This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Overview of Protegrity AI Team Edition

An overview of the Protegrity AI Team Edition.

The Protegrity AI Team Edition introduces a modern, container-based approach to data protection built on a microservices architecture. It enables organizations to evaluate how Protegrity’s methods, such as, policy management, anonymization, discovery, and semantic controls, integrate into AI and analytics pipelines.

1 - Architecture and Design Principles

Architecture of AI Team Edition

Protegrity AI Team Edition delivers core Protegrity capabilities. This includes governance, discovery, protection, privacy, and semantic controls. It is provided in a lightweight, containerized form factor that emphasizes fast deployment, simplified operations, and consistent enforcement of data security policies across environments. It is designed around five engineering goals: ease of deployment, high availability, scalability, extensibility, and maintainability.

GoalImplementation Details
Ease of Deployment- OpenTofu templates provision a Kubernetes environment (EKS) with minimal manual intervention.
- Helm Charts deploy and configure all components for consistent, reproducible setups.
- Because each component runs as a container image, upgrades and patches follow standard CI/CD workflows.
High Availability- Kubernetes manages service health and redundancy automatically.
- No Trusted Appliance Cluster (TAC) required.
- No external load balancers required.
- No manual replication required.
Scalability- The system scales horizontally and vertically through Kubernetes-native scale-up and scale-down mechanisms.
- Administrators can adjust resources dynamically as workloads grow or shrink without redeployment.
Extensibility- New capabilities are introduced by adding new container images and Helm configurations.
- Allows incremental feature expansion without redesign.
Maintainability- Kubernetes simplifies lifecycle management.
- Updating a container image replaces an older version automatically, avoiding downtime and manual patching.

2 - Protegrity Common Services

Common services offered by Protegrity AI Team Edition

All deployments include a standardized set of common services delivered by a microservices architecture that provide routing, security, and audit capabilities for all features and protectors.

ServiceDescription
Authentication and AuthorizationProvides user and service credential validation with role-based access enforcement.
Backup and RestoreCreates periodic backup of the cluster and indexes for restoration during Disaster Management.
Certificate ManagementManages and validates TLS certificates for inbound and inter-service communication.
Common Ingress ControllerThe main entry point for all API and service traffic to the cluster.
InsightProvides logging and auditing capabilities using OpenSearch for event storage and Insight Dashboard for visualization and reporting.

3 - Supported Deployment Platforms

Cloud platforms supported by Protegrity AI Team Edition.

Protegrity AI Team Edition runs on the Protegrity Provisioned Cluster (PPC), a Kubernetes-based runtime that packages all services into a single, managed deployment target. PPC is available on the following cloud platforms.

AWS (EKS)

Protegrity AI Team Edition is generally available on Amazon Web Services using Elastic Kubernetes Service (EKS). OpenTofu templates automate cluster provisioning, and Helm charts deploy all AI Team Edition services into the EKS environment. This is the primary supported platform for production workloads.

Note: AWS is the recommended platform for production deployments.

Microsoft Azure (AKS)

Protegrity AI Team Edition for Microsoft Azure deploys PPC on Azure Kubernetes Service (AKS). This platform option is currently available as a Tech Preview. It supports the same core services and protectors, with additional integration for Azure-native analytics platforms.

Compatibility

The following table summarizes the supported deployment platforms for Protegrity AI Team Edition.

FeatureAWS (EKS)Microsoft Azure (AKS)
Protegrity Provisioned Cluster (PPC)✅ Supported✅ Supported
Protegrity Policy Manager (PPM)✅ Supported✅ Supported
Protegrity Agent✅ Supported❌ Not Supported
Data Discovery✅ Supported❌ Not Supported
Semantic Guardrails✅ Supported❌ Not Supported
Protegrity Anonymization✅ Supported❌ Not Supported
Protegrity Synthetic Data✅ Supported❌ Not Supported
ProtectorsSupported AWS protectors✅ Azure Databricks

4 - Compatible Features

Services offered by Protegrity AI Team Edition

The various features compatible with Protegrity AI Team Edition are provided here.

* - Available for purchase as an add-on. Can be installed as an individual product.

