Compliance, privacy and security, clearly stated.
PastWipe builds for the reality that breaches happen. PastWipe™ focuses on reducing the usable value of stolen or exfiltrated copies outside approved conditions, while preserving lawful access, auditability and interoperability.
This page summarises security controls, privacy posture, incident response and vendor management for procurement and security review.
- Security controls documented
- Independent assurance summaries on request, under NDA
- GDPR-first posture
- Responsible disclosure
PastWipe does not claim any certification.
At a glance
- Data minimisation: we prioritise minimal collection and retention, and reduce unnecessary copies to limit exposure.
- Encryption: encryption in transit and at rest for applicable systems, with strict controls around keys and access.
- Access governance: role-based access, least privilege, multi-factor authentication and periodic access reviews.
- Auditability: security-relevant events are logged and monitored to support investigations and assurance.
Security and compliance contacts: compliance@pastwipe.com · security@pastwipe.com · privacy@pastwipe.com
Security programme
Ref: PW-SEC-CTRL · Classification: public summary
Governance, technical controls and operational practices designed to protect PastWipe services and customer data.
Security governance
- Accountability: security and compliance ownership assigned, with documented escalation paths.
- Risk management: periodic risk assessments and remediation tracking.
- Change control: controlled deployments to production with peer review and rollback capability.
- Security policies: access control, incident response, vendor risk, retention and secure development policies maintained and reviewed.
Identity and access management
- Least privilege: access granted only to perform job functions, reviewed at least quarterly.
- MFA: multi-factor authentication required for administrative interfaces and privileged actions.
- Environment separation: segmentation between development, staging and production environments.
- Secrets handling: secrets are stored in managed secret stores; rotation and revocation supported.
Encryption and key protection
- In transit: TLS enforced for web and API traffic.
- At rest: encryption for databases, storage volumes and backups where applicable.
- Key access control: key access restricted and logged; separation between key management and application roles.
- Cryptographic agility: upgrade paths for cryptographic primitives and parameters are considered in design.
Monitoring and logging
- Security logs: authentication, authorisation and administrative activity logged.
- Alerting: detection for anomalous sign-in patterns, privilege changes and data-access anomalies.
- Log retention: security logs are retained for a defined period for investigation and assurance.
Secure development lifecycle
- Code review: all production changes undergo peer review; security-sensitive changes require additional reviewer approval.
- Dependency management: third-party components are tracked; known vulnerabilities are triaged and patched based on severity.
- Testing: automated testing and environment controls reduce regressions and configuration drift.
- Security assessments: periodic independent testing of externally exposed surfaces; executive summaries available under NDA.
Product security intent
PastWipe focuses on reducing the usable value of exfiltrated copies outside approved conditions. Where applicable, this is reinforced through cryptographic controls, authorisation, policy enforcement and auditability designed to support governance after compromise. RepSec™ is an optional protocol framework.
Privacy and GDPR summary
Ref: PW-PRIV-GDPR · Public summary
How PastWipe handles personal data, lawful bases, data-subject rights and international transfers. The full privacy policy applies.
Roles and scope
PastWipe Ltd (Company Number 16893742) acts as a data processor when providing services to customers (processing on documented instructions), and as a data controller for limited business-operations data (billing, support communications and marketing preferences).
Personal data categories
- Account and identity data: name, email, organisation, role, authentication metadata.
- Operational and security data: logs, event metadata and system telemetry used to maintain security and reliability.
- Support data: information submitted in tickets and emails, including attachments.
- Website data: IP address and basic analytics events, when enabled, for site performance and security.
Lawful bases (typical)
- Performance of contract (delivering the service).
- Legitimate interests (security, fraud prevention, service improvement).
- Legal obligation (tax, accounting, lawful requests).
- Consent (marketing communications when required).
Data-subject rights
Access, rectification, erasure, restriction, portability and objection; withdrawal of consent where consent is the basis; complaint to a supervisory authority.
How to exercise your rights: email privacy@pastwipe.com with the subject "Data Subject Request". Requests are handled within 30 days unless complexity requires an extension permitted by applicable law.
International transfers
Where transfers outside the UK/EEA occur, PastWipe applies appropriate safeguards, including Standard Contractual Clauses and vendor assessments. Transfer risk is reviewed and updated as vendor footprints change.
Data Processing Addendum
A Data Processing Addendum is available for business customers, including SCCs where required. Requests: compliance@pastwipe.com.
Privacy principles
- Minimisation: collect and retain only what is necessary.
- Purpose limitation: use data for defined, legitimate purposes.
- Security by design: controls embedded in architecture and operations.
- Transparency: clear summaries and contractual commitments for customers.
Data handling and retention
Ref: PW-DATA-HND · Public summary
Retention overview
PastWipe limits retention by design and maintains defined retention periods for operational needs, security assurance and legal obligations. Retention may vary by customer contract, deployment model and regulatory requirements.
| Data type | Retention | Purpose |
|---|---|---|
| Support tickets and attachments | 24 months | Customer support quality and continuity |
| System metrics and telemetry | 90 days | Reliability and performance monitoring |
Deletion and offboarding
- Customer-requested deletion: supported subject to legal and contractual constraints.
- Contract termination: data return and deletion performed per agreement and DPA terms.
- Backups: residual copies may persist until backup rotation completes.
Customer controls
- Role-based permissions: administrative and user roles with scoped privileges.
- Audit logs: visibility into sensitive actions and administrative events.
- Export capability: customer data export supported where applicable.
Data-handling boundary
Avoid sending highly sensitive secrets (private keys, unredacted credentials, special-category personal data) through general support channels unless a controlled secure exchange process is explicitly agreed.
Incident response and breach notification
Ref: PW-IR-PLAN · Public summary
Detection and triage
- Continuous monitoring for suspicious activity and operational anomalies.
