SYNTRA DATAVAULT

Enterprise Data Masking Across Connected Systems

Protect sensitive implementation and test data wherever it travels. DataVault discovers sensitive data, applies reusable protection policies, traces it across connected systems and verifies whether protected data remains protected downstream.

Designed for connected enterprise landscapes including Workday, Oracle, SAP, Salesforce, databases, integration platforms and analytics systems.

DataVault
Sensitive Data
Source System
↓ Discover & Classify
Mask / Protect
System A
✓ Verified
System B
✓ Verified
Data Lake
⚠ Drift
Exposure detected

Sensitive Data Doesn't Stop at the Source System

Enterprise implementation and test data frequently moves through ERP and HCM applications, CRM systems, integration platforms, databases, data lakes, reporting systems, extracts and files, and other downstream applications. Masking the source environment alone doesn't necessarily demonstrate that downstream copies are protected.

DataVault is designed to provide visibility into both source masking and downstream masking assurance.

One Data Protection Lifecycle Across Connected Systems

Discover → Classify → Protect → Trace → Verify → Monitor → Govern

01 · Discover

Identify sensitive fields and records across connected application objects and data stores.

  • Personal & contact information
  • National & tax identifiers
  • Bank & payroll details
  • Supplier & customer information
02 · Classify

Apply classifications such as PII, Financial, Contact, Payroll, Confidential, or customer-defined categories.

03 · Protect

Apply policy types where implemented: redaction, partial masking, hashing, shuffling, substitution, synthetic replacement, tokenization.

04 · Trace

Understand where sensitive data originates and where it moves.

05 · Verify

Scan connected target systems to determine whether the required protection remains effective downstream.

06 · Monitor

Identify masking drift, newly exposed values, new sensitive fields, policy gaps and unverified downstream systems.

07 · Govern

Provide policy visibility, masking status, coverage, exceptions, evidence and exportable reports.

Screenshot of the Syntra DataVault module and object browser showing a hierarchy of business modules including Absence Management, Accounts Payable and Core HR, with the Locations object open showing 1,750 harvested records and Excel and JSON export options.
Discovery starts with a full object catalog. Example view from a connected Oracle Fusion test environment — the same underlying model extends to other connected systems.

Know What's Protected — and What Isn't

A representative view of the coverage dashboard shown to customers during onboarding and ongoing monitoring.

61%
Masking Coverage
480,388
Sensitive Records
291,528
Masked Records
188,860
Unmasked / Exposed
ObjectSensitiveMaskedExposedCoverage
Workers1,1041,0218392%
Suppliers8,2208,1804099%
Customers14,44213,92052296%
Bank Accounts2,3102,3100100%

Illustrative representative interface data, not a live customer environment.

Screenshot of the Syntra DataVault masking dashboard showing 61% masking coverage across 730,093 total records, 480,388 sensitive records, 291,528 masked and 188,860 unmasked, with a per-object coverage table listing fields, records and coverage percentage.
Actual DataVault masking-coverage interface, shown here against a representative test dataset.

Define Reusable Data Protection Policies

Policies are reusable across environments and, where mappings and connectors support it, across connected systems.

PolicyObject / FieldMethodClassification
Supplier Emailemail_addressEmail MaskPII
Bank Accountaccount_numberPartial MaskFinancial
National IDnational_idRedactPII
Tax Registrationtax_registration_noHashConfidential
Screenshot of the Syntra DataVault masking rules interface listing configured rules including supplier and customer email masking, bank account partial masking, tax registration hashing and contact phone masking, each showing object and field, method, a masked sample value, classification and an enabled toggle.
Actual DataVault masking-rules interface from a test environment.

Verify Protection Beyond the Source Application

Policy Applied

A masking or protection policy has been configured or executed.

Downstream Verified

DataVault has checked the relevant downstream target and confirmed the expected protection condition.

Drift Detected

DataVault has identified values or fields that no longer satisfy the expected protection policy.

SOURCE SYSTEM — 98% protected
↓ Integration ↓
CRM
✓ Verified · 99%
Data Lake
⚠ Drift · 72%
Reporting ✓ Verified · 97%

Propagating a policy to a system is not the same as proving that system's data is protected — DataVault is designed to distinguish the two.

One View Across the Enterprise Data Landscape

DataVault is designed around a connector-based architecture for enterprise applications and data platforms. Coverage below reflects system categories the architecture targets — only explicitly validated connectors are represented as currently supported on a given customer's system pages.

Enterprise Applications

Workday Oracle Fusion SAP Salesforce ServiceNow Microsoft Dynamics

Data Platforms

Snowflake Databricks Oracle Database SQL Server PostgreSQL Cloud data stores

Integration

Oracle Integration Cloud MuleSoft Boomi Application APIs File-based integrations

Reporting / Analytics

BI platforms Application reporting Extracts Downstream analytics
Screenshot of the Syntra DataVault connected-systems view from a test environment, showing upstream and downstream system connections, end-to-end coverage percentage, systems with masking drift, and a table of connected systems with connection type, masking status and coverage.
Example connected-systems view from a DataVault test environment. Specific systems shown are illustrative of the connector model, not a list of currently certified customer connectors.

Follow Sensitive Data From Source to Destination

Employee Email
HCM.Worker.Email
Integration
↓ ↓
CRM.Contact
✓ Protected
Data Lake
⚠ Exposed

Example Drill-Down

Data Concept
Employee Email
Classification
PII / Contact
Source
HCM Worker
Policy
Synthetic / Email Mask
Downstream Verification
CRM — Verified
Data Lake — Drift detected

Keep Test Data Private Without Breaking Business Relationships

Independent random masking per system can make end-to-end testing unusable — if a supplier's name is masked one way in one system and a different way in another, cross-system test flows break. Deterministic masking strategies can preserve cross-system relationships while replacing sensitive source values, where configured and supported by the relevant connectors.