FeatureDescriptionVersion for Team Edition
AnonymizationApply statistical privacy models such as k-anonymity, l-diversity, and t-closeness to sensitive datasets.2.0.1
Data DiscoveryAutomatically identify structured and unstructured sensitive data through pattern matching and machine learning classification.2.0.0
Policy ManagerDefine and manage data protection policies that govern tokenization, masking, and anonymization.1.12
Protegrity AgentIntelligent assistant for automated policy creation, data classification recommendations, and guided configuration of protection workflows.1.1.0
Semantic GuardrailsApply contextual and runtime safeguards to AI and analytics workflows to prevent data leakage or misuse.1.1.1
Synthetic DataGenerate tabular synthetic datasets for development, testing, and AI model validation without exposing real sensitive data.2.1.0

Protegrity Protectors

Protegrity AI Team Edition protectors enable organizations to embed data protection directly where data is processed, inside applications, analytics engines, or cloud-native data systems. The protectors use the Workbench for obtaining the policy for processing. The Protegrity Agent is available for creating and working with policies in the Workbench.

Cloud API

The Cloud API protector extends Protegrity protection to AWS serverless and API-based workloads. It is typically used for securing transient data handled by AWS Lambda or similar function-based architectures.

NameDescriptionPart Number
CloudProtect – Cloud API – AWSProtegrity CloudProtect using AWS Serverless Functions.CP_SVRL-ALL-64_x86-64_AWS.API_4.0

Application Protectors

Application protectors provide data protection directly within applications or runtime containers. They are suitable for teams developing secure APIs or microservices that handle sensitive data in languages such as Java, Python, or .NET.

NameDescriptionPart Number
Application Protector – Java ContainerProtects data within Java-based containers, such as OpenShift, AKS, and EKS.ApplicationProtector_RHUBI-9-64_x86-64_Generic.K8S.JRE-1.8_10.1
Application Protector – REST ContainerProvides REST-based protection services for containerized workloads.REST_RHUBI-9-64_x86-64_K8S_10.1
Application Protector – Python (Linux AMD64)Protegrity Application Protector for Python environments on Linux AMD64.ApplicationProtector_Linux-ALL-64_x86-64_PY-3.13_10.0
Application Protector – Python (Linux ARM64)Protegrity Application Protector for Python environments on Linux ARM64.ApplicationProtector_Linux-ALL-64_arm64_PY-3.13_10.0
Application Protector – Java (Linux AMD64)Standard Java runtime protector for Linux AMD64 environments.ApplicationProtector_Linux-ALL-64_x86-64_JRE-1.8-64_10.1
Application Protector – Java (Linux ARM64)Standard Java runtime protector for Linux ARM64 environments.ApplicationProtector_Linux-ALL-64_arm64_JRE-1.8-64_10.0
Application Protector – .NETProtegrity Application Protector for Microsoft .NET applications.ApplicationProtector_WIN-ALL-64_x86-64_NET-STD-2.0-64_10.0

Repository Protectors

Repository protectors allow you to apply data protection directly within persistent data stores, enabling sensitive data to remain protected at rest while still being used for analytics and AI workloads.

These protectors consist of Big Data Protectors for Amazon EMR, Databricks, and CDP Data Hub and Cloud-Native Data Warehouse protectors for analytics environments such as Snowflake, Redshift, and Athena.

NameDescriptionPart Number
AWS Protectors:
Big Data Protector – Amazon EMRProvides data protection within Amazon EMR clusters.BigDataProtector_Linux-ALL-64_x86-64_EMR-7.9-64_10.0
Big Data Protector – AWS DatabricksEnables tokenization and masking for Databricks on AWS.BigDataProtector_Linux-ALL-64_x86-64_AWS.Databricks-17.3-64_10.0
Big Data Protector – AWS Databricks (Linux ARM64)Enables tokenization and masking for Databricks on AWS on ARM64.BigDataProtector_Linux-ALL-64_ARM64_AWS.Databricks-17.3-64_10.0
Big Data Protector – CDP Data HubSupports Cloudera DataWorks Platform deployments on AWS.BigDataProtector_Linux-ALL-64_x86-64_AWS.Generic.CDP-Datahub-7.3-64_10.0
Cloud Native Data Warehouse Protector – SnowflakeIntegrates with Snowflake for secure, compliant analytics on AWS.CP_SVRL-ALL-64_x86-64_AWS.Snowflake_4.0
Cloud Native Data Warehouse Protector – RedshiftProvides protection for Amazon Redshift queries and transformations.CP_SVRL-ALL-64_x86-64_AWS.Redshift_4.0
Cloud Native Data Warehouse Protector – AthenaApplies protection to Amazon Athena query execution.CP_SVRL-ALL-64_x86-64_AWS.Athena_4.0
Cloud Storage Protector – Amazon S3Applies protection for Amazon S3.CSP-S3_SVRL-ALL-64_x86-64_AWS.S3_2.0
Azure Protectors:
Big Data Protector – Azure DatabricksEnables tokenization and masking for Databricks on Azure.BigDataProtector_Linux-ALL-64_x86-64_Azure.Databricks-17.3-64_10.0