- Documented triage process to validate severity, scope and affected assets.
- Evidence preservation (logs, timelines, indicators) to support investigation.
Containment and remediation
- Containment actions may include credential rotation, access restrictions and service isolation.
- Root-cause analysis and remediation tracked to completion, with post-incident review.
- Security learnings feed back into controls, tooling and secure development practices.
Notification principles
If an incident results in unauthorised access to customer data, PastWipe notifies affected customers without undue delay and provides the details needed for risk assessment and regulatory obligations.
Notifications cover:
- what happened, and the timeline of discovery and response;
- systems and data types potentially affected;
- actions taken, containment status and recommended customer actions;
- ongoing updates until resolution.
| Communication | Target |
|---|---|
| Initial acknowledgement of incident reports | Within 24 hours |
| First substantive status update (where feasible) | Within 72 hours |
| Customer notification after confirming unauthorised access to customer data | Without undue delay |
Incident coordination: security@pastwipe.com
Vendors and subprocessors
Ref: PW-VEND-RISK · Public summary
PastWipe uses selected vendors for infrastructure, security, customer communications, billing and support. Vendors are assessed for security and privacy risk and engaged with contractual safeguards appropriate to their role.
| Vendor | Purpose | Data processed | Primary region |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, storage, managed databases | Service data, account data, logs, backups | EU (Spain/Frankfurt) with global resilience options |
| Cloudflare | DNS, CDN, DDoS protection, WAF | IP addresses, request metadata, security telemetry | Global edge with EU processing controls |
| Google Workspace | Email and internal collaboration | Business contact data, support correspondence | EU/global depending on tenant settings |
| Stripe | Payment processing | Billing identifiers, transaction metadata | EU/US depending on payment flows |
| Zendesk | Customer support ticketing | Support requests, contact data, attachments | EU/US depending on tenant settings |
Subprocessor change notice: enterprise agreements may include notice of material subprocessor changes and the right to object where appropriate.
Legal, contracts and assurance
Ref: PW-LEGAL · Public summary
Documents available for review
- Data Processing Addendum (DPA), including Standard Contractual Clauses where required.
- Mutual NDA for exchanging confidential security documentation.
- Security overview and architecture summary.
- Policy set: incident response, access control, secure development, retention, vendor risk.
- Independent assessment summaries where available (under NDA).
Framework mapping for procurement
PastWipe is designed to support evidence for:
- GDPR (EU/EEA) and UK GDPR privacy and data-processing commitments;
- security control domains organised along ISO/IEC 27001-style topics (governance, access, operations, supplier risk);
- control topics organised along SOC 2-style principles (security, availability, confidentiality) where applicable.
This is a mapping to support procurement review. It is not a certification or attestation.
Vendor questionnaires supported: SIG Lite, CAIQ and custom assessments.
Procurement contact: compliance@pastwipe.com
Legal note: this page is an informational summary and does not modify any contract, warranty or service terms. In the event of conflict, the executed customer agreement and DPA govern.
Responsible disclosure
Ref: PW-VULN-DISC · Public
Reporting channel
Email security@pastwipe.com with the subject "Vulnerability Report". Include the affected component or URL, reproduction steps, an impact assessment and a proof of concept if available.
Researcher guidelines
- Do not access, modify or exfiltrate data beyond what is necessary to demonstrate impact.
- Do not disrupt services (no DDoS, destructive testing or production outages).
- Provide reasonable time for remediation before public disclosure.
Response targets
| Milestone | Target |
|---|---|
| Acknowledgement of report | Within 2 business days |
| Initial triage outcome | Within 7 business days |
| Remediation timeline communicated | Within 14 business days |
Safe harbour (summary)
If you follow the guidelines above and act in good faith, PastWipe will not pursue legal action solely for your research. This does not cover extortion, social engineering, intentional disruption or attempts to access data beyond what is required to validate impact.
Security contact key
Cookies and website analytics
Ref: PW-COOKIE · Public summary
- Strictly necessary: required to operate the website and core functions.
- Preferences: remember user choices and reduce friction.
- Analytics: measure site performance and usage to improve content and reliability.
- Marketing: advertising and retargeting features, where enabled.
You can control cookies in your browser settings and clear stored cookies at any time. See the cookie policy.
FAQ
Do you sign DPAs and Standard Contractual Clauses? Yes. PastWipe provides a Data Processing Addendum for business customers. Where required for cross-border transfers, Standard Contractual Clauses are included and transfer safeguards are documented.
Do you support vendor security questionnaires? Yes. PastWipe supports common procurement questionnaires, including SIG Lite and CAIQ, and can complete organisation-specific vendor assessments.
How long do you retain backups and logs? Retention periods for backups and logs are provided in the DPA and security documentation on request.
How do you handle vulnerability reports? Reports are acknowledged within 2 business days. PastWipe provides an initial triage outcome within 7 business days and communicates a remediation timeline within 14 business days, depending on severity and complexity.
What is PastWipe's compliance focus? PastWipe builds its privacy commitments around GDPR and UK GDPR, and organises its controls so they map to widely used security frameworks (ISO/IEC 27001-style domains and SOC 2-style principles). PastWipe does not claim certification. Where independent assurance summaries are available, they are shared under NDA.
Contact
| Topic | Contact | Typical response window |
|---|---|---|
| Privacy / GDPR | privacy@pastwipe.com | Within 5 business days (DSRs completed within 30 days) |
| Security incidents | security@pastwipe.com | Within 24 hours for initial acknowledgement |
| Compliance / procurement | compliance@pastwipe.com | Within 5 business days |
| Legal | legal@pastwipe.com | Within 10 business days |
PastWipe Ltd (Company Number 16893742).