2026.5 version release (September 2026)
New features
Click a product name below to expand its new features list for this version.
AI Assistant (Preview)
DCT now includes a broadly capable AI Assistant that lets you interact with the platform in natural language across Virtualization, Masking, Administration, and Synthetic Data workflows. Rather than clicking through the UI or writing API calls, you can ask the Assistant to find objects, answer questions about your environment, and carry out supported actions on your behalf from a single conversational experience.
The Assistant is aware of the page you are on, so you can refer to "this VDB" or "this account" without naming or searching for the object first, and it can navigate you to other objects on request. It is built with safeguards: bulk or high-impact operations prompt for confirmation before proceeding, and sensitive values such as database passwords are collected through a secure input path that keeps them out of the AI model, tool calls, logs, and on-screen traces entirely.
The AI Assistant is available as a preview in this release and is enabled through a feature flag. For more information, see DCT AI Assistant.
If you want to drive DCT from your own AI client, such as Claude Desktop, VS Code, or Cursor, you can stand up a separate DCT MCP Server, which is available today.
DCT-orchestrated engine upgrades (Preview)
DCT introduces centralized, DCT-managed orchestration of Continuous Data and Continuous Compliance engine upgrades, allowing engine upgrades to be initiated, monitored, and managed centrally across a single engine or multiple engines rather than through each engine's local SysAdmin UI.
Telemetry enforcement
Telemetry registration and regular export upload are now required. New installations and upgrades must complete telemetry registration within 30 days, and customers registering offline must upload telemetry at least every 90 days thereafter.
Administrators receive in-product alerts and notifications as these deadlines approach. If a deadline passes, DCT enters a restricted state: users can continue to navigate the product and view details, and can still make changes in the Admin section, but no new operations can be started. Any in-flight jobs complete normally, and existing VDBs continue to run. Restoring telemetry compliance returns the product to full function.
For more information, see Registration and telemetry.
Expanded Operations visibility
The Operations page now surfaces a more complete record of what happened to your data assets. Policy-triggered and engine-initiated actions appear alongside DCT-initiated jobs, deduplicated so an action driven through DCT is not counted twice, and attributed to the triggering policy or originating engine user where that can be resolved. Job events are now visible directly in DCT as well, which was one of the main reasons users previously had to go to the engine. Failed Virtualization operations now show the engine's Description, Recommended Action, and Command Output directly in the operation detail panel, so failures can be diagnosed without leaving DCT.
Customers with more than 10 engines may experience some slowness until the jobs are fully synced from the engines.
Bundled PostgreSQL 18 upgrade
DCT 2026.5.0 upgrades its bundled PostgreSQL database from version 14 to version 18 through an in-place migration. Because the migration shares heap inodes and has no in-product rollback, take a full backup before upgrading. This release is a required bridge step: customers on 2026.4.x or older must pass through 2026.5.0 before moving to later DCT releases. The migration itself completes in seconds; the longer part of the upgrade is the post-upgrade reindex sweep, which scales with the number of indexes rather than the size of the database.
DCT 2026.5.0 is also the bridge release for restoring backups created before the PostgreSQL 18 upgrade. Restore an older backup onto DCT 2026.5.0, allow the automatic database conversion to finish, and create a new backup before moving to a later release. The backup and restore tool verifies compatibility before modifying the target installation and reports whether a failed restore can be retried. New backups also preserve the AI control service encryption key, so stored AI provider credentials survive a restore.
External PostgreSQL 16.x support
For customers running DCT against an external PostgreSQL database, DCT now certifies PostgreSQL 16.x as a supported external database backend. As with 15.x, support tracks the 16.x line continuously rather than a specific minor version. Customers running an external PostgreSQL 14 database should plan to upgrade, as PostgreSQL 14 reaches end of life in November 2026. We plan to drop support for PostgreSQL 14 at the same time.
