What this is
PGP (Pretty Good Privacy) encryption is an option available when you create a batch file-based Zeotap CDP source — flat file sources such as Zeotap Google Cloud Storage and SFTP (Push). When enabled, Zeotap CDP generates a public/private key pair for your account: you encrypt files locally with the public key, upload them to the source’s storage location, and Zeotap CDP decrypts them with the matching private key before queuing them for ingestion. This page explains how the flow works, how to turn it on for a source, and how to confirm that encrypted uploads are being decrypted and ingested.Prerequisites
Before turning on PGP encryption for a source, confirm:
- You have permission in Zeotap CDP to create or edit a Source.
- The source you are creating is a batch file-based type that exposes the PGP Encrypted option at creation (for example, Zeotap Google Cloud Storage or SFTP Push).
- Your PGP client follows the OpenPGP standard (RFC 4880), with session keys enabled.
- For SFTP (Push) sources, your Zeotap Admin has whitelisted the IP you will upload from.
How PGP encryption works in Zeotap CDP
Zeotap CDP follows RFC 4880 (OpenPGP Message Format) for PGP encryption. Both Zeotap CDP and your systems must adhere to this standard for the integration to work. RFC 9580 is not supported, because adoption across PGP clients is limited. Zeotap CDP’s control plane generates an asymmetric public/private key pair per account. The public key is exposed to you through the source’s Implementation Details tab (and through the admin portal) so you can encrypt files locally. The private key is retained by Zeotap CDP and is used server-side to decrypt files at ingestion time. When an encrypted file lands in the source’s storage location (for example, a GCS bucket or SFTP folder), a cloud function decrypts it with the private key and moves the plaintext data to the raw data bucket for ingestion. For pull-based sources such as BigQuery or SFTP (pull), Zeotap CDP places the file in the appropriate bucket for you. The PGP public key you download looks like this:Enable PGP encryption on a source
Turn on PGP at source creation, then download the account’s public key from the source’s own detail page.- Create the source from the Sources application under Integrate, choosing a batch file-based type (for example, Zeotap Google Cloud Storage or SFTP Push). In the creation form, set the PGP Encrypted field to True.
- Complete the remaining source fields (name, file format, delimiter, region, data entity), then create the source.
- Open the newly created source and download the PGP public key from the Implementation Details tab. The account-level public key is also available in the admin portal.
Encrypt and upload your files
Encryption happens on your side, using the downloaded public key. Zeotap CDP never sees the plaintext file until after decryption inside its own infrastructure.-
Encrypt each source file with the downloaded public key, using an RFC 4880-compliant PGP client with session keys enabled. Encrypted files must carry the
.pgpextension. -
Upload each encrypted
.pgpfile to the source’s storage location. For SFTP (Push), place the file under the encrypted-folder structurepgpencrypted/sourceid/raw/yyyy/mm/dd(for example,pgpencrypted/5121/raw/2025/01/15). For Zeotap Google Cloud Storage, upload to the bucket provisioned for your source. - Zeotap CDP decrypts the file with the private key and moves the plaintext content into the ingestion queue automatically. No further action is required from you for the decryption step itself.
Verify the encryption flow
You have configured PGP correctly when all of the following hold:- The source’s Implementation Details tab lists the PGP public key as available for download.
- After you upload an encrypted file, an SFTP (Push) source’s status advances from Created to Integrated.
- Decrypted records appear in the source’s Preview tab.
Troubleshoot PGP-encrypted uploads
Common conditions when a PGP-encrypted file does not reach ingestion, and where to check:FAQ
Which OpenPGP version does Zeotap CDP support?
Which OpenPGP version does Zeotap CDP support?
Zeotap CDP implements RFC 4880 (OpenPGP Message Format). RFC 9580 is not supported, because adoption across PGP clients is limited.
Where do I download the public key for my source?
Where do I download the public key for my source?
After you create a source with PGP Encrypted set to True, open the source and go to the Implementation Details tab — the PGP public key is available for download there. The account-level public key is also exposed in the admin portal.
Does Zeotap CDP ever hand out the private key?
Does Zeotap CDP ever hand out the private key?
No. Zeotap CDP generates the key pair inside its control plane and retains the private key for server-side decryption at ingestion time. You interact only with the public key.
Which source types support PGP encryption?
Which source types support PGP encryption?
PGP is available on batch file-based sources — for example, Zeotap Google Cloud Storage and SFTP (Push). Event-stream sources such as Web Pixel, IFrame, and App Pixel do not use file-based PGP encryption.