PastWipe™ is the product. RepSec™ is an optional protocol framework. PastWipe can be deployed and used without RepSec.
What RepSec is
RepSec describes a direction for expressing policy, validation and evidence consistently across participating systems, so that different organisations and vendors can interpret the same conditions and records in an interoperable way.
Core ideas:
- Attested access: protected data is only accepted when requested from an approved identity, device or environment.
- Purpose-bound validation: a use is valid only for the declared, allowed purpose.
- Evidence exchange: decisions produce records that participating systems can verify.
What RepSec is not
- Not required for PastWipe deployment.
- Not presented as a universally adopted standard.
- Not a product or edition in its own right.
Adoption requires technical validation and ecosystem participation.
RepSec-Q
RepSec-Q is a development direction that extends RepSec toward post-quantum resilience. Post-quantum claims depend on the selected cryptography and implementation. About RepSec-Q
When RepSec is relevant
RepSec is most relevant where several organisations, such as agencies, vendors or insurers, need to exchange policy and evidence across boundaries. For a single organisation's deployment, PastWipe works on its own.