Version 2.1 · Updated 29 September 2026
This page brings together what security, procurement, legal and risk teams usually ask first: who we are, which providers handle website data, how evaluation data is handled, how PastWipe maps to regulatory frameworks, and how to report a security issue.
Request the procurement pack · Report a security issue · security.txt
Company facts
| Legal entity | PastWipe Ltd, registered in England and Wales |
| Company number | 16893742 |
| Registered office | 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom |
| Incorporated | 5 December 2025 |
| Intellectual property | US patent pending |
| Security and privacy contact | info@pastwipe.com (subject "Security report" or "Privacy") |
| Official channels | pastwipe.com, portal.pastwipe.com, @pastwipe.com email, LinkedIn |
Certifications and assurance
PastWipe’s website does not claim ISO 27001 certification, a SOC 2 report, regulatory approval or guaranteed legal compliance. References to laws or frameworks describe review topics, not an assurance that PastWipe makes an organisation compliant. Any assessment report or control statement supplied for procurement will identify its scope, date and applicable product version.
Website subprocessors
These providers process personal information for the public website, its forms and email. Providers for a customer evaluation or service are listed in its data-processing terms.
| Provider | Purpose | When |
|---|---|---|
| Cloudflare, Inc. | Website delivery, network security, Turnstile anti-spam check on forms | Every request; Turnstile only when a form is used |
| Hostinger | Virtual private server that runs the website and form-handling service | Every request |
| Namecheap, Inc. | Email hosting for info@pastwipe.com, including enquiry and newsletter emails | When you send an enquiry or subscribe |
| Google Ireland Limited and Google LLC | Google Analytics 4 and Google Tag Manager | Only after you choose Accept optional |
Transfers and retention are explained in the Privacy Policy; browser storage in the Cookie Policy.
How evaluation data is handled
Where does PastWipe run during an evaluation? In an environment set up for that customer: on-premises, hybrid or in the customer’s own cloud account. There is no shared, multi-tenant hosted service. Deployment and data residency
Does PastWipe need our production data? No. Evaluations are scoped around a defined data class and workflow. Synthetic or representative data is preferred, and the scope records any real data, its location and who can access it.
Who holds the keys? Keys are intended to stay under the customer’s control through its own key-management system or HSM. What applies to a given evaluation is written into its scope.
What happens to data at the end of an evaluation? Evaluation environments and any customer data in them are returned or deleted as agreed in the evaluation scope, with written confirmation on request.
Can we see the documentation before we sign? Yes. Security, architecture and data-handling documentation is shared during scoping, under NDA where needed. Request the procurement pack
Regulatory mapping
PastWipe does not make an organisation compliant, and PastWipe holds no certification. Its evidence records are designed to support the obligations below, alongside your existing governance, risk and compliance processes.
| Framework | Relevant obligations | How PastWipe maps to them |
|---|---|---|
| GDPR (EU) | Accountability, integrity and confidentiality, purpose limitation, breach assessment (Art. 5, 32, 33–34) | Supports records of who used protected data, for which declared purpose and under which policy, and of what was requested after an incident |
| UK GDPR and DPA 2018 | The same principles under UK law | Maps to the same evidence as GDPR; processing locations are agreed per engagement |
| NIS2 Directive | Incident handling, supply-chain security, effectiveness of measures | Supports scoped responses to incidents and evidence that can be reviewed after exercises and real incidents |
| DORA (financial entities) | ICT risk management, incident management, third-party risk | Supports policy that stays with selected data shared with vendors in supported workflows, and decision records for incident reporting |
| ISO/IEC 27001:2022 | Annex A controls on information transfer, access control, logging and monitoring | Maps to customer controls such as 5.14, 5.15, 8.15 and 8.16 as a source of evidence. PastWipe itself is not certified |
Sector obligations in health, financial, public-sector and legal environments can be mapped as part of a scoped evaluation.
Evidence records
Policies describe what should happen. Evidence shows what did happen. Each control decision PastWipe makes can be recorded:
- What was requested: the protected object and the operation.
- Who or what requested it: the user or workload identity, and the device or environment context.
- What was evaluated: the policy, declared purpose and security state at the time.
- What happened: permitted, denied, restricted or degraded.
- When: time of the decision.
Records use signatures for integrity, timestamps and tamper-evident logs that can be streamed into existing SIEM and audit systems. Selective disclosure, independent verification and privacy-minimised receipts are in development for the next release. See a sample record
Evidence covers decisions made within supported, policy-aware workflows. It does not record uses that happen entirely outside enforcement, such as a photograph of a screen or an unrestricted plaintext copy. No claim is made that a record is automatically admissible in court, sufficient for a regulator or insurer, or proof that every copy of information has become unusable.
Security disclosure
To report a suspected vulnerability, email info@pastwipe.com with “Security report” in the subject line. Send a concise description and ask for a secure channel before providing sensitive evidence. Do not access or extract other people’s information, disrupt services or test third-party systems. Obtain written authorisation before intrusive testing. This notice is not a general authorisation to test and does not grant immunity from law or bind third parties.
Machine-readable contact details are published at /.well-known/security.txt.
Limitations
- PastWipe cannot guarantee that data will never be stolen or copied.
- It cannot stop photographs, screenshots or manual retyping in every case.
- It cannot reliably revoke copies that have already become independent plaintext.
- Enforcement is not identical across every legacy, offline or third-party workflow.
Support targets and incident-escalation routes are specified in customer agreements where applicable. General website enquiries do not carry an SLA. Privacy complaints and rights requests follow the process in our Privacy Policy.