Post-breach data control

Trust Centre

PastWipe company facts, subprocessors, data handling, regulatory mapping, evidence records, security disclosure and procurement pack requests.

Version 2.1 · Updated 29 September 2026

This page brings together what security, procurement, legal and risk teams usually ask first: who we are, which providers handle website data, how evaluation data is handled, how PastWipe maps to regulatory frameworks, and how to report a security issue.

Request the procurement pack · Report a security issue · security.txt

Company facts

Legal entity PastWipe Ltd, registered in England and Wales
Company number 16893742
Registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Incorporated 5 December 2025
Intellectual property US patent pending
Security and privacy contact info@pastwipe.com (subject "Security report" or "Privacy")
Official channels pastwipe.com, portal.pastwipe.com, @pastwipe.com email, LinkedIn

Certifications and assurance

PastWipe’s website does not claim ISO 27001 certification, a SOC 2 report, regulatory approval or guaranteed legal compliance. References to laws or frameworks describe review topics, not an assurance that PastWipe makes an organisation compliant. Any assessment report or control statement supplied for procurement will identify its scope, date and applicable product version.

Website subprocessors

These providers process personal information for the public website, its forms and email. Providers for a customer evaluation or service are listed in its data-processing terms.

Provider Purpose When
Cloudflare, Inc. Website delivery, network security, Turnstile anti-spam check on forms Every request; Turnstile only when a form is used
Hostinger Virtual private server that runs the website and form-handling service Every request
Namecheap, Inc. Email hosting for info@pastwipe.com, including enquiry and newsletter emails When you send an enquiry or subscribe
Google Ireland Limited and Google LLC Google Analytics 4 and Google Tag Manager Only after you choose Accept optional

Transfers and retention are explained in the Privacy Policy; browser storage in the Cookie Policy.

How evaluation data is handled

Where does PastWipe run during an evaluation? In an environment set up for that customer: on-premises, hybrid or in the customer’s own cloud account. There is no shared, multi-tenant hosted service. Deployment and data residency

Does PastWipe need our production data? No. Evaluations are scoped around a defined data class and workflow. Synthetic or representative data is preferred, and the scope records any real data, its location and who can access it.

Who holds the keys? Keys are intended to stay under the customer’s control through its own key-management system or HSM. What applies to a given evaluation is written into its scope.

What happens to data at the end of an evaluation? Evaluation environments and any customer data in them are returned or deleted as agreed in the evaluation scope, with written confirmation on request.

Can we see the documentation before we sign? Yes. Security, architecture and data-handling documentation is shared during scoping, under NDA where needed. Request the procurement pack

Regulatory mapping

PastWipe does not make an organisation compliant, and PastWipe holds no certification. Its evidence records are designed to support the obligations below, alongside your existing governance, risk and compliance processes.

Framework Relevant obligations How PastWipe maps to them
GDPR (EU) Accountability, integrity and confidentiality, purpose limitation, breach assessment (Art. 5, 32, 33–34) Supports records of who used protected data, for which declared purpose and under which policy, and of what was requested after an incident
UK GDPR and DPA 2018 The same principles under UK law Maps to the same evidence as GDPR; processing locations are agreed per engagement
NIS2 Directive Incident handling, supply-chain security, effectiveness of measures Supports scoped responses to incidents and evidence that can be reviewed after exercises and real incidents
DORA (financial entities) ICT risk management, incident management, third-party risk Supports policy that stays with selected data shared with vendors in supported workflows, and decision records for incident reporting
ISO/IEC 27001:2022 Annex A controls on information transfer, access control, logging and monitoring Maps to customer controls such as 5.14, 5.15, 8.15 and 8.16 as a source of evidence. PastWipe itself is not certified

Sector obligations in health, financial, public-sector and legal environments can be mapped as part of a scoped evaluation.

Evidence records

Policies describe what should happen. Evidence shows what did happen. Each control decision PastWipe makes can be recorded:

  • What was requested: the protected object and the operation.
  • Who or what requested it: the user or workload identity, and the device or environment context.
  • What was evaluated: the policy, declared purpose and security state at the time.
  • What happened: permitted, denied, restricted or degraded.
  • When: time of the decision.

Records use signatures for integrity, timestamps and tamper-evident logs that can be streamed into existing SIEM and audit systems. Selective disclosure, independent verification and privacy-minimised receipts are in development for the next release. See a sample record

Evidence covers decisions made within supported, policy-aware workflows. It does not record uses that happen entirely outside enforcement, such as a photograph of a screen or an unrestricted plaintext copy. No claim is made that a record is automatically admissible in court, sufficient for a regulator or insurer, or proof that every copy of information has become unusable.

Security disclosure

To report a suspected vulnerability, email info@pastwipe.com with “Security report” in the subject line. Send a concise description and ask for a secure channel before providing sensitive evidence. Do not access or extract other people’s information, disrupt services or test third-party systems. Obtain written authorisation before intrusive testing. This notice is not a general authorisation to test and does not grant immunity from law or bind third parties.

Machine-readable contact details are published at /.well-known/security.txt.

Limitations

  • PastWipe cannot guarantee that data will never be stolen or copied.
  • It cannot stop photographs, screenshots or manual retyping in every case.
  • It cannot reliably revoke copies that have already become independent plaintext.
  • Enforcement is not identical across every legacy, offline or third-party workflow.

Support targets and incident-escalation routes are specified in customer agreements where applicable. General website enquiries do not carry an SLA. Privacy complaints and rights requests follow the process in our Privacy Policy.

Request the procurement pack · Scope an evaluation