Encrypt in flight · Format preserved
CCA RDRS Secure Data Connector
Protect sensitive data in motion—without changing your schema.
The CCA RDRS Secure Data Connector is a high-performance replication exit that encrypts selected fields as data moves through your RDRS stream, using OpenText Voltage SecureData format-preserving encryption—so sensitive values are protected before they reach the target database.
Replication keeps data moving, but sensitive values—customer identifiers, account details, personal information—can land in target databases unprotected. Encrypting everything slows replication and forces schema changes. Encrypting nothing leaves your most sensitive data exposed.
The Secure Data Connector encrypts only the fields you choose, at the point of replication. A high-performance exit in the RDRS data path, it calls the OpenText Voltage SecureData API to apply format-preserving encryption (FPE) to mapped fields—ciphertext keeps the length and format of the original value, so databases, indexes and applications do not change. Sensitive data arrives protected, and data that does not need protection flows untouched.
Encrypt the fields that matter, with the formats intact.
A config-driven Windows replication exit that brings OpenText data protection into the RDRS data path.
Field-level, mapping-driven encryption
Encrypts selected fields as defined in a mapping configuration—not whole records, and not the entire stream.
Format-preserving encryption
Uses AES-FF1 format-preserving encryption (NIST SP 800-38G) so protected values keep the same length and format—no schema, index or application changes.
Date and timestamp masking
Dedicated masking profiles protect date and timestamp values while preserving their format.
Shared-secret authentication
Connects to the Voltage SecureData policy server with a shared secret—no client certificates to manage.
Licensed per deployment
Keycode-validated through CCA’s licensing, with expiry warning built into the exit.
From source data to protected target, in one pass.
The exit slots into the RDRS replication stream and handles protection automatically.
-
01Configure
Configure
Define the policy server, authentication and licence keycode in a single configuration file.
-
02Connect
Connect
The exit establishes a policy connection to the Voltage SecureData policy server.
-
03Protect
Protect
As each record replicates, mapped fields are encrypted with format-preserving encryption—same length, same format, protected content.
-
04Verify
Verify
Encrypted values are confirmed with a decrypt round-trip in verification builds, with per-field logging for audit.
Useful for the people who protect data.
Give every team a consistent, schema-safe way to keep sensitive data protected.
Security and compliance teams
Field-level encryption for sensitive data without touching schema, indexes or applications.
RDRS administrators
Plugs into the replication stream, configured by mapping—no changes to replication scripts.
Project teams
Protect data end to end along your RDRS data flows, with one consistent method.
Give your replication stream a security boundary it can keep.
Talk to CCA about RDRS Secure Data Connector and how it fits alongside CCA RDRS Script Monitor, CCA RDRS Environment Migration Automation and the wider CCA RDRS utilities.