Our mission
Reduce the value of stolen data. Prove correct use.
Data theft will never be reduced to zero, and neither will mistakes, misconfigurations or vendor-side leaks. What can be reduced is the usable value of data once it leaves the conditions under which it is meant to be used.
PastWipe's mission is to reduce the usable value of stolen or exfiltrated data outside approved conditions, and to turn governance from a static document into a verifiable record. PastWipe associates enforceable rules with data so that use is purpose-bound, time-limited and revocable, including where data crosses a boundary, where AI agents are involved and where several third-party systems are in the path, subject to the supported workflow.
Three audiences, one control
- Security leaders need assurance that a breach need not become a catastrophe. PastWipe reduces the usable value of exfiltrated data outside permitted conditions.
- Risk, legal and compliance teams need evidence, not promises. PastWipe records tamper-evident events showing who used what, when and for what declared purpose.
- Product and operations teams need to move quickly without fear. PastWipe lets data move to where it creates value, such as analytics, cross-agency exchange, supply-chain partners and AI assistants, while keeping use within bounds you can demonstrate.
Four design principles
- Policy that travels with the data. A thin control layer mediates access and expresses policy as enforceable conditions. We assume data will cross trust zones. The layer evaluates identity, device and environment context and records the result.
- Purpose before payload. A purpose is declared and checked before sensitive use. Purpose is scoped to a data class, a time window and sometimes a specific task or case.
- Proof over promises. Control decisions produce signed events that can flow to SIEM/SOAR tools, dashboards and board reporting. The aim is to show that enforcement happened, or that it did not.
- Human- and agent-aware by design. AI agents are treated as actors with identities, capabilities and limits. They request purpose-scoped access like any other actor, and their actions are recorded with the same rigour.
What this looks like in practice (illustrative)
- Government: citizen records shared across agencies with purpose-limited disclosure, withdrawal of use and an evidence trail.
- Financial services: KYC/AML datasets circulating across vendors are usable only for a declared purpose and period.
- Healthcare and life sciences: clinical data stays useful for care coordination and research, with evidence of adherence to consent and protocol boundaries.
- Enterprises generally: post-incident conversations become factual: which entities requested what, why, and whether conditions were met.
Our vision
Useful without being vulnerable.
We envision a world in which sensitive information can be shared and analysed with confidence because the terms of its use are enforceable and the facts of its use are verifiable.
Software increasingly plans, acts and collaborates as an agent. Risk does not simply increase; it changes shape. Our vision is an agent-aware governance layer in everyday operations: agents propose a purpose, request the minimum data needed and operate under time- and scope-limited grants, with every decision recorded.
We expect governments and industries to converge on a few bedrock expectations: purpose limitation, data minimisation, withdrawal of use, traceability and demonstrable compliance. PastWipe's vision is to make those expectations operational.
Interoperability
Meaningful protection cannot be achieved by forcing organisations into a monolithic stack. PastWipe is designed to work with existing identity platforms, data catalogues, encryption and HSM tooling, data pipelines, DLP/CASB layers and incident-response tooling.
Why now
- Agentic software became real. When an agent acts, an organisation must know which data was accessed, for what purpose and under what conditions.
- Data velocity increased. Data moves through services, SaaS tools, contractor environments and partner platforms. Governance needs to stay effective across those hops.
- Assurance pressure intensified. Boards, insurers and regulators expect evidence. After an incident, leadership needs to know what was touched, what was not, and why.
PastWipe complements, and does not replace, identity, encryption, DLP, CASB, EDR and GRC tools. Breaches may be inevitable; the aim is to narrow their impact and make the facts clear.
RepSec and intellectual property
RepSec™ is an optional protocol framework. PastWipe operates without it. RepSec is designed to support consistent policy and evidence exchange across participating systems. US patent pending.
Limits
PastWipe cannot stop every breach, every screenshot or every retyped copy, and cannot withdraw use from copies that have already become unrestricted plaintext. See full limitations