Policies describe what should happen. Evidence shows what did happen, and lets you demonstrate it to a regulator, court, insurer, partner or customer.
PastWipe™ reduces the usable value of stolen or exfiltrated data outside approved conditions. Each control decision it makes can be recorded as evidence.
What an evidence record captures
- What was requested: the protected object and the operation.
- Who or what requested it: the user or workload identity, and the device or environment context.
- What was evaluated: the policy, declared purpose and security state at the time.
- What happened: permitted, denied, restricted or degraded.
- When: time of the decision.
Questions evidence should answer
- Who says so? (issuer identity)
- What exactly is asserted? (claims and scope)
- How do we know it hasn't changed? (integrity)
- When did it exist? (time)
- Under which obligations can it be used? (purpose and policy)
- Can an independent party verify it without having to "just trust" us? (verifiability)
Built on established building blocks
Evidence records use widely understood primitives: cryptographic signatures for integrity and authenticity, trusted timestamps, and signed, tamper-evident logs that can be streamed into existing SIEM and audit systems.
The evidence layer is being developed to support signature verification, trusted timestamps, tenant separation, selective disclosure, controlled retention and independent verification. Privacy-minimised receipts are intended to confirm that an approved action took place under a defined policy and security state without containing the underlying client data.
Who uses the evidence
- Security and incident response: what was attempted after an incident, and what was allowed or refused.
- Legal and compliance: support for accountability obligations and regulatory reporting. Regulatory evidence
- Insurers and underwriters: clearer technical information for risk and claims review. Insurers
- Auditors: a verifiable trail of control decisions.
Limits
Evidence covers decisions made within supported, policy-aware workflows. It does not record uses that happen entirely outside enforcement, such as a photograph of a screen or an unrestricted plaintext copy.