example, pgpencrypted/5121/raw/2025/01/15). For Zeotap Google Cloud Storage, upload to the bucket provisioned for your source.
  3. Zeotap CDP decrypts the file with the private key and moves the plaintext content into the ingestion queue automatically. No further action is required from you for the decryption step itself.
For PGP-encrypted SFTP (Push) sources, upload only .pgp files and only under the pgpencrypted/ folder path. A file placed under the non-encrypted path (/sourceid/raw/yyyy/mm/dd) or without the .pgp extension will not be decrypted.

Verify the encryption flow

You have configured PGP correctly when all of the following hold:
  • The source’s Implementation Details tab lists the PGP public key as available for download.
  • After you upload an encrypted file, an SFTP (Push) source’s status advances from Created to Integrated.
  • Decrypted records appear in the source’s Preview tab.
If a file is uploaded but nothing appears in Preview, work through the troubleshooting table below.

Troubleshoot PGP-encrypted uploads

Common conditions when a PGP-encrypted file does not reach ingestion, and where to check:
Zeotap CDP holds the private key for decryption; you are responsible for safeguarding the public key you download and for the encryption workflow that runs before upload. Establish a key rotation and access-control process on your side that fits your organisation’s key-management policy.

FAQ

Zeotap CDP implements RFC 4880 (OpenPGP Message Format). RFC 9580 is not supported, because adoption across PGP clients is limited.
After you create a source with PGP Encrypted set to True, open the source and go to the Implementation Details tab — the PGP public key is available for download there. The account-level public key is also exposed in the admin portal.
No. Zeotap CDP generates the key pair inside its control plane and retains the private key for server-side decryption at ingestion time. You interact only with the public key.
PGP is available on batch file-based sources — for example, Zeotap Google Cloud Storage and SFTP (Push). Event-stream sources such as Web Pixel, IFrame, and App Pixel do not use file-based PGP encryption.

Next steps

Last modified on September 8, 2026