February 18, 2022
The eStealth Vault stores datasets centrally manages private data through role-based profil enforcement. It provides the core functionalities of eStealth.
| Component | Purpose |
|---|---|
| Customized GDPR Profiles | Customized profiles based on industry standards describe private data attributes, purpose, role and access rights. |
| Client Authentication | Every request is authenticated and autorized based on business application identifier, role, and profile. |
| Profile Rule Engine | The Rule Engine enforces data protection rules, aka Profile, on all access to data. It also ensures, that every access is recorded in the audit log. |
| Audit Log | The Audit Log records all decisions made by the rule engine, all accesses to the audit log itself, and all accesses to and actions on the data vault. The access log is protected against manipulation and deletion. |
| Data Vault | The Vault stores Datasets containing sensitive data in a secure way. Outside of the vault, datasets are identified by a randomized token. |
| Key Management / Encryption / HSM | The integrated key management system handles access authentication and autorization keys based on the defined profiles. eStealth supports integration of state-of-the-art high-security modules (HSM). Storage and transport of private datasets are encrypted and signed by design. |
| Archive | Expired private data is moved automatically to archive storage for later purging. |
| SIEM | eStealth supports integration of security incident event management (SIEM) systems. |
| Backup | Encrypted backup services ensure business continuity and fast recovery from catastropical desasters. |