Post-breach data control

Compliance & Trust Centre

PastWipe security programme, privacy and GDPR summary, data handling, incident response, subprocessors, procurement documents and responsible disclosure.

Compliance, privacy and security, clearly stated.

PastWipe builds for the reality that breaches happen. PastWipe™ focuses on reducing the usable value of stolen or exfiltrated copies outside approved conditions, while preserving lawful access, auditability and interoperability.

This page summarises security controls, privacy posture, incident response and vendor management for procurement and security review.

  • Security controls documented
  • Independent assurance summaries on request, under NDA
  • GDPR-first posture
  • Responsible disclosure

PastWipe does not claim any certification.

At a glance

  • Data minimisation: we prioritise minimal collection and retention, and reduce unnecessary copies to limit exposure.
  • Encryption: encryption in transit and at rest for applicable systems, with strict controls around keys and access.
  • Access governance: role-based access, least privilege, multi-factor authentication and periodic access reviews.
  • Auditability: security-relevant events are logged and monitored to support investigations and assurance.

Security and compliance contacts: compliance@pastwipe.com · security@pastwipe.com · privacy@pastwipe.com

Security programme

Ref: PW-SEC-CTRL · Classification: public summary

Governance, technical controls and operational practices designed to protect PastWipe services and customer data.

Security governance

  • Accountability: security and compliance ownership assigned, with documented escalation paths.
  • Risk management: periodic risk assessments and remediation tracking.
  • Change control: controlled deployments to production with peer review and rollback capability.
  • Security policies: access control, incident response, vendor risk, retention and secure development policies maintained and reviewed.

Identity and access management

  • Least privilege: access granted only to perform job functions, reviewed at least quarterly.
  • MFA: multi-factor authentication required for administrative interfaces and privileged actions.
  • Environment separation: segmentation between development, staging and production environments.
  • Secrets handling: secrets are stored in managed secret stores; rotation and revocation supported.

Encryption and key protection

  • In transit: TLS enforced for web and API traffic.
  • At rest: encryption for databases, storage volumes and backups where applicable.
  • Key access control: key access restricted and logged; separation between key management and application roles.
  • Cryptographic agility: upgrade paths for cryptographic primitives and parameters are considered in design.

Monitoring and logging

  • Security logs: authentication, authorisation and administrative activity logged.
  • Alerting: detection for anomalous sign-in patterns, privilege changes and data-access anomalies.
  • Log retention: security logs are retained for a defined period for investigation and assurance.

Secure development lifecycle

  • Code review: all production changes undergo peer review; security-sensitive changes require additional reviewer approval.
  • Dependency management: third-party components are tracked; known vulnerabilities are triaged and patched based on severity.
  • Testing: automated testing and environment controls reduce regressions and configuration drift.
  • Security assessments: periodic independent testing of externally exposed surfaces; executive summaries available under NDA.

Product security intent

PastWipe focuses on reducing the usable value of exfiltrated copies outside approved conditions. Where applicable, this is reinforced through cryptographic controls, authorisation, policy enforcement and auditability designed to support governance after compromise. RepSec™ is an optional protocol framework.

Privacy and GDPR summary

Ref: PW-PRIV-GDPR · Public summary

How PastWipe handles personal data, lawful bases, data-subject rights and international transfers. The full privacy policy applies.

Roles and scope

PastWipe Ltd (Company Number 16893742) acts as a data processor when providing services to customers (processing on documented instructions), and as a data controller for limited business-operations data (billing, support communications and marketing preferences).

Personal data categories

  • Account and identity data: name, email, organisation, role, authentication metadata.
  • Operational and security data: logs, event metadata and system telemetry used to maintain security and reliability.
  • Support data: information submitted in tickets and emails, including attachments.
  • Website data: IP address and basic analytics events, when enabled, for site performance and security.

