Security, privacy & governance

Protection is a lifecycle. Keep the whole lifecycle in view.

Encryption protects the data. Permissions determine who may use it. Recovery, erasure and algorithm changes determine whether that protection holds up over time. Evaluate them together.

Protect01Authorize02Evolve03
Conceptual view · Protect → Authorize → Evolve

01 / The practical advantage

The questions your security team will ask.

8DB’s native protection is most useful when the trust boundary is explicit: who holds authority, who sees plaintext, which copies exist and what happens when that authority changes.

02 / The alternative and the difference

Compare responsibilities.
Then compare products.

Storage encryption alone

YOUR DESIGN CHOICE

Protects stored bytes; authorized queries, exports, recipients and backups still need their own rules.

THE 8DB EVALUATION

Follow the data through computation and exchange, not just the encrypted file.

An algorithm migration feature

YOUR DESIGN CHOICE

Helps change cryptography; old copies, readers, rollout order and rollback still require coordination.

THE 8DB EVALUATION

Evaluate the migration lifecycle, compatibility and retained data as well as algorithm selection.

Explore named alternatives and sources ↗

03 / Scope and evidence

Privacy and compliance need concrete answers.

For this website’s analytics policy, see Website privacy. An application or deployment needs its own data-handling and compliance assessment.

Open the evidence library →
01

Key custody and recovery

Identify the key material, derivation inputs, recovery authority and backup responsibilities in the selected profile. “No external KMS required” is not a claim that recovery needs no secrets or operational controls.

02

Permissions and revocation

Specify who can read, modify or receive data. Test changes against offline and restored devices. Revoking future access cannot retract plaintext a recipient already copied.

03

Erasure and retained evidence

Our erasure research examines how a system can preserve necessary history while retiring access to protected content. Define the data, copies, legal retention and recovery boundaries before treating an erasure operation as complete.

Read the erasure article →
04

Cryptographic change

The published encryption reference covers migration evidence and constraints. Ask how algorithm identifiers, older data, compatibility, rollback and resource limits are handled in your selected release.

Inspect migration evidence →
05

Standards and assurance

Algorithm choices, tested implementation, validated cryptographic modules and regulatory approval are different kinds of evidence. Agree on the assurance your organization needs; this page does not claim a compliance certification.

Keep moving

Define the protection your workload needs.

Discuss your security boundary