Choose a bounded use case
Start with a data flow whose producer, recipient and enforcement point can be observed. Record the data class, intended actor, permitted purpose and the condition that should make later use invalid.
Identify the control point
Select a gateway, service or application boundary where a request can be checked before data is accepted. The first evaluation should avoid broad production changes and use representative assets in a controlled environment.
Agree the evidence
- Accepted requests when the required policy and attestation are valid.
- Declined copied or replayed requests when those conditions are absent or revoked.
- An evidence record showing the policy decision and its reason.
- Observed validation behaviour within the agreed environment.
Plan the evaluation
PastWipe and the customer agree the integration boundary, test cases, roles, data handling and success criteria. API and implementation details are provided during a scoped evaluation.
Evaluation tools
SDK and CLI packages are distributed for approved evaluations. See downloads for the current availability process.
