Post-breach data control

RepSec: an optional protocol framework

RepSec is an optional protocol framework for consistent policy, validation and evidence exchange. PastWipe does not depend on RepSec adoption.

PastWipe™ is the product. RepSec™ is an optional protocol framework. PastWipe can be deployed and used without RepSec.

What RepSec is

RepSec describes a direction for expressing policy, validation and evidence consistently across participating systems, so that different organisations and vendors can interpret the same conditions and records in an interoperable way.

Core ideas:

  • Attested access: protected data is only accepted when requested from an approved identity, device or environment.
  • Purpose-bound validation: a use is valid only for the declared, allowed purpose.
  • Evidence exchange: decisions produce records that participating systems can verify.

What RepSec is not

  • Not required for PastWipe deployment.
  • Not presented as a universally adopted standard.
  • Not a product or edition in its own right.

Adoption requires technical validation and ecosystem participation.

RepSec-Q

RepSec-Q is a development direction that extends RepSec toward post-quantum resilience. Post-quantum claims depend on the selected cryptography and implementation. About RepSec-Q

When RepSec is relevant

RepSec is most relevant where several organisations, such as agencies, vendors or insurers, need to exchange policy and evidence across boundaries. For a single organisation's deployment, PastWipe works on its own.

How PastWipe works · Contact PastWipe