LONDON - PastWipe has announced a substantial strengthening of the technical architecture planned for its next release, following requirements raised by CISOs, security architects, incident-response specialists, insurers and enterprise technical evaluators.
The next release is being developed around a strict zero-access deployment model. Client data will remain within the client’s own infrastructure, cloud account, virtual private cloud or approved trusted environment. Encryption and decryption will take place within that client-controlled environment, while cryptographic keys will remain under the client’s control through its own key-management system, hardware security module or equivalent infrastructure.
PastWipe will not require access to client plaintext, client decryption keys or the underlying protected information.
The updated architecture will introduce a formally defined protection boundary across approved files, records, database fields, documents, API payloads, backups and associated data flows. It will identify where encryption occurs, where authorised processing may take place and which routes must pass through the enforcement layer.
Access decisions will be based on more than identity alone. Short-lived, proof-of-possession authorisations will be bound to the requesting user or workload, the protected object, the permitted operation, the declared purpose, the applicable policy and the current security state. Workload and environment attestation will provide additional verification that protected information is being requested from an approved and current execution environment.
The release will also introduce a more granular incident-response model. Controls will be capable of being applied to an individual object, dataset, application, workload, key family, tenant, region or jurisdiction. Policy-controlled incident states and security epochs will allow authorisations issued under a previous state to be rejected across the defined scope.
A structured recovery process will support fresh attestation, replacement of affected credentials, key rotation, policy reissue, object rewrapping and reauthorisation of approved workloads. High-impact actions will support customer-defined approval rules and dual authorisation.
Privacy-minimised cryptographic receipts will provide verifiable evidence of access decisions, policy state, revocation actions and recovery events without exposing the underlying client data.
“Technical and customer feedback has helped make the architecture more precise, more accountable and more suitable for enterprise deployment,” said Ralph Ehlers, Founder and CEO of PastWipe. “PastWipe does not need access to the client’s data. Its role is to provide the framework through which the client retains control of the cryptographic right to use protected information beyond the traditional perimeter.”
The next release will undergo end-to-end technical validation covering protected-data creation, authorised access, simulated exfiltration, replay prevention, scoped revocation, trusted recovery and independent verification of the resulting evidence.
PastWipe also plans to publish measurable results covering access latency, revocation propagation, recovery time, throughput and enforcement coverage.
Further information is available at http://www.pastwipe.com.
About PastWipe
PastWipe develops post-breach data-security technology designed to help organisations preserve control over the cryptographic use of protected information beyond the traditional security perimeter. Its architecture is based on client-controlled data, client-controlled keys, policy-bound authorisation, trusted workload verification and breach-responsive security-state management.





