Stop Shipping Plaintext: Why Data Platforms Need Encryption-in-Use Now

The Growing Threat: Silent Data Exfiltration Through Valid Credentials

Your security team receives an urgent alert at 3 a.m. A CISA field agent warns that threat actors claim access to your environment. Within minutes, your team confirms the worst: credential theft through vishing led to months of silent data exfiltration through legitimate API calls. No ransomware. No alerts. Just clean, authorized data extraction of your most sensitive customer information.

This scenario is playing out across enterprises worldwide, and traditional encryption methods aren’t stopping it.

Why Traditional Encryption Fails Against Modern Data Breaches

Attackers no longer need to break encryption when they can simply use stolen credentials to access plaintext data during normal operations. Recent high-profile breaches demonstrate this vulnerability:

Major Data Breaches Caused by Plaintext Exposure

    • Snowflake Customer Incidents (2024): Threat actors used stolen credentials to access customer environments and exfiltrate data for sale
    • Ticketmaster and Santander Breaches (2024): Both linked to compromised cloud tenant access through valid authentication
    • AT&T Data Exposure (2024): Call and text metadata leaked via third-party cloud platform, resulting in 2025 settlement
    • Salesforce Data Loader Abuse (2025): Attackers weaponized an approved admin app to run high-volume API queries and extract records
    • Change Healthcare Breach (2024-2025): Historic PHI theft impacting approximately 192.7 million individuals

The common factor? None of these breaches required breaking encryption. All exploited plaintext data during normal operational access.

What Is Encryption-in-Use? Understanding Advanced Encryption Technology

Traditional encryption protects data at rest (static stored data) and in transit (moving between systems—still static data). But what happens when applications and platforms need to actually use that data?

Encryption-in-use (also called searchable encryption) extends cryptographic protection into the processing phase. Applications can search, join, and perform computations upon encrypted data while that data remains encrypted, without exposing plaintext during operations.

This isn’t basic data masking, tokenization, or hashing. It’s advanced cryptographic technology designed to protect data where it’s most valuable to threat actors, and most vulnerable to manipulation or theft: during active use.

How Paperclip SAFE® Enables Practical Encryption-in-Use

Paperclip’s SAFE® (Searchable and Fast Encryption) platform brings enterprise-grade advanced encryption-in-use to production environments without requiring complete system rewrites.

How SAFE Works: The Architecture

Capture: Sensitive fields (PII, PHI, payment card data, Social Security numbers, secrets) are sent to SAFE via simple API configuration at ingestion points—no change to end user operations

Store: Non-sensitive data remains in your existing databases and warehouses. Only sensitive data lives encrypted within the SAFE datastore. Your schemas stay intact—database agnostic, requires no direct integration to existing dbase environment

Query: Application requests are fulfilled by joining results from your database and SAFE (only when needed and authorized). Only the minimum necessary sensitive data is decrypted, and only at the application layer

Compute: Run joins, deduplication, cohort analysis, and fraud detection without exposing raw identifiers to services or staff

Access: Limited privilege-based decryption with fine-grained controls, and complete audit logging. Additional masking and anonymization added to presentment to further reduce exposure

Business Benefits: Win Regulated Buyers and Enterprise Customers

Checks critical compliance boxes including:

    • Encryption during processing and use
    • Customer-managed encryption keys
    • Data minimization by design
    • Zero-trust access controls
    • Immutable audit trails

Enable Privacy-Preserving Use Cases

    • Data clean rooms: Share analytics insights without exposing raw data
    • Consortium fraud detection: Cross-organization checks that return only match/no-match signals
    • Secure data marketplaces: Offer encrypted datasets where providers never hand over plaintext

Reduce Data Breach Blast Radius

    • Consolidate sensitive data from many siloed dbases serving many applications, down to a single SAFE datastore with controlled access serving many applications—reduces expanded, complex data security footprint and exposure points
    • Dramatically reduce breach blast radius—eliminate decrypt -> store -> process -> re-encrypt activities that are currently exposing data to threat actors moving laterally within your network
    • Zero trust through core dbase operations—additional tier of control—only authorized applications and users, have access to only the data they are approved to read in plaintext.
    • Trend modeling controls risk of application and user compromised access—shuts down any activity outside historical norms
    • Accelerate DSAR (Data Subject Access Request) and right-to-be-forgotten compliance—consolidating controlled and privacy data to a single datastore is much easier to manage

Improve Operational Security

    • DBAs, data architects, and SREs can perform their jobs without handling raw sensitive identifiers, eliminating insider threat risks and reducing the attack surface.

Implementation Patterns for Data Platforms

For Data Aggregators and Cloud Data Warehouses (Snowflake-Style Platforms)

    • Ingest Phase: Pre-processor calls SAFE during data ingestion, landing ciphertext with searchable indices
    • Analytics: Execute encrypted joins for identity resolution, deduplication, and cohort queries with minimal decryption for model features
    • Data Marketplace: Offer “SAFE-enabled” data products where data providers never expose plaintext customer information

For Processing Platforms (Banking, Payments, Healthcare Systems)

    • Edge Encryption: Mobile and web applications encrypt at data capture; core systems never store payment cards or SSNs in plaintext
    • Consortium Fraud Checks: Cross-institution queries using multi-party computation reveal only match signals, not raw data
    • Operations: Support teams, KYC/AML compliance, and claims processors can search effectively without accessing raw identifiers

Meeting Evolving Regulatory Requirements

Regulators worldwide are mandating stronger data protection controls with specific deadlines:

PCI DSS 4.0 Compliance

51 future-dated requirements became mandatory on March 31, 2025, emphasizing encryption during processing and storage.

DORA (Digital Operational Resilience Act)

EU regulation entered application on January 17, 2025, requiring financial entities to demonstrate operational resilience and data protection.

SAFE’s architecture of data minimization, split-key cryptography, and immutable audit trails directly addresses these regulatory frameworks while reducing the attack surface your security controls must defend.

Future-Proofing: AI Safety and Post-Quantum Cryptography

Secure AI Integration

AI and machine learning models require contextual data, but regulators demand proof you’re not exposing plaintext unnecessarily. Encryption-in-use enables LLM-powered workflows to access minimal, policy-approved data fragments while keeping everything else protected.

Post-Quantum Readiness

NIST finalized the first post-quantum cryptography standards in 2024 (FIPS 203 ML-KEM and FIPS 204 ML-DSA). Designing for cryptographic agility now means post-quantum migration becomes a simple configuration change rather than a multi-year infrastructure overhaul.

The Bottom Line: Plaintext Is Your Weakest Link and a Threat Actors Greatest Power

Plaintext data during processing represents the most exploitable vulnerability in modern data platforms. Traditional at-rest and in-transit encryption leave this gap wide open for attackers with valid credentials.

Encryption-in-use with Paperclip SAFE allows data platforms and aggregators to:

    • Maintain full analytics and operational capabilities
    • Remove plaintext from the places attackers target most
    • Meet evolving compliance requirements
    • Prepare for AI integration and post-quantum threats

It’s the logical evolution of secure-by-design architecture and a pragmatic approach to staying ahead of the next compliance deadline, the next AI feature request, and the post-quantum era.

The entire Paperclip ecosystem is built on a foundation of SAFE advanced encryption technology, ensuring that every solution—from document capture to secure data exchange—protects sensitive information not just at rest and in transit, but during active processing and use. This unified encryption layer means your data remains protected across every workflow, every integration, and every touchpoint in your supply chain.

Ready to stop shipping plaintext? Contact Paperclip to discuss how SAFE and the Paperclip ecosystem can protect your most sensitive data during processing and use.

 

References and Resources