Lightweight Discovery for Oracle environments
Data Control Tower 2026.5.0 introduces Lightweight Discovery, an on-demand operation that discovers new, changed, or upgraded Oracle homes and new databases (CDBs, PDBs, and single-instance or RAC source configurations) on an already-configured Oracle environment without running a full environment refresh. Unlike a full environment refresh, it does not re-push the toolkit, re-discover the whole environment, or temporarily disable enabled dSources while it runs. Lightweight Discovery is supported for Oracle data sources in Unix/Linux standalone hosts and Oracle RAC clusters, is supported on DCT engines running version 2026.5.0 or later, and is available from the Refresh Environment dialog and the REST API.
PostgreSQL V2P and broad AppData (vSDK) support
This release delivers two related improvements to Virtual-to-Physical (V2P) export. First, the Delphix virtualization SDK (vSDK) now supports V2P, enabling AppData connectors to offer V2P export. Second, the DCT V2P wizard has been implemented for the latest release of the PostgreSQL data connector, which is the connector that fully supports V2P through the DCT UI at this time. The wizard dynamically renders connector-specific target and source configuration fields. Support for additional connectors will follow over time.
DCT UI support for SQL Server Availability Group VDBs
DCT now supports provisioning and managing MSSQL Availability Group VDBs from the UI. Administrators can use AG-aware provisioning steps, review AG fields and replica sync state on the VDB detail page, and inspect AG topology from Infrastructure detail pages.
Compliance Engine job migration
DCT now lets you migrate existing Masking, Tokenization, and Re-identification jobs from connected Compliance Engines into DCT management. You can track each migration and download a PDF or CSV report, then realign migrated rule sets and synchronize mapping data as needed. For more information, see Migrate jobs from Compliance Engines to DCT.
Containerized masking engines for DCT Compliance
DCT now fully supports containerized masking engines for DCT Compliance. You can use containerized engines as execution capacity for DCT-managed masking workloads.
Nullability validation for masking algorithms
DCT now prevents you from assigning a masking algorithm that can return null values to a database column marked as NOT NULL. This validation helps prevent incompatible masking assignments before job execution.
Compliance in DCT — Complete Migration Support
With 2026.5, the day-to-day masking and profiling functionality of the standalone Continuous Compliance engine now exists in Data Control Tower. Customers who have been running compliance workloads through the standalone Compliance engine UI can now run those same workflows through DCT. Delphix encourages existing customers to begin migrating their compliance operations to DCT.
Migration guides are available in the documentation to help existing customers move their compliance workloads to DCT.
Mainframe support
Compliance in DCT now supports connecting to IBM z/OS mainframe datasets, managing COBOL Copybook formats, creating Copybook rule sets, and profiling mainframe data with discovery jobs.
For more information, see Mainframe connectors, Create a data format, Create a rule set, and Create a discovery job for files.
Per-job non-conformant data handling for masking jobs
Compliance masking jobs run through DCT now let operators override non-conformant data handling at the job level. You can use the global default, fail on encounter, leave the value unmasked, or set the value to null, to match each job's required policy.
Import/Export Ruleset via CSV
With 2026.5, DCT now supports creating and updating rulesets by importing CSV files, as well as exporting existing rulesets to CSV. DCT also supports importing ruleset CSV files exported from Compliance engines, allowing existing Compliance engine rulesets to be brought into DCT and used as part of DCT compliance workflows.
General Availability
Delphix Synthetic Data Generation reaches General Availability in 2026.5, its first fully public release. Synthetic data extends the Delphix Test Data Management platform into use cases that virtualization and masking alone cannot serve: greenfield development where no production data exists, zero-risk data generation, and proactive edge-case and boundary testing. Delphix combines virtualization, masking, and synthetic generation in a single platform, with capabilities such as multi-system referential integrity, deterministic generation, and prompt-driven test data generation.
Data Control Tower Enterprise customers with the Synthetic Data add-on are entitled to two reference connectors.
Synthetic Data usage telemetry
Synthetic Data usage is now included in Delphix telemetry exports. Review the telemetry details for more information.
