The thesis

It was never the walls
that kept a secret.

Every security system answers a single question: who is allowed to know. The perimeter answers “anyone inside”, which is why it does not hold: a room where everyone hears everything protects nothing. The opposite answer was set down in a public document on 22 March 2006 — application ITMI2006A000528, later WO 2007/108034. For the twenty years that followed, the industry went on building walls.

The model everyone built

Defend the perimeter

You protect the infrastructure and hope the data stays inside. It works as long as the data stays inside. The data never stays inside.

  • The data leaves the perimeter and becomes readable by anyone
  • One compromised supplier undoes every investment upstream
  • An employee uploads a contract to an AI tool and control is gone
  • After a breach you cannot prove the data was protected
The patented model · US 12,596,770 · EP 4,427,154

Defend the data

Protection travels inside the data. Wherever it is copied, forwarded or archived it stays protected. For those with the keys nothing changes. For everyone else the contents are mathematically inaccessible.

  • The data defends itself, even outside the company
  • The supply chain stops being the weak point
  • Artificial intelligence cannot read what it has no key to read
  • Under inspection, protection is demonstrable
The word in common

Compartmentation.

The rule, older than computers

Who needs to know what. It is a rule older than computers: it comes from places where a mistake cannot be undone, and for decades the only thing holding it up was the discipline of the people involved. Someone decides who is let in on a thing, and everything else follows from that decision.

The perimeter replaced that decision with a door. Whoever gets in knows, whoever stays out does not: it is convenient, it can be bought, it draws nicely on a diagram. And it amounts to telling a secret in a crowded room and trusting the door.

The same rule, in mathematics

The patent does nothing different from that rule: it writes it in mathematics instead of in a standing order. The key belongs neither to the room nor to the list of authorised people. It belongs to the document. Whoever was let in opens it. For everyone else there is no door to force, because there is no door.

Among people the rule can be taught, and teaching it is a trade: it is the subject of the programme on keeping secrets. Machines cannot be taught anything, which is exactly where the other half is needed.

The wall was never the control. The control is who was let in on it.

The technical name is data-centric security: protection sits inside the data rather than in the infrastructure holding it. It stays encrypted wherever it is copied, forwarded or archived — for whoever holds the keys nothing changes, for anyone else the content is mathematically out of reach. This is the principle of US 12,596,770, granted in the United States on 7 April 2026, and EP 4,427,154, granted by the European Patent Office on 3 September 2025 with unitary effect across seventeen member states. Filings and dates are in the record →

Where this is going

Being right is not enough.
You have to be right early.

Post-quantum risk

Criminal groups and state actors are already collecting vast quantities of encrypted data today, intending to decrypt it tomorrow. It is called harvest now, decrypt later. For a board thinking in multi-year horizons the question is not whether the data is protected today, but whether it will still be in ten years. Post-quantum cryptography is not a technical matter: it is risk governance.

Digital sovereignty and on-premises AI

Every time an employee uploads a contract or a financial report to an external AI platform, control is gone, and the organisation can be in breach even while formally compliant. That is why models are needed that stay inside the organisation's own perimeter. Artificial intelligence is not bolted on afterwards: it is designed alongside the protection of the data.

In the end it always comes down to one question.Who is allowed to know what.

AI agents

An AI agent inherits the permissions of whoever runs it, and there is no way to teach it discretion. Not a metaphor: we demonstrated it live.

At Beyond the Perimeter, in front of an audience of security leaders, the risk was not explained. It was executed.

The demonstration, in four steps
01

We built an AI agent. An ordinary tool, of the kind thousands of companies now install to raise productivity.

02

We placed it on a target machine, with the normal permissions of any employee in the organisation.

03

From a remote location we launched a commercial AI assistant and asked it to read everything held in the corporate cloud store.

04

It read every single document. The person sitting at that machine noticed nothing at all.

No perimeter breach. No suspicious activity. No alert. An agent with access to the data is all it takes.

A zero-signal attack surface

Why it happens

The large cloud platforms do encrypt data, at rest and in transit. But it is the platform that encrypts, not the data. Which means the platform decrypts for anyone it considers authorised.

An agent acting on an employee's behalf is, to the system, that employee. It reads in the clear, within seconds, generating nothing anomalous. And when a document is shared externally, it leaves that control along with all its protections.

A person who receives an odd request can notice, and can be trained to notice. An agent cannot: the list of authorised users cannot tell the two apart, and no course will ever make it cautious.

The problem is not the AI agent. The problem is that the data it reads is not protected.

How it closes

If every document were encrypted at the moment of creation, and the key belonged to the document rather than to the platform, that same back door would read nothing but unusable ciphertext.

The agent would go on working for whoever uses it legitimately. For everyone else, and for any unauthorised automated system, the contents would remain mathematically inaccessible.

Artificial intelligence can be adopted quite safely. It just has to stop being added on top of data that cannot defend itself.

The demonstration runs twelve minutes and is given in boardrooms and lecture rooms. It changes the tone of the meeting.

Bring it to your company

Two halves of one rule: compartmentation between people is taught, compartmentation between systems is designed.