Conversation

Pegasystems Inc.
GB
Last activity: 23 Jul 2025 5:13 EDT
Enhanced data security for Pega SoR solutions
The promotion of the Pega SoR pattern, and the capabilities of the Common Data Application are making it more probable that our applications will contain larger quantities of more accessible sensitive data and PII. Can this Expert Circle be a host for insights into product capabilities (and limitations), and design best practices for maximising data security?
Traditionally we would only store small subsets of work-in-progress business data, typically embedded in Case BLOBs. This made it feasible to encrypt, and difficult to access at volume. Case architecture also contains capabilities to associate data by reference, and control, monitor, and alert on data missuse e.g. field-level audit. Storage of SoR data tends to make use of the Data architecture in Pega, which utilises 'external classes' with data stored in exposed columns. This implies more complexity in terms of data encryption and access control, and more risk from bulk access operations e.g. Search.
I appreciate that the topic spans all aspects of the solution design - storage, infrastucture, application design, operations design, and UX design. But where might we best host a University of Data Security?