Custom JDBC connection properties
Synthetic Data connectors now support custom JDBC connection properties. Upload a CSV or .properties file to pass advanced driver settings, such as SSL options and connection timeouts, to the database driver during connector testing and data generation.
Multi-schema reference connectors
Reference connectors for schema-based sources can now include multiple schemas in a single connector instead of requiring one connector per schema. The connector status reported in DCT is an aggregate of the statuses of its schemas. DCT routes generated data to matching target schemas and groups tables and relationships by connector and schema.
After upgrading, jobs with mismatched reference and target schema names may fail. Ensure that a schema with the same name as the schema configured on the reference connector exists on the target database, then update or recreate the target connector before running the job.
Synthetic Data dataset enhancements
Synthetic Data now supports canceling long-running application sync, dataset pull, dataset duplication, and structure-deletion operations. DCT also improves dataset browsing, job tracking, AI-assisted table matching, field metadata visibility, and data-generation error handling.
The structure-comments PATCH endpoint was removed in this release. Update any API integrations that use this endpoint.
Composite primary and foreign key support
Synthetic Data now supports discovering and generating data for tables with composite primary and foreign keys in full-truncate and incremental generation modes. Synthetic Data validates composite-key assignments and key-space capacity before execution to prevent referential-integrity and duplicate-key failures.
Multi-column correlated generation
Synthetic Data now supports grouping multiple fields from the same table under one generator so related values, such as the components of a shipping address, are generated together and remain correlated. You can configure these groups in the Synthetic Data UI or through the generator-assignment API.
Generator enhancements
This release adds generator capabilities aimed at real-world enterprise data patterns:
-
Multi-column and multi-row function generators. A multi-column generator can return multiple values, each mapped to a column, so you no longer need to repeat the same code across related columns. Function generators support global definitions with placeholder arguments that are mapped when applied to a dataset.
-
Distribution generators. The distribution generator now supports well-known distributions such as normal, Zipf, and Poisson with configurable parameters, in addition to weighted distributions.
-
Null-proportion control. Each generator can be assigned a null-value percentage to more realistically reflect production data.
-
Lookup from reference and master data. A new lookup capability resolves values from reference or master data at generation time, including single-column lookups, coherent multi-column lookups, and conditional lookups. This also covers lookups from an uploaded seed file, supporting patterns such as deriving national IDs from a generated post code and city.
Additional Synthetic Data enhancements
-
Use data for discovery. Existing data can now be used to inform and drive synthetic data generation.
-
Getting-started packs. You can upload pre-built getting-started packs to accelerate time-to-value when standing up a new synthetic data project.
Application-level discovery settings
Synthetic Data applications now support application-level Locale, Industry, and Discovery Depth settings. These settings control the context and amount of source data used during discovery.
MCP Server
The Delphix MCP Server lets you drive Data Control Tower from your own MCP client, such as Claude Desktop, VS Code, or Cursor, against the public DCT API. This release focuses on making destructive and high-volume operations safe by default, enforced at the server rather than left to the discretion of the AI model or client.
View the MCP Server documentation for more information.
To use features in the Preview phase, you must first enable feature flags.
EOL features
-
Continuous Data UI end-of-life
As we transition to a Data Control Tower (Data Control Tower) platform experience, we are sunsetting all Continuous Data management and setup interfaces. The transition happens in stages:-
September 2026: Starting with 2026.5, new engine installations will no longer include the Management UI, while upgraded engines are unaffected.
-
July 2027: With 2027.4, all UI, CLI, and API interfaces are removed from new installs and upgrades, marking End of Maintenance; support will continue to triage issues and offer reasonable workarounds, with equivalent fixes delivered through Data Control Tower or interface-free engine upgrades.
-
January 2029: End of Maintenance and Support concludes.
As you migrate, your data, dSources, virtual databases, and configurations remain fully intact; only the interfaces change. All Delphix customers are entitled to Data Control Tower, and we recommend installing it and connecting your engines now to begin the transition.
