Protegrity & Informatica
Live Demo
View DemoProtegrity Non-Native
Protegrity extends Informatica workflows through protection components incorporated into data-integration mappings rather than through functionality built directly into the Informatica platform. For PowerCenter, protection logic can be incorporated through Java Transformations so sensitive fields are processed as part of the mapping workflow. Cloud data-integration architectures can connect Informatica processing to Protegrity protection services according to the organization’s deployment model.
Integration type
- ELT
- ETL
Partner
Yes
overview
For data engineering teams processing millions of records, security cannot come at the cost of latency. Protegrity delivers high-velocity data protection for Informatica by running cryptographic operations in-process via Java Transformations (JTX) for PowerCenter, effectively eliminating network overhead. For cloud-native workflows in IICS, the solution scales elastically using serverless functions. This dual approach allows you to apply consistent privacy policies across your entire data estate, ensuring that massive datasets are tokenized and compliant before they are ever written to your target data warehouse.
Key Integration Features
Protegrity delivers a high-performance security layer designed specifically for the rigorous demands of Informatica’s enterprise data engineering. Unlike standard API-based solutions, Protegrity can embed protection logic directly into the Informatica PowerCenter processing engine via Java Transformations (JTX), eliminating network latency for massive on-premise workloads. Simultaneously, it extends this governance to Informatica Intelligent Cloud Services (IICS), ensuring a unified security posture. This page outlines how Protegrity enables data teams to secure millions of records in minutes, maintaining the velocity required for modern data warehousing and cloud migration.
Features & Capabilities
Protegrity integrates with Informatica PowerCenter and IICS to deliver high-velocity, hybrid data protection:
01
Zero-Latency “In-Process” Protection
Why It Matters
Maximize throughput for massive on-premise workloads by running protection logic directly on the Informatica server. Unlike standard API calls that incur network overhead, Protegrity integrates via Java Transformations (JTX) within the PowerCenter pipeline, allowing cryptographic operations to execute locally in memory for blazing-fast performance.
How it Works
A telecom operator processes 500 million Call Detail Records (CDRs) daily. By using Protegrity’s local Java protector within their PowerCenter mappings, they achieved a throughput of over 100,000 records per second, eliminating the bottlenecks associated with external REST calls.
02
Hybrid Cloud Interoperability (PowerCenter & IICS)
Why It Matters
Future-proof your data strategy with a security layer that spans generations of infrastructure. Policies applied in legacy on-premise PowerCenter workflows are fully compatible with modern Informatica Intelligent Cloud Services (IICS) flows, ensuring seamless data mobility during cloud migrations without requiring re-encryption.
How it Works
A retail bank uses PowerCenter to protect sensitive customer data on-premise before migrating it to Snowflake. Once in the cloud, new IICS workflows (connected to Protegrity Cloud Protect) can seamlessly process that same data, ensuring a secure, uninterrupted chain of custody during their multi-year cloud journey.
03
Schema-Preserving Tokenization
Why It Matters
Maintain absolute data integrity across diverse target systems. Protegrity’s vaultless tokenization preserves the original data type and length (e.g., keeping a 16-digit credit card number as 16 digits), ensuring that protected data loads successfully into target data warehouses without triggering schema validation errors or requiring column resizing.
How it Works
When loading data from a mainframe into a strict SQL database, a mismatch in field length often causes ETL failures. Protegrity ensures the tokenized output mirrors the source format exactly, allowing the Informatica mapping to run successfully without complex validation logic or exception handling.
04
Decoupled Policy Governance
Why It Matters
Abstract security logic away from ETL development. Instead of hardcoding encryption rules inside Informatica Mapplets, the integration calls a named policy (e.g., “Policy_HR_Global”) managed centrally in the Protegrity Enterprise Security Administrator (ESA). This allows security teams to update algorithms or rotation schedules without forcing data engineers to modify and redeploy critical ETL jobs.
How it Works
A multinational insurer needed to update their encryption standard from AES-128 to AES-256 to meet new compliance mandates. They updated the policy in Protegrity ESA, and thousands of Informatica mappings instantly adhered to the new standard on their next run—zero code changes required.
05
Granular Separation of Duties
Why It Matters
Enforce a strict boundary between data engineering and security operations. The Informatica developer places the protection transformation into the workflow but never has access to the encryption keys or the ability to see clear-text data. This satisfies strict “Separation of Duties” compliance requirements common in banking and healthcare.
How it Works
During a compliance audit, a financial services firm demonstrated that while their ETL developers had full administrative access to the Informatica environment, they were technically incapable of reversing the tokenization because the unprotect rights were restricted solely to specific authorized service accounts managed by the CISO’s office.
Architecture &
Sample Data Flow
Protegrity can be incorporated at different points in an Informatica architecture depending on where sensitive data should transition into or out of a protected state. PowerCenter can apply protection during on-premises ETL processing, while cloud data-integration workflows can connect to Protegrity protection capabilities within the appropriate cloud or hybrid architecture.
The data journey
Visualizing the data journey
The data journey
The data journey explained
-
01
Protect at the Source
Sensitive fields can be tokenized or encrypted within Informatica PowerCenter before data leaves the on-premises processing environment. This establishes a protected state early in the pipeline and reduces the need to move clear sensitive data into downstream cloud or analytics systems.
-
02
Process and Move Protected Data
Informatica continues to transform, route, and load the data according to the workflow design. Protected values can move between on-premises systems, cloud environments, warehouses, and analytics platforms while Protegrity policy remains responsible for how sensitive fields are protected.
