Basics
What is PastWipe? PastWipe™ provides post-breach data control for enterprise and government. It reduces the usable value of stolen or exfiltrated data outside approved conditions, using policy, cryptographic validation, identity and device context, and evidence records. What is PastWipe?
Who is PastWipe for? Enterprises and government bodies, and the insurers, incident responders and advisers who support them. Priority sectors include corporate enterprises, insurance, public sector, banking and finance, healthcare, education, legal and IP, and marine. Sectors
Does PastWipe replace DLP, EDR, IAM or incident response? No. Those controls remain essential. PastWipe adds a separate control stage for protected data that has already moved beyond the original trust boundary. Integrations
Does PastWipe stop every stolen file being used? No universal claim is credible. The achievable outcome depends on the protected format, integration, workflow, policy, available context signals and whether an unrestricted plaintext copy already exists. The objective is measurable reduction of utility and legitimate acceptance under unsupported conditions.
Is this a replacement for encryption? No. Encryption protects confidentiality when keys and access remain controlled. PastWipe addresses whether data should still be usable when the surrounding conditions, identity, device or purpose are no longer trusted.
RepSec
What is RepSec? RepSec™ is an optional protocol framework for expressing policy, validation and evidence consistently across participating systems. About RepSec
Is RepSec required? No. PastWipe operates without RepSec.
What is RepSec-Q? A development direction extending RepSec toward post-quantum resilience. Post-quantum claims depend on the selected cryptography and implementation. About RepSec-Q
How it works
How does PastWipe control data after it moves? Protected data is associated with policy. At the point of use, PastWipe checks whether current identity, device, environment, time and purpose conditions still satisfy that policy, then allows, denies, restricts or degrades the result and records the decision. How it works
Which data types can be protected? It depends on the formats and applications integrated. Common office documents, structured exports and application data are typical starting points.
What if someone photographs the screen or retypes the content? PastWipe cannot stop that in every case. An authorised viewer may still create another physical representation.
Can use be withdrawn after sharing? Where the workflow remains under supported control, use can be restricted, expired or withdrawn. Copies that have already become unrestricted plaintext may be outside enforcement.
Can PastWipe work offline? Offline operation may be possible for defined periods and policies, but it changes the trust model and must be designed and tested for the environment.
Deployment and integration
On-premises, cloud or hybrid? PastWipe is designed for on-premises, hybrid and cloud-first deployments, with client-controlled data and keys. Deployment
Does PastWipe need access to our data or keys? PastWipe's architecture is being developed so that it does not require access to client plaintext or decryption keys. Deployment
Does PastWipe integrate with our identity provider and SIEM? PastWipe uses identity and device signals from existing systems and sends evidence records to monitoring and response tools. Integrations
Security, privacy and compliance
Does PastWipe make us compliant? No. PastWipe is designed to support evidence for obligations such as GDPR, UK GDPR, NIS2 and DORA. It does not replace your compliance programme. Regulatory evidence
Does PastWipe hold certifications? PastWipe does not claim any certification. Security documentation and any independent assessment summaries are available to qualified parties under NDA. Trust Centre
Is patent protection in place? US patent pending. Legal notices
How do we report a security issue? Email security@pastwipe.com. Responsible disclosure
Evaluation and buying
How do we evaluate PastWipe? Through a scoped controlled evaluation against a defined data class and workflow, with success criteria agreed in advance. Controlled evaluation
How is PastWipe priced? PastWipe is scoped per engagement. Contact us to discuss your environment. Contact
Do you work with partners? Yes: MSSPs, resellers, incident-response practices and technology partners. Partners
Media and analyst enquiries? See the press page or email press@pastwipe.com.