Lawful bases (typical)

  • Performance of contract (delivering the service).
  • Legitimate interests (security, fraud prevention, service improvement).
  • Legal obligation (tax, accounting, lawful requests).
  • Consent (marketing communications when required).

Data-subject rights

Access, rectification, erasure, restriction, portability and objection; withdrawal of consent where consent is the basis; complaint to a supervisory authority.

How to exercise your rights: email privacy@pastwipe.com with the subject "Data Subject Request". Requests are handled within 30 days unless complexity requires an extension permitted by applicable law.

International transfers

Where transfers outside the UK/EEA occur, PastWipe applies appropriate safeguards, including Standard Contractual Clauses and vendor assessments. Transfer risk is reviewed and updated as vendor footprints change.

Data Processing Addendum

A Data Processing Addendum is available for business customers, including SCCs where required. Requests: compliance@pastwipe.com.

Privacy principles

  • Minimisation: collect and retain only what is necessary.
  • Purpose limitation: use data for defined, legitimate purposes.
  • Security by design: controls embedded in architecture and operations.
  • Transparency: clear summaries and contractual commitments for customers.

Data handling and retention

Ref: PW-DATA-HND · Public summary

Retention overview

PastWipe limits retention by design and maintains defined retention periods for operational needs, security assurance and legal obligations. Retention may vary by customer contract, deployment model and regulatory requirements.

Data type Retention Purpose
Support tickets and attachments 24 months Customer support quality and continuity
System metrics and telemetry 90 days Reliability and performance monitoring

Deletion and offboarding

  • Customer-requested deletion: supported subject to legal and contractual constraints.
  • Contract termination: data return and deletion performed per agreement and DPA terms.
  • Backups: residual copies may persist until backup rotation completes.

Customer controls

  • Role-based permissions: administrative and user roles with scoped privileges.
  • Audit logs: visibility into sensitive actions and administrative events.
  • Export capability: customer data export supported where applicable.

Data-handling boundary

Avoid sending highly sensitive secrets (private keys, unredacted credentials, special-category personal data) through general support channels unless a controlled secure exchange process is explicitly agreed.

Incident response and breach notification

Ref: PW-IR-PLAN · Public summary

Detection and triage

  • Continuous monitoring for suspicious activity and operational anomalies.
  • Documented triage process to validate severity, scope and affected assets.
  • Evidence preservation (logs, timelines, indicators) to support investigation.

Containment and remediation

  • Containment actions may include credential rotation, access restrictions and service isolation.
  • Root-cause analysis and remediation tracked to completion, with post-incident review.
  • Security learnings feed back into controls, tooling and secure development practices.

Notification principles

If an incident results in unauthorised access to customer data, PastWipe notifies affected customers without undue delay and provides the details needed for risk assessment and regulatory obligations.

Notifications cover:

  • what happened, and the timeline of discovery and response;
  • systems and data types potentially affected;
  • actions taken, containment status and recommended customer actions;
  • ongoing updates until resolution.
Communication Target
Initial acknowledgement of incident reports Within 24 hours
First substantive status update (where feasible) Within 72 hours
Customer notification after confirming unauthorised access to customer data Without undue delay

Incident coordination: security@pastwipe.com

Vendors and subprocessors

Ref: PW-VEND-RISK · Public summary

PastWipe uses selected vendors for infrastructure, security, customer communications, billing and support. Vendors are assessed for security and privacy risk and engaged with contractual safeguards appropriate to their role.

Vendor Purpose Data processed Primary region
Amazon Web Services (AWS) Cloud hosting, storage, managed databases Service data, account data, logs, backups EU (Spain/Frankfurt) with global resilience options
Cloudflare DNS, CDN, DDoS protection, WAF IP addresses, request metadata, security telemetry Global edge with EU processing controls
Google Workspace Email and internal collaboration Business contact data, support correspondence EU/global depending on tenant settings
Stripe Payment processing Billing identifiers, transaction metadata EU/US depending on payment flows
Zendesk Customer support ticketing Support requests, contact data, attachments EU/US depending on tenant settings

Subprocessor change notice: enterprise agreements may include notice of material subprocessor changes and the right to object where appropriate.

