London, 18 July 2026. PastWipe Ltd has announced a substantial strengthening of its architecture, following detailed requirements from CISOs, security architects, incident-response specialists, insurers and enterprise technical evaluators.
Update, 29 September 2026: the capabilities below are scoped per evaluation, and what is included in a given evaluation is written into its scope. Scope an evaluation
Client-controlled data and keys
At the centre of the architecture is a strict zero-access operating model:
- client data remains in the client's own infrastructure, cloud account or approved trusted environment
- encryption and decryption take place inside that client-controlled environment
- keys stay under the client's control through its own key-management system or HSM
- PastWipe does not require access to client plaintext, decryption keys or the protected information
The client controls the data. The client controls the keys. The client controls the security response.
What the architecture includes
- A defined protection boundary: where encryption occurs, where authorised processing may take place, which systems may request access and which routes must pass through enforcement, so that coverage can be measured.
- Authorisation based on more than identity: short-lived, proof-of-possession authorisations bound to the requester, the object and its version, the operation, the declared purpose, the policy and the current incident state, with protections against replay and rollback.
- Workload and environment attestation: confirmation that a request comes from an approved, current execution environment, depending on the deployment.
- Scoped incident states: security changes applied to an object, dataset, application, workload, key family, tenant, region or jurisdiction, so unaffected systems keep working. Authorisations issued under an earlier state can be rejected across the defined scope.
- Trusted recovery: fresh attestation, credential replacement, key rotation, policy reissue and reauthorisation of approved workloads, with authority kept by the client.
- Control-plane security: hardware-backed signing, mutual TLS, administrative separation, short-lived operational credentials and tamper-evident logging.
- Privacy-minimised evidence: cryptographic receipts that show an approved action took place under a defined policy and security state without containing the client's data, with support for independent verification.
Validation
Evaluations validate the architecture end to end against the scenarios agreed in their scope, such as protected data created and encrypted with client keys, authorised access from an attested workload, simulated exfiltration, replay attempts, a scoped incident, rejection of earlier authorisations, migration to a clean environment, restored access and independent verification of the evidence. Latency, revocation propagation, recovery time, throughput and coverage are measured in the evaluation environment rather than assumed.
"Technical and customer feedback has helped us make the architecture more precise, more accountable and more suitable for enterprise deployment. PastWipe does not need access to the client's data. Our role is to provide the framework through which the client retains control of the right to use protected information beyond the traditional perimeter."
Ralph Ehlers, Founder
About PastWipe
PastWipe Ltd builds post-breach data control for enterprise and government. PastWipe reduces the usable value of stolen or exfiltrated data outside approved conditions and records each control decision as evidence. It complements existing security tools.
Media contact: info@pastwipe.com · Press kit
All insights and news · Get the quarterly Post-Breach Briefing
