Engineer Privacy into Identity and Access Systems
Control personal data, metadata, identifiers, correlation, telemetry, inference, release, retention, and deletion across access systems.
Topic index
Learn how cryptographic constructions, key lifecycles, and data governance protect information across its complete lifecycle.
Topic index
Pomerium uses authenticated transport and managed cryptographic material for access sessions, identity assertions, and TLS. Application owners still choose data classification, storage protection, cryptographic constructions, key custody, retention, deletion, and migration for application data.
2 learning paths
Control personal data, metadata, identifiers, correlation, telemetry, inference, release, retention, and deletion across access systems.
Learn cryptographic primitives, key systems, data lifecycle controls, storage protection, and migration without inventing protocols.
7 related guides
Model secret-dependent signals and deliberate covert channels across software, shared hardware, protocols, and physical devices.
Select a standard construction and define keys, nonces, context, record format, failure behavior, tests, and migration before coding.
Define labels, allowed flows, trusted transformations, release policy, evidence, and residual channels across an application and its data systems.
Connect roots of trust, boot verification, measurements, fresh evidence, appraisal, policy, update, revocation, and recovery.
Inventory cryptographic dependencies and migrate protocols, algorithms, keys, certificates, code, hardware, and stored data safely.
Choose transport, application, database, filesystem, storage, and in-use protections from the data threat model and key boundary.
Control collection, use, sharing, storage, logging, backup, recovery, retention, deletion, and sanitization for one data class.
20 related terms
Encrypt plaintext and authenticate ciphertext plus unencrypted context with a standard AEAD construction and correct nonce handling.
Create isolated, complete, recoverable copies and prove they restore current service without old compromise, authority, or expired data.
Inventory and replace algorithms, parameters, protocols, keys, libraries, certificates, and stored formats without hidden dependencies.
Map data to a fixed-length digest with defined preimage, second-preimage, and collision resistance for the selected use.
Control cryptographic key purpose, generation, custody, distribution, use, rotation, compromise, recovery, and destruction.
Generate unpredictable security values from a validated entropy source and cryptographic random-bit generator with protected state.
Assign data sensitivity, criticality, ownership, use, sharing, retention, and recovery requirements that drive technical controls.
Collect, use, expose, and retain only the data necessary for a stated operational purpose and bounded period.
Retain data for a stated need, then remove access across primary storage, replicas, caches, backups, indexes, keys, and media.
Bind a defined message to a private signing key and verify it through an authenticated public key, purpose, and context.
Encrypt data with a data-encryption key and protect that key under a separately stored key-encryption key or key service.
Anchor a narrow security function in protected hardware while stating the manufacturing, firmware, key, lifecycle, and physical assumptions that remain.
Derive purpose-separated cryptographic keys from suitable key material with a standard KDF, salt, context, and output length.
Separate key lifecycle orchestration, hardware protection, cryptographic operations, workload authorization, and application data policy.
Verify message integrity and shared-key origin with a standard MAC while controlling key scope, context, replay, and verification.
Apply the exact uniqueness, unpredictability, length, and state rules that a cryptographic construction requires for each key.
Treat identifiers, device facts, access events, relationships, timing, locations, and derived attributes as personal when context can link them to people.
Prepare public-key systems for quantum-resistant key establishment and signatures through inventory, standards, testing, and migration.
Remove a system, route, identity, key, dependency, and data without leaving reachable shadow service or breaking another security control.
Analyze information leaked through time, caches, memory access, power, emissions, sound, faults, resources, and error behavior.