Get Breached. Lose Nothing.
Pillar 01 · Security
Let's retire the nation-state fantasy. It's load-bearing in too many security decks and it protects no one.
The thing that actually ends a mid-sized company isn't a foreign intelligence service running a decade-long operation against your file server. It's an intern who reused his Netflix password. A storage bucket someone set to public "just for the demo" and then went on holiday. A phishing email with a logo good enough for a Tuesday. A ransomware affiliate who bought your VPN credentials for the price of a sandwich.
That's the threat model. Not Bond villains. People with a downloaded toolkit, a long weekend, and nothing better to do.
So the only question worth asking your architecture is this: when they get in — and plan as though they will, because the ones who didn't plan that way are the case studies — what do they leave with?
In most setups, the honest answer is everything. They're authenticated, the data is sitting there decrypted at rest behind a key the provider manages on your behalf, and the difference between an incident and a company-ending event is whether a log alert fired before the exfil finished. That's not security. That's a smoke detector.
In ours, they leave with confetti.
Zero-knowledge means data is encrypted client-side, before it crosses into anyone's cloud, under keys we never hold and never see. Erasure-coded sharding means no single location stores a reconstructable copy of anything — what sits in any one provider is a fraction of a fragment, mathematically useless on its own. Compromise one cloud completely. Own the hypervisor. Read every byte in the tenancy. You get shards that decode to noise, missing both the other shards and the keys, neither of which were ever there to steal.
Not "encrypted at rest with the key in the same account." Not "hard to crack." Not "would take a determined adversary some time." Nothing. A pile of high-entropy garbage and a confused attacker.
The cloud vendor can't read it. Their administrators can't read it. The team that handles a lawful-access request can't read it, because there is nothing in their custody to hand over. We can't read it. That isn't positioning. It's a property of where the encryption boundary sits, and it sits with you.
Most security budget goes to keeping attackers out. Worthy work. Also a game you win every single day until the one day you don't, and that day is already scheduled. You just don't know the date.
We spent ours making the breach worthless on arrival.
Ask your current provider what an attacker walks out with on their worst day. If the answer is "your data," you've already met your real adversary, and it isn't a nation-state. It's the architecture you signed for.
More from the blog
CBC and CTV Say Canada's Cloud Market Is "Broken." They're Half Right.
A Better Question Doesn't Survive a Subpoena
Bergson Lopes Rego published a piece in CDO Magazine called "The Data Sovereignty Illusion." Read it. The diagnosis is…
Read → Commentary · 5 min readHave You Ever Wondered Where Your Data Goes in the Cloud?
You upload the quarterly numbers. A little spinner turns. "Saved to the cloud." Reassuring phrase, the cloud. Sounds…
Read → Regulation · 3 min readThe Kill Switch Has a Loyalty Program - Microsoft is in the Trump trap
Three weeks before Brad Smith promised Europe that Microsoft would protect it from Washington, Microsoft had already…
Read →