Regulators, auditors and boards increasingly expect organisations to show how data was handled, not only to state policies. PastWipe™ reduces the usable value of stolen or exfiltrated data outside approved conditions, and records each control decision as evidence.
PastWipe does not make an organisation compliant, and PastWipe holds no certification. It is designed to support evidence for the obligations below, alongside your existing governance, risk and compliance processes.
Designed to support evidence for…
Data protection (GDPR and UK GDPR)
- Accountability and integrity/confidentiality principles: records of who used protected data, for which declared purpose and under which policy.
- Purpose limitation: use tied to a declared purpose, with requests outside it denied or degraded.
- Breach assessment: evidence of which protected data was requested after an incident, and what was allowed or refused.
Operational resilience and security (NIS2, DORA)
- Incident handling: scoped changes to security state, with a record of the decisions that followed.
- Third-party risk: policy that travels with selected data shared with vendors in supported workflows.
- Testing and review: evidence that can be reviewed after exercises and real incidents.
Sector obligations
Health, financial, public-sector and legal environments have their own record-keeping and handling rules. PastWipe evidence can be mapped to those controls as part of a controlled evaluation.
How PastWipe helps governance teams
- Policy attached to data classes: machine-readable policy for selected records, documents and exports.
- Signed decision records: material actions can produce a signed event, which can be sent to your SIEM/SOAR.
- One set of evidence, several reviews: the same records can support internal audit, external audit, insurer and regulator questions.
What PastWipe does not do
- It does not replace your compliance programme, DPO, legal advice or audit.
- It does not guarantee regulatory outcomes.
- It cannot provide evidence for uses outside supported workflows.
For PastWipe's own security, privacy and procurement documentation, see the Trust Centre.