CCA RDRS Secure Data Connector

Encrypt in flight · Format preserved

CCA RDRS Secure Data Connector

Protect sensitive data in motion—without changing your schema.

The CCA RDRS Secure Data Connector is a high-performance replication exit that encrypts selected fields as data moves through your RDRS stream, using OpenText Voltage SecureData format-preserving encryption—so sensitive values are protected before they reach the target database.

Keep sensitive fields protected, end to end.

Replication keeps data moving, but sensitive values—customer identifiers, account details, personal information—can land in target databases unprotected. Encrypting everything slows replication and forces schema changes. Encrypting nothing leaves your most sensitive data exposed.

The Secure Data Connector encrypts only the fields you choose, at the point of replication. A high-performance exit in the RDRS data path, it calls the OpenText Voltage SecureData API to apply format-preserving encryption (FPE) to mapped fields—ciphertext keeps the length and format of the original value, so databases, indexes and applications do not change. Sensitive data arrives protected, and data that does not need protection flows untouched.

Capabilities

Encrypt the fields that matter, with the formats intact.

A config-driven Windows replication exit that brings OpenText data protection into the RDRS data path.

Field-level, mapping-driven encryption

Encrypts selected fields as defined in a mapping configuration—not whole records, and not the entire stream.

Format-preserving encryption

Uses AES-FF1 format-preserving encryption (NIST SP 800-38G) so protected values keep the same length and format—no schema, index or application changes.

Date and timestamp masking

Dedicated masking profiles protect date and timestamp values while preserving their format.

Shared-secret authentication

Connects to the Voltage SecureData policy server with a shared secret—no client certificates to manage.

Licensed per deployment

Keycode-validated through CCA’s licensing, with expiry warning built into the exit.

How it works

From source data to protected target, in one pass.

The exit slots into the RDRS replication stream and handles protection automatically.

  1. 01Configure

    Configure

    Define the policy server, authentication and licence keycode in a single configuration file.

  2. 02Connect

    Connect

    The exit establishes a policy connection to the Voltage SecureData policy server.

  3. 03Protect

    Protect

    As each record replicates, mapped fields are encrypted with format-preserving encryption—same length, same format, protected content.

  4. 04Verify

    Verify

    Encrypted values are confirmed with a decrypt round-trip in verification builds, with per-field logging for audit.

Built for progress

Useful for the people who protect data.

Give every team a consistent, schema-safe way to keep sensitive data protected.

Security and compliance teams

Field-level encryption for sensitive data without touching schema, indexes or applications.

RDRS administrators

Plugs into the replication stream, configured by mapping—no changes to replication scripts.

Project teams

Protect data end to end along your RDRS data flows, with one consistent method.

Start the conversation

Give your replication stream a security boundary it can keep.

Talk to CCA about RDRS Secure Data Connector and how it fits alongside CCA RDRS Script Monitor, CCA RDRS Environment Migration Automation and the wider CCA RDRS utilities.

Talk to a consultant


Our solutions help you drive outcomes and transform your data

View All Solutions