Cloud adoption has pushed organizations into a difficult balance between data privacy and data sovereignty, especially when sensitive data is processed by third parties across borders. As data protection laws proliferate globally, compliance failures can trigger substantial financial penalties, and requirements can be contradictory across jurisdictions. The Schrems II judgment and subsequent EDPB recommendations sharpen this challenge by stating that processing EU personal data “in the clear” outside the EU is not permitted and that legal safeguards like Standard Contractual Clauses are insufficient without supplementary technical measures. The EDPB highlights three primary technical approaches: strong encryption with exporter-held keys, pseudonymization prior to transfer, and split processing across independent importers in different jurisdictions.
ShardSecure’s patented Microshard technology is presented as a technical response, aiming to desensitize data at rest by compressing, shredding data into microshards (as small as four bytes), mixing them into multiple logical containers, optionally adding decoys, removing metadata, and distributing containers across multiple customer-controlled storage locations (multi-cloud, multi-region, or hybrid). Reassembly is performed in real time and in parallel, using securely stored, distributed reassembly instructions; decoys are ignored. The approach avoids traditional reversible cryptographic computation and reduces reliance on encryption key management, while adding integrity checks that can detect tampering and automatically reconstruct altered fragments.
Mapped to an information lifecycle framework, Microshard is positioned under “Secure” controls for confidentiality and integrity in transit and at rest. Evaluated against EDPB use cases, it best aligns with split/multi-party processing (Use Case 5), can support storage/backup scenarios if the microsharding cluster remains under EU jurisdiction (Use Case 1), and can complement encryption or pseudonymization but does not replace pseudonymization. Key challenges include lack of independent certification (e.g., FIPS/Common Criteria), absence of confidential computing support, and practical limitations where applications (e.g., SecureDrive for Microsoft 365) reassemble data on web servers during editing sessions.
See All Locations
See All Locations