For more information, read the full announcement and FAQ.
-
-
PostgreSQL 14 reaches end of life in November 2026
The next DCT release will drop support for PostgreSQL 14. Customers on the bundled PostgreSQL 14 (Appliance or K8s) will upgrade to PostgreSQL 18 automatically in 2026.5+. Customers on an external PostgreSQL 14 database (K8s only) should plan their upgrade accordingly.
Fixed issues
| Issue ID | Description |
| APIGW-25258 | [DCT Compliance] Compliance job imports from older sync bundles now preserve constraint, trigger, and index task settings. |
| APIGW-13091 | When two DCT-managed policy changes are run against the same VDB at the same time, the first policy-apply job is no longer left stuck in a Pending state that never clears. |
| APIGW-14207 | A VDB or dSource no longer displays an inaccurate status in the DCT UI compared to the engine, including cases where the status appeared as Unknown. Data status now reflects the engine's state accurately. |
| APIGW-14229 | Actions initiated by engine-side policy workers, such as policy-driven refresh or snapshot jobs, are now visible in the Operations view instead of being omitted from DCT. |
| APIGW-14503 | When actions are taken against an offline engine, such as refreshing a VDB, DCT now clearly indicates that the operation could not proceed because the target engine was unreachable. |
| APIGW-23773 | A file uploaded during Compliance data-format or rule-set creation is no longer accessible only to the admin user; scoped (non-admin) accounts can access the files they own through the UI wizards. |
Known issues
| Issue ID | Description | Workaround |
| APIGW-11704 | Certificate (truststore) changes made in the appliance System Setup are not picked up by the masking service until the application is restarted, so engine registration can continue to fail immediately after importing certificates. | Restart DCT (in the Appliance model, use System Setup → Restart or Reboot) after importing or deleting certificates. |
| APIGW-12408 | Submitting a very large hook can cause DCT to return an internal server error. | N/A |
| APIGW-13599 | When a Compliance Engine data admin login fails due to invalid credentials, the engine may continue to appear as "Online" in the DCT interface. Users are not alerted to the failed login, which can result in stale utilization data and other inaccurate reporting. | N/A |
| APIGW-13711 | When creating or updating policies through the API or DCT Toolkit, cron expressions are not validated. Submitting an invalid cron expression may cause policy apply jobs to remain in a STARTED state without user feedback. This issue does not affect users working through the UI, where cron validation is already enforced (APIGW-13709). | N/A |
| APIGW-14407 | When a Virtualization operation fails server-side validation, the DCT UI displays only a generic error message without the specific validation details. | Use the DCT API directly to retrieve the detailed error response. |
| APIGW-14545 | Replication profiles deleted directly from the engine are not automatically removed from DCT and continue to appear. | Restart DCT to force a sync, which removes the stale replication profiles. |
| APIGW-14899 | When hooks are imported into DCT from a connected Continuous Data engine, the execution order of hooks is not preserved. Operations that depend on a specific hook execution order may behave incorrectly after import. | Manually reorder hooks in DCT after import using the Reorder function. |
| APIGW-16124 | When refreshing a VDB from a bookmark that contains both a snapshot reference and a timeflow bookmark reference, DCT always uses the snapshot reference and ignores the timeflow bookmark, which may refresh the VDB to an unintended point in time. | N/A |
| APIGW-16461 | When a field value is unset on a compliance job (for example, Row Limit), the backend sets the field to the application default value rather than leaving it unset. Users who intentionally clear a field may see an unexpected value after saving. | N/A |
| APIGW-22659 | When editing a DCT-managed Snapshot or Refresh policy, the sync interval resets to "1" in the edit dialog (making it easy to save the wrong value), and the policy View page displays the "Starting at" time offset by several hours from what was selected. | N/A |
| APIGW-26211 | A Compliance engine can be added both as an orchestrator node and as a Compliance engine if one registration uses the engine's IP address and the other uses its hostname; the duplicate is only blocked when both use the hostname. | N/A |