---
name: atracker-data-security
title: Securing your data
description: To ensure that you can securely manage your data when you use Activity Tracker Event Routing, it is important to know exactly what data is stored and encrypted, and how you can delete any stored data.
last-updated: 2026-09-21
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/atracker?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Securing your data
{: #data-security}

To ensure that you can securely manage your data when you use Activity Tracker Event Routing, it is important to know exactly what data is stored and encrypted, and how you can delete any stored data.
{: shortdesc}



## What data is stored in Activity Tracker Event Routing
{: #data-security-stored}

When you use Activity Tracker Event Routing to manage your audit events, you should differentiate between configuration data and audit data.


### Configuration data
{: #data-security-config}


To configure Activity Tracker Event Routing, you must configure account settings, targets, and routes. You can configure Activity Tracker Event Routing via REST API calls, CLI commands, or by using terraform scripts. The definitions of these resources are hosted on the IBM Cloud.

- You can configure the Activity Tracker Event Routing account settings to indicate the primary and backup metadata locations where global definitions are stored such as route definitions and the type of endpoints that are enabled.

    You can set the primary metadata location by configuring the account settings. Alternatively, when you define the first target in the account; the location where the target is defined is automatically set as the primary location.

    You must configure the account settings to define the backup metadata location. This location is optional.

-  You can define [targets](https://cloud.ibm.com/docs/atracker?topic=atracker-atracker-resources&format=markdown#atracker-resources-targets) in any [supported region](https://cloud.ibm.com/docs/atracker?topic=atracker-regions&format=markdown).

    You can control the locations in the account where a target is defined by specifying the allowed locations in the Activity Tracker Event Routing account settings.

    Target definitions are stored in the primary metadata location. If you have a backup metadata location, target definitions are also stored there.

- Route definitions are stored in the primary metadata location. If you have a backup metadata location, route definitions are also stored there.


### Auditing data
{: #data-security-audit}

Activity Tracker Event Routing routes management and data events from IBM Cloud services and resources:
* **Management Events** are generated when an API call changes the state of a Cloud resource. A resource might be an entire service instance or a resource managed by the service.
* **Data Events** are generated when an API call reads or modifies a resource's data.

Data from [IBM Cloud services and resources](https://cloud.ibm.com/docs/atracker?topic=atracker-cloud_services_atracker&format=markdown) is generated automatically.  However, you might need to upgrade the service plan, apply a  configuration setting, or both, to enable events in your account for selected services.

Activity Tracker Event Routing does not store auditing events. By configuring Activity Tracker Event Routing, you define the target where the auditing data that is generated in the account is routed and uploaded. You can route auditing events to targets that are available in the account or in a different account.
{: note}


## How your data is stored and encrypted
{: #data-storage}

### Configuration data
{: #data-security-storage-config}

You can configure Activity Tracker Event Routing resources by using public and private endpoints.

To ensure that you have enhanced control and security over your data, your account must be virtual routing and forwarding (VRF) enabled and you must use private routes to IBM Cloud&reg; service endpoints. Consider configuring Activity Tracker Event Routing resources over a private network connection.
{: note}

Activity Tracker Event Routing stores the configuration of settings, targets and routes for your account.
- Connections use TLS/SSL encryption for data in transit. The current supported version of this encryption is TLS 1.2.
- The storage where the configuration is stored is encrypted with LUKS using AES-256.


### Auditing data
{: #data-security-storage-audit}

You can define 1 or more routing rules that define how auditing events are routed in the account. Auditing data from an IBM Cloud service to your target service in IBM Cloud is secure via private connection. The connection supports TLS 1.2.

You can route auditing data to any of the following target types:
- An IBM Cloud Object Storage bucket: You create and manage the bucket, and the data that is collected in the bucket. For more information about COS data security, see [Data security](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-security&format=markdown).
- An IBM Cloud Logs instance: You manage the instance and the data that is collected in the instance. For more information, see [Data security](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-mng-data&format=markdown).
- An Event Streams topic: You create and manage the topic. For more information, see [Data security](https://cloud.ibm.com/docs/EventStreams?topic=EventStreams-data_security&format=markdown). 
- An IBM Cloud App Configuration instance: You manage the instance and the data that is collected in the instance. For more information, see [Data security](https://cloud.ibm.com/docs/app-configuration/build/app-configuration-review-output?topic=app-configuration-ac-data-security-and-compliance&format=markdown).


## How can you delete any stored data
{: #data-security-storage-delete}

### Configuration data
{: #data-security-storage-delete-config}


Activity Tracker Event Routing stores configuration data only.

You can delete any route or target by using the API, the CLI or terraform scripts. You can also reset account setting configuration, other than the primary metadata region, to empty values.

- To stop Activity Tracker Event Routing from routing audit events to the configured targets, you must [remove any default targets](https://cloud.ibm.com/docs/atracker?topic=atracker-target-default-reset&format=markdown) and delete all routes.
- To delete auditing event destinations, you must delete the target definitions.
- To remove any account setting, you can reset the account default settings.


### Auditing data
{: #data-security-storage-delete-audit}

To delete auditing data, check the target type instructions.
- For IBM Cloud Logs, see [Data security](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-mng-data&format=markdown).
- For IBM Cloud Object Storage bucket, see [Data security](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-security&format=markdown).
- For Event Streams, see [Data security](https://cloud.ibm.com/docs/EventStreams?topic=EventStreams-data_security&format=markdown). 
- For IBM Cloud App Configuration, see [Data security](https://cloud.ibm.com/docs/app-configuration?topic=app-configuration-ac-data-security-and-compliance&format=markdown).