Protegrity hybrid and multicloud data protection platform is now available on the Google Cloud marketplace, rounding out the multicloud integrations of the vendor's “non-traditional” data security approach, Protegrity Chief Revenue Officer Brad Rouse told SDxCentral.
The vendor's data protection platform is built to run on any cloud, on-premises environment, or a hybrid of the two. Protegrity has “strong partnerships” with major cloud providers like Amazon Web Services (AWS), Microsoft Azure, Google, and Oracle, along with smaller data providers like Snowflake, Cloudera, and Databricks. “The new Google Cloud Marketplace availability will allow customers to directly access our services through their cloud provider and customize their Protegrity solutions to best fit their needs,” Rouse explained.
The platform's uniqueness is tied to its protection of data wherever it's located and with whatever party it's shared. Rouse described this unorthodox approach as “safeguarding data itself without compromising its usability, allowing it to still be leveraged for analytics, ML [machine learning], and symbiotic research purposes,” he said. “We believe data should be used” and not locked down, he added.
Once data is protected, it can be shared within departments, business units, partners, or third-party services while maintaining security compliance. “Data can move from initial ingestion to platform A, platform B, and into the cloud without any modifications or calls to Protegrity,” he explained.
Sensitive data is transformed into non-sensitive substitute values, meaning the platform is particularly suited for ML model training and analysis. To re-identify data, “a requester must have the right permissions within the organization’s policy and have access to the protection service,” Rouse explained.
Quantum-Resistant Data ProtectionThe platform blends encryption, anonymization, cryptography, data masking, and vaultless tokenization to protect data “from all angles with quantum-resistant methods,” Rouse said. He claimed that even in the unfortunate event of a data breach, “data will remain useless to cybercriminals.”
The vaultless tokenization method used by Protegrity is resistant to Shor's quantum algorithm. That resistance “dramatically decreases” the security of asymmetric of public/private key algorithms because “our vaultless tokenization method doesn’t rely on a mathematical problem at all, and instead utilizes strong randomization.”
Protegrity's platform is also resistant to Grover's quantum search algorithm, which “optimize[s] some problems and reduce[s] the security of symmetric algorithms like AES-256 by about half,” Rouse noted. The vendor's platform, however, increases the key size to address that weakness. “We will be adding AES-512 in future releases as organizations begin shifting to the longer key length. With vaultless tokenization, because the security is based exclusively on randomization, it does not appear to have this same weakness for Grover’s algorithm as other solutions do,” he noted.
“We are constantly monitoring both quantum and classical attack vectors to ensure that our customers are operating with the most secure methods available,” Rouse added. “The fun part about working in this industry is that nothing is static or written in stone.”
A League of Its OwnRouse claimed that due to Protegrity's combination of offerings, the vendor seems to have no direct competitors. “Other companies or cloud providers provide a limited version of our services,” he said. He also touted the vendor's partnerships with multiple cloud providers and databases that support implementation regardless of where data is being geographically stored.
Another point of differentiation is the vendor's format-preserving encryption services for any language, which is a vaultless tokenization method that “enables alphabet, format, and length-preserving data security for the world's languages based on Unicode. This sets us apart because most other encryption or tokenization methods are only available for the English language or traditional numerical system,” he explained.
The Unicode standard used by Protegrity contains more than 140,000 unique characters so enterprises can define their own alphabet or language, even in emojis if desired. “There is no judgment or discrimination against a customer's alphabet of choice,” Rouse said.