Source

Jane Smith

jane.smith@company.com

DataVault Masked Identity

Sarah Williams

sarah.williams@masked.test

HCMSarah Williams
CRMSarah Williams
Data LakeSarah Williams
ReportingSarah Williams

Deterministic masking strategies can preserve cross-system relationships where configured; universal referential consistency across every connector is not guaranteed and depends on the mappings implemented for a given landscape.

Detect When Protected Data Becomes Exposed Again

Masking Drift Detected

System
Data Lake
Object
Worker Extract
Field
personal_email
Records affected
62
Expected policy
EMAIL_MASK
Status
Exposed
View Exposure Run Verification Export Evidence

Illustrative interface example.

Screenshot of a Syntra DataVault record-level masking drill-down for the Payroll Relationships object, showing individual records with original and masked values side by side and each record's masked or unmasked state.
Actual record-level drill-down from the DataVault masking interface, shown here for a representative object.

Protect Data After Environment Refreshes

Production / Source
↓ Clone / Refresh / Extract
Non-Production
DataVault
Discover Classify Mask Verify
Downstream Check
Ready for Testing

DataVault can be incorporated into environment-refresh and test-data workflows. Automatic detection of refresh events depends on the integration configured for a given environment.

Know Whether an Environment Is Ready for Testing

DataVault Verified

Mandatory masking policies satisfied.

Attention Required

Sensitive records remain exposed or downstream verification is incomplete.

Verified Warning Drift Detected Not Verified

More Than Data Masking

DataVault can maintain reusable application-aware test data for automated testing — test-data discovery, object relationships, valid data selection, reusable test datasets, test dimensions, data refresh, masking, scenario-specific data, and Jarvis integration.

Connected Systems
DataVault
Privacy-Protected Test Data
Jarvis
Generated Test Variations
SyntraFlow
Autonomous Execution

From Protected Data to Autonomous Testing

DataVault can have value independently of Jarvis and test execution — the two layer on top of the same protected data foundation.

DataVault

Discover · Protect · Organize · Verify

Jarvis

Understand · Generate · Expand Coverage

SyntraFlow

Execute · Schedule · Validate · Evidence

DataVault
Privacy-protected enterprise data
Jarvis
Positive + negative + boundary scenarios
SyntraFlow
Autonomous execution and evidence

Built for Heterogeneous Enterprise Landscapes

Workday

HCM, worker and implementation/test-data scenarios.

Explore Workday DataVault

Oracle Fusion

ERP, HCM and SCM application data.

Explore Oracle Data Vault
Roadmap

SAP

Enterprise application and business-object data. Connector not yet validated.

Roadmap

Salesforce

CRM, customer and contact data. Connector not yet validated.

Data & Integration Platforms

Databases, data lakes, integration and reporting destinations.

Produce Evidence of Masking Coverage

Data Masking & Downstream Verification Report

Representative report contents: systems scanned, objects scanned, sensitive records, masked records, exposed records, source coverage, downstream coverage, masking policies, drift, verification status, and exceptions.

See a Sample Report

Common DataVault Use Cases

Non-Production Data Protection

Protect sensitive information copied into implementation, test, UAT and development environments.

Downstream Masking Assurance

Verify that protection remains effective after data moves into connected systems.

ERP / HCM Implementation Testing

Use realistic but protected data during enterprise application implementation and regression testing.

Environment Refresh

Reapply and verify masking policies following test-environment refreshes.

Cross-System Testing

Maintain usable data relationships across integrated applications.

Test Data Management

Provide valid, reusable data to automated business-process tests.

Frequently Asked Questions

What is Syntra DataVault?
Syntra DataVault combines test-data management with sensitive-data discovery, protection and downstream assurance across connected enterprise systems — helping teams identify sensitive data, apply reusable protection policies, and verify whether that protection remains effective as data moves downstream.
Is DataVault only for Oracle Fusion?
No. DataVault is structured as a platform-neutral capability built on a connector-based architecture for enterprise applications and data platforms. Only explicitly supported and validated connectors are represented as production-ready; others are shown as designed-for or roadmap.
Can DataVault work with Workday?
DataVault is designed around a connector-based approach that can extend to Workday. See the dedicated Workday DataVault page for how this applies to worker and implementation data specifically.
Can DataVault verify downstream systems?
DataVault distinguishes between a protection policy being applied or propagated, and that protection being independently verified at a downstream target. Where DataVault has authorized connectivity to a target system, it can evaluate that system against the expected policy and surface gaps or drift.
Does masking preserve test-data relationships?
Deterministic masking strategies can preserve cross-system relationships — the same source identity consistently replaced with the same masked identity — where configured and supported by the relevant connectors, rather than every system masking independently at random.
Does DataVault make us GDPR compliant?
No. DataVault provides technical controls that can support an organization's privacy and data-protection program. Regulatory compliance depends on the organization's broader processes, configuration, governance and legal requirements — it is not conferred by any single tool.
Can DataVault be used without SyntraFlow testing?
Yes. DataVault is independently useful for test-data privacy and management. Integration with Jarvis and SyntraFlow adds AI-generated scenario variations and autonomous execution on top of the same protected data foundation.

See How Your Data Stays Protected Across Connected Systems

Bring a representative source-to-downstream data flow to the demo. We'll show how DataVault can model sensitive data, protection policies, lineage, masking coverage and downstream verification for your enterprise landscape.