Skip to content
  • There are no suggestions because the search field is empty.

How Do PGP Encryption Keys Work in Arkalytics?

PGP encryption helps protect sensitive data while it is being stored or transmitted. Arkalytics uses PGP encryption to help ensure that files sent to Arkatechture can only be accessed by the intended recipient.

PGP uses a pair of related keys: a public key for encrypting data and a private key for decrypting it.

When Do PGP Keys Expire?

Arkalytics public PGP keys expire every two years and must be replaced to ensure your data delivery processes continue without interruption.

Approximately 30 days before your current public key expires, Arkatechture will notify you through a Service Desk ticket.

In the ticket, we'll ask you to confirm the appropriate contact or contacts who should receive the new key.

Once confirmed, an Arkatechture administrator will securely send the new public key using Virtru.

When Can I Start Using the New Key?

As soon as you receive the new public key, it is ready to use.

You do not need to wait for the existing key to expire. We recommend updating your data delivery processes during the 30-day renewal window to avoid interruptions.

Once the previous public key expires, your encryption software may no longer allow it to be used. Any processes still relying on the expired key could therefore prevent files from being successfully delivered to Arkalytics.

What Do I Need to Update?

What you need to do depends on how your organization sends data to Arkalytics.

If You Use the Arkalytics Extractor

Update the encryption key used by the Arkalytics Extractor before your existing key expires.

Refer to the Arkalytics Extractor User Manual for instructions.

If a Vendor Sends Files on Your Behalf

If you previously provided the Arkalytics public key to a vendor that sends files on your behalf, provide the vendor with the new public key and ask them to update their encryption process.

The process may vary by vendor. In some cases, Arkatechture manages a vendor-specific encryption key directly, meaning you do not need to provide the updated key yourself.

If you're unsure which process applies to your vendor, ask us in the Service Desk ticket associated with your PGP key renewal.

If You Use a Custom Data Delivery Process

If your organization has developed its own jobs or processes for sending data to Arkalytics, you'll likely need to update the public key within those processes.

Because these processes are managed by your organization, Arkatechture may not have visibility into where or how the encryption key is configured.

PGP Key Terminology

PGP/GPG Key Pair: A related public and private key used together for encryption and decryption.

Public Key: The key provided to your organization and used to encrypt files being sent to Arkalytics. Arkalytics public keys expire every two years.

Private Key: The corresponding key securely maintained by Arkatechture and used to decrypt files encrypted with the public key.

Encryption Key: In Arkalytics communications, this generally refers to the public key provided to your organization for encrypting files.

Key Takeaway

When you receive a new Arkalytics PGP public key, update any applicable data delivery processes before the existing key expires.

You can begin using the new key as soon as you receive it. If you're unsure whether the key needs to be updated in the Arkalytics Extractor, a vendor-managed process, or a custom process, respond to your PGP renewal Service Desk ticket for assistance.