***This blog post was written to accompany this press release on the same topic.***
Lawmakers throughout the U.K. and Europe are discussing the ability to monitor and investigate criminal activity within encrypted channels—often referred to as “lawful access.” While this isn’t a new concern, it has bubbled back up to the top as threat actors are leveraging encryption, blockchain and VPN technology to hide from law enforcement.
Unfortunately, any encryption vendor who creates a backdoor or “lawful access” point is now also creating a point where the data is viewable in plaintext. In short, that data is no longer encrypted, sacrificing the privacy and data sovereignty for 99% just to monitor the 1%. As a data security vendor and data manager, Paperclip empathizes with law enforcement and is committed to finding a solution. At the same time, we believe a solution exists without sacrificing our clients, or the privacy of the 99%.
At Paperclip, our mission is to safeguard the world’s most sensitive data without compromise. So, when UK and EU legislators (or any lawmakers) propose mandating “lawful access” backdoors within data encryption solutions, we view it as a threat to both digital trust and systemic resilience. Any access point, lawful or otherwise, will lead to manipulation and breach. This doesn’t mean that there isn’t a solution to the challenge. It just means that we need to approach it from a different angle so that proper controls, both technical and legal, are followed. Below, we outline why strong, uncompromised encryption is non-negotiable—even in the face of evolving regulatory pressures—and how Paperclip SAFE® delivers a balanced, auditable “lawful access” solution through our client-managed administrative portal, where that access rightfully belongs.
Consumer Trust & Digital Confidence
Strong encryption is the bedrock of confidence—for enterprises deploying cloud-native applications and consumers safeguarding personal records. When that foundation is weakened, trust collapses.
- Real-world impact: In early 2025, the UK government invoked the Investigatory Powers Act to compel Apple to disable its Advanced Data Protection feature for UK iCloud users. In response, Apple ceased offering end-to-end encryption for nine key data categories—exposing customers to standard protections only and triggering widespread concern about privacy erosion. See Apple’s statement here: https://support.apple.com/en-us/122234
- Competitive consequences: VPN providers like Mullvad ran full-page ads in major outlets to warn that backdoor mandates would “drive data into the wrong hands,” and have pointed to the 2022 exodus of providers from India after similar laws, underscoring risks to service availability and market choice. References: https://www.techradar.com/vpn/vpn-privacy-security/vpn-firm-warns-against-encryption-backdoor-in-new-ad; https://www.wired.com/story/vpn-firms-flee-india-data-collection-law
- Eroding brand equity: According to the Thales 2025 Digital Trust Index, no industry exceeded 50% in consumer trust, with banking leading at just 32%. Privacy fears alone drove 82% of digital-service customers to abandon brands over the last year—proof that undermined encryption directly translates into lost revenue and reputational damage. Learn more: https://cpl.thalesgroup.com/about-us/newsroom/digital-trust-index-2025
At Paperclip SAFE, we’ve designed our platform so that only data owners hold the cryptographic keys—no third-party or government mandate can or should force us to expose plaintext without a fundamental redesign that would jeopardize every user’s security. Paperclip is not the data owner, and therefore, should not be making decisions on how that data is shared. But there is a solution, read on.
SAFE Encryption: How it Works and Why it Matters
Encryption employs mathematical algorithms to render data unreadable without the correct key, or set of keys. The Paperclip SAFE approach combines the speed of searchable symmetric encryption (SSE) with the secure key exchanges of asymmetric schemes.
Symmetric vs. Asymmetric:
- Symmetric uses one shared secret key for encryption and decryption—ideal for bulk data.
- Asymmetric uses a public key to encrypt and a private key to decrypt, safeguarding key distribution.
Hybrid “Padlock” Model: Imagine a sturdy box with a one-way padlock: anyone can drop a message in using the public key, but only the private key can open it. This underpins TLS/SSL in nearly every web transaction.
Key-Management Lifecycles: Per NIST SP 800-57, robust key-management governs generation, storage (often in HSMs), rotation, and destruction—ensuring keys themselves never become single points of failure. Reference: https://csrc.nist.gov/publications/detail/sp/800-57
Backdoors = Systemic Risk. Any built-in access mechanism expands the attack surface; civil-society coalitions warn that “lawful access” inevitably leaves exploitable gaps for nation-state and criminal actors alike. This stands to further violate trust and potentially put even more power in the hands of the threat actors.
Paperclip’s Client-Managed Portal and “Lawful Access”
Rather than embedding a universal backdoor, SAFE introduces an approach whereas the access is through the existing SAFE client-managed administrative portal. This puts the access where it belongs, within the accountability layer:
- Controlled Access Point: Clients spin up and configure their own “lawful access” interface—no universal master key exists.
- Strict Audit Trail: Every request is logged immutably, embedding requester identity, legal basis, timestamps, and data scopes.
- Client-First Governance: Legal, compliance, and privacy teams at the client control who can invoke access, ensuring both regulatory requirements and consumer rights are honored while still allowing law enforcement agencies legal access to monitor and/or investigate.
- Zero Plaintext Exposure to Paperclip: Because data holder and data owner keys, and decryption controls reside solely within the client’s environment, Paperclip SAFE’s infrastructure, as designed, never sees unencrypted data.
This design aligns with legitimate investigative needs with robust accountability, maintaining full end-to-end encryption and preserving trust within the SAFE ecosystem.
Encryption as a Pillar of Operational Continuity and Resilience
Encryption isn’t a mere checkbox—it’s an integral element of data-centric resilience strategies, spanning business operations, continuity, incident response, and regulatory compliance.
- Active Business Operations: Critical data (PII, PHI, IP, NHI, etc.) must be encrypted in use, at rest, and in transit. Resilience begins with a solid operational data encryption strategy. Remove critical data from exposure and reduce risk of destructive breach.
- Business Continuity & Archives: Encrypted archives and backups stored off-site ensure rapid recovery after an incident without risking data leakage—our zero-knowledge key-separation model guarantees that only authorized recovery processes can decrypt data.
- Incident Response & Forensics: Even under breach conditions, encrypted logs and snapshots maintain chain-of-custody integrity; keys are never co-located with data, preventing exfiltration of both simultaneously.
Regulatory Alignment:
- GDPR Article 32 explicitly cites pseudonymization and encryption “to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems.” Read more: https://gdpr-info.eu/art-32-gdpr/
- NIS2 Directive mandates encryption of sensitive data in transit and at rest, plus secure backups with tested recovery procedures to minimize service disruption. Details: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
- DORA Article 6 requires encryption of data at rest, in transit, and—in exceptional cases—in use, alongside rigorous key-management controls, to fortify the EU financial sector’s operational resilience. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
Leveraging these requirements, Paperclip SAFE’s platform integrates patented approaches to strong, post-quantum resistant cryptography with workflow orchestration—providing turnkey compliance and bulletproof resilience without sacrificing performance or violating client trust and growing regulatory demands.
Conclusion
As policymakers debate “lawful access,” Paperclip invites partners, clients, and regulators to collaborate on solutions that uphold public safety without dismantling the cryptographic foundations that protect us all. With SAFE’s client-managed portal approach, we deliver a path where security, privacy, and law enforcement thrive—powered by unbreakable, uncompromised encryption.
