Post-breach data control

Deployment and operating model

How PastWipe is deployed: on-premises, hybrid or cloud, with client-controlled data and keys, and enforcement that depends on the environment.

PastWipe™ is designed to add post-breach data control inside existing environments. It reduces the usable value of stolen or exfiltrated data outside approved conditions and complements the controls already in place.

Deployment options

PastWipe can be deployed on-premises, in hybrid environments or cloud-first, adjacent to the systems that hold the selected protected data.

Client-controlled data and keys

PastWipe's architecture is being developed around a strict zero-access operating model:

  • Client data remains in the client's own infrastructure, cloud account, virtual private cloud or approved trusted environment.
  • Encryption and decryption take place inside that client-controlled environment.
  • Cryptographic keys stay under the client's control through its own key-management system, hardware security module or equivalent.
  • PastWipe does not require access to client plaintext, client decryption keys or the underlying protected information.

A defined protection boundary

A deployment identifies where encryption occurs, where authorised processing may take place, which systems may request access and which routes must pass through the enforcement layer. This makes it possible to measure how much of the relevant workflow is actually covered.

Authorisation based on more than identity

Access decisions consider the requesting user or workload, the protected object, the permitted operation, the declared purpose, the applicable policy and the current security state. Where supported, workload and environment attestation confirms that a request comes from an approved, current execution environment.

Incident and recovery

  • Scoped response: security-state changes can apply to an object, dataset, application, workload, key family, tenant, region or jurisdiction.
  • Controlled recovery: revalidation, credential replacement and reauthorisation of approved workloads restore legitimate operations, with authority for the process kept by the client.

Offline and legacy environments

Offline operation may be possible for defined periods and policies, but it changes the trust model. Local validation, cached authority, device integrity, expiry, reconciliation and failure behaviour must be designed and tested for the specific environment. Enforcement is not identical across every legacy, offline or third-party workflow.

Data residency

Works with your security stack · Scope a controlled evaluation