-
03
Land Data Protected
Sensitive values can remain protected when written to downstream destinations such as cloud data warehouses or data lakes. This extends protection beyond the Informatica pipeline rather than automatically returning data to clear form at the end of the ETL process.
-
04
Unprotect by Policy
When an approved application, service, or user requires access to original values, controlled unprotection can occur at the appropriate point in the Informatica workflow or destination environment. Protegrity policy determines when access to clear data is permitted.
Use Cases
See how Protegrity works with Informatica to protect sensitive data across cloud migration, ETL processing, and downstream analytics while keeping data-protection policy centrally managed.
Finance
Protect Data During Cloud Migration
Challenge
Banks moving customer and transaction data from legacy systems into cloud data platforms often need to protect sensitive fields such as payment card data, tax identifiers, and other PII before that information leaves the on-premises environment. At the same time, downstream analytics and fraud workflows still need data that can move through existing Informatica mappings and target schemas without introducing unnecessary redesign.
Solution
Protegrity protection can be incorporated into Informatica PowerCenter or cloud data-integration workflows so configured sensitive fields are tokenized or encrypted as part of the pipeline. For migrations originating on-premises, protection can be applied before sensitive values are sent to the cloud. Centrally managed Protegrity policy remains separate from the Informatica mapping, while protected values continue through downstream transformation, loading, and analytics workflows.
Result
Organizations can move protected customer and transaction data into cloud environments while reducing the amount of clear sensitive information exposed across the migration path. Where supported by the configured tokenization method, protected values can retain characteristics required by downstream schemas and processing. Controlled unprotection remains available for approved applications, services, or users.
Healthcare Payers
Apply Consistent Protection Across ETL Pipelines
Challenge
Healthcare organizations often use Informatica to move patient and operational data between clinical systems, enterprise repositories, analytics platforms, and cloud environments. These pipelines may contain protected health information and other sensitive identifiers that require consistent handling as data moves between systems and teams.
Solution
Protegrity applies centrally managed data-protection policy within Informatica workflows so configured sensitive fields can be tokenized, encrypted, or otherwise protected before they reach downstream destinations. Protection policy remains separate from ETL development, allowing data engineering teams to build and operate Informatica mappings while security teams govern how sensitive values are protected and when access to original data is permitted.
Result
Healthcare organizations can distribute protected data across analytics and reporting workflows while reducing unnecessary exposure of original sensitive values. This creates a more consistent approach to data protection across on-premises and cloud data-integration environments and supports broader privacy, security, and governance requirements.
DEPLOYMENT
Protegrity can be incorporated into Informatica architectures spanning PowerCenter, cloud data-integration workflows, and hybrid environments. The appropriate deployment model depends on where Informatica processing occurs, where sensitive data should first be protected, and which Protegrity protection capabilities are available within the environment.
PowerCenter
Cloud Data Integration
Hybrid Environments
Deployment Considerations
Deployment planning should account for:
- Where sensitive data first enters the Informatica workflow
- Where protection and controlled unprotection should occur
- Connectivity between Informatica processing environments and Protegrity protection services
- Data volume and workload concurrency
- Schema and format requirements for protected values
- Identity and policy requirements for authorized access to clear data
- Performance requirements for batch and real-time workloads
Representative workloads should be tested and sized according to the organization’s Informatica architecture and protection requirements.
RESOURCES
Explore Protegrity documentation and technical resources for implementing and managing data protection across Informatica workflows.
Protegrity Documentation Center
Explore technical documentation for Protegrity data protection, policy management, protectors, deployment, and platform capabilities.
READ MOREFrequently
Asked Questions
Protegrity supports Informatica PowerCenter and Informatica Intelligent Cloud Services (IICS). Since the integration utilizes standard integration methods (Java Transformations, Custom Transformations, or REST connectors), it is compatible with any Informatica Mapping or Workflow running on standard Integration Services or Cloud Secure Agents that can communicate with the Protegrity protection service.
Protegrity offers flexible deployment options to match your Informatica architecture. You can deploy Protegrity Protection Gateways on-premise to service local PowerCenter Integration Services, or utilize Protegrity Cloud Protect (serverless/containerized) for Informatica Cloud Secure Agents running in AWS, Azure, or Google Cloud. This ensures that whether your ETL jobs run in the cloud or on-premise, they always access a low-latency protection service nearby.
Protegrity supports vaultless tokenization, encryption, masking, hashing, and format-preserving encryption, all centrally managed in the Enterprise Security Administrator (ESA). This ensures that the specific policies applied within your Informatica ETL pipelines (e.g., “Tokenize Email”) are identical to those enforced in your data warehouse, mainframe, or other applications, simplifying global compliance.
Our customers benefit from:
- Secure Data Migration: Tokenizing sensitive assets during the move from on-premise to cloud (e.g., Mainframe to Snowflake), ensuring raw data never leaves the secure zone.
- Optimized Batch Performance: High-throughput protection using batched API calls or optimized Java implementations to minimize ETL runtime.
- Universal Connectivity: The ability to protect data flowing between any source and destination supported by Informatica (e.g., Salesforce to Redshift) using a single, consistent security standard.
Protegrity integrates into Informatica workflows using Java Transformations (JTX) or standard REST connectors (depending on the deployment model). Developers simply configure these transformations within the Informatica Designer/Developer tool to pass sensitive fields to the Protegrity API/Library for protection or unprotection. This setup often utilizes parameterized connections for secure authentication. Please refer to the Integration Features section for more details.
See the Protegrity
platform in action
Accelerate data access and turn data security into a competitive advantage with Protegrity’s uniquely data-centric approach to data protection.
Get an online or custom live demo.