Legal, contracts and assurance

Ref: PW-LEGAL · Public summary

Documents available for review

  • Data Processing Addendum (DPA), including Standard Contractual Clauses where required.
  • Mutual NDA for exchanging confidential security documentation.
  • Security overview and architecture summary.
  • Policy set: incident response, access control, secure development, retention, vendor risk.
  • Independent assessment summaries where available (under NDA).

Framework mapping for procurement

PastWipe is designed to support evidence for:

  • GDPR (EU/EEA) and UK GDPR privacy and data-processing commitments;
  • security control domains organised along ISO/IEC 27001-style topics (governance, access, operations, supplier risk);
  • control topics organised along SOC 2-style principles (security, availability, confidentiality) where applicable.

This is a mapping to support procurement review. It is not a certification or attestation.

Vendor questionnaires supported: SIG Lite, CAIQ and custom assessments.

Procurement contact: compliance@pastwipe.com

Legal note: this page is an informational summary and does not modify any contract, warranty or service terms. In the event of conflict, the executed customer agreement and DPA govern.

Responsible disclosure

Ref: PW-VULN-DISC · Public

Reporting channel

Email security@pastwipe.com with the subject "Vulnerability Report". Include the affected component or URL, reproduction steps, an impact assessment and a proof of concept if available.

Researcher guidelines

  • Do not access, modify or exfiltrate data beyond what is necessary to demonstrate impact.
  • Do not disrupt services (no DDoS, destructive testing or production outages).
  • Provide reasonable time for remediation before public disclosure.

Response targets

Milestone Target
Acknowledgement of report Within 2 business days
Initial triage outcome Within 7 business days
Remediation timeline communicated Within 14 business days

Safe harbour (summary)

If you follow the guidelines above and act in good faith, PastWipe will not pursue legal action solely for your research. This does not cover extortion, social engineering, intentional disruption or attempts to access data beyond what is required to validate impact.

Security contact key

Cookies and website analytics

Ref: PW-COOKIE · Public summary

  • Strictly necessary: required to operate the website and core functions.
  • Preferences: remember user choices and reduce friction.
  • Analytics: measure site performance and usage to improve content and reliability.
  • Marketing: advertising and retargeting features, where enabled.

You can control cookies in your browser settings and clear stored cookies at any time. See the cookie policy.

FAQ

Do you sign DPAs and Standard Contractual Clauses? Yes. PastWipe provides a Data Processing Addendum for business customers. Where required for cross-border transfers, Standard Contractual Clauses are included and transfer safeguards are documented.

Do you support vendor security questionnaires? Yes. PastWipe supports common procurement questionnaires, including SIG Lite and CAIQ, and can complete organisation-specific vendor assessments.

How long do you retain backups and logs? Retention periods for backups and logs are provided in the DPA and security documentation on request.

How do you handle vulnerability reports? Reports are acknowledged within 2 business days. PastWipe provides an initial triage outcome within 7 business days and communicates a remediation timeline within 14 business days, depending on severity and complexity.

What is PastWipe's compliance focus? PastWipe builds its privacy commitments around GDPR and UK GDPR, and organises its controls so they map to widely used security frameworks (ISO/IEC 27001-style domains and SOC 2-style principles). PastWipe does not claim certification. Where independent assurance summaries are available, they are shared under NDA.

Contact

Topic Contact Typical response window
Privacy / GDPR privacy@pastwipe.com Within 5 business days (DSRs completed within 30 days)
Security incidents security@pastwipe.com Within 24 hours for initial acknowledgement
Compliance / procurement compliance@pastwipe.com Within 5 business days
Legal legal@pastwipe.com Within 10 business days

PastWipe Ltd (Company Number 16893742).