Request Demo

Use confidential data in the public cloud without compromising on security and compliance

Cloud benefits without risk: find out how eperi sEcure protects sensitive data in the public cloud - and turns it into a secure private cloud.

Cloud infrastructures offer flexibility, scalability and efficiency, but for many companies, trust in the public cloud comes to an end when it comes to sensitive data. There is too much concern about unauthorized access, data loss or regulatory violations. This is precisely where a modern security approach comes in: It transforms every public cloud into a private cloud: cryptographically secured, compliance-capable and still usable as usual.

The challenge: data is inadequately protected

Encryption during transmission ("data in transit") has long been standard. But what happens when data has to be processed in an externally hosted application? In practice, it is transferred in a way that is visible to the application operator, including customer data, business secrets and medical data. This applies to cloud applications, external databases, containers and even AI models.

Anyone relying on conventional security measures here must trust the cloud providers or administrators - or forego the benefits of the cloud.

The solution: Encryption before the cloud but still in the cloud

The combination of two proven approaches creates a consistent protection concept:

  1. Application-oriented encryption: targeted, rule-based and data type-sensitive
    Sensitive data is not protected at the infrastructure or storage level, but directly at the source, before it is transferred to the cloud. eperi sEcure protects specific fields or content (e.g. name, email, IBAN, patient number) as an upstream security service. This encryption is transparent for the target application, so that existing cloud services such as M365, Salesforce or Trello continue to function as usual, but without access to plain text data.
  2. Encryption and decryption in protected enclaves, even in the public cloud
    The most sensitive part of the process, i.e. the decryption and, if necessary, re-encryption of the data, takes place entirely within a hardware-isolated, trusted execution environment (e.g. from enclaive). This environment cryptographically protects the running processes so that even the cloud provider, the administrator or a compromised operating system cannot access the plaintext data or the processing logic.
    This makes it possible to operate the entire protection mechanism - including sensitive encryption of the plaintext - in a third-party infrastructure without losing control or confidentiality.

The effect: Confidentiality is completely maintained, regardless of where the data is stored or processed.

What you get out of it as a customer

  • Data sovereignty in any environment
    Whether public cloud, hybrid setup or multi-cloud: confidential information always remains under the control of the company as data owner.
  • Compatibility with existing applications
    The architecture works without any major changes to applications or infrastructure. It fits into existing processes and is completely invisible to end users.
  • Compliance with regulatory requirements
    The solution supports data protection requirements from GDPR, DORA, HIPAA, PCI DSS or ISO 27001, not as a "check-the-box" measure, but in a substantial and auditable way.
  • Trust despite outsourcing
    Even in outsourced processes or with external hosting, business-critical information remains private. Trust is replaced by technology, in line with the "zero trust" principle.
  • Future-proof through modular expandability
    The security architecture grows with you, be it through new cloud applications to be protected, regulatory requirements or post-quantum-resistant cryptography.

Conclusion: Safety at the highest level, without compromise


Using sensitive data in the public cloud without disclosing it? What has long been a contradiction is now a reality. Selective encryption by eperi sEcure and confidential processing in an enclave transforms every public cloud - whether from global hyperscalers or smaller providers - into a cryptographically protected private cloud. For you as a company, this means you can finally enjoy the benefits of the cloud without losing security and control.

Or in short:
With eperi sEcure, you can turn any public cloud into a private cloud.

Insure against cyber risks

Cyber attacks have long been part of everyday life - but anyone hoping for support from their cyber insurance in an emergency must now more than ever provide concrete proof of security. Encryption is no longer a "nice to have", but a prerequisite. In our white paper, you can find out what the current AVB Cyber 2024 requirements are, what insurers pay particular attention to and how you can demonstrably protect your data with eperi sEcure.

Prepare your company optimally - before a claim occurs. Download now free of charge and make an informed decision.