Where things stand
Every service that holds your information keeps its own copy of it. Indexed, replicated, and defended on your behalf.
Each platform rebuilds the same store from scratch, and each store becomes something worth attacking. An entire defensive industry exists because those stores exist.
The information is yours. The custody is not.
Custody was never part of the arrangement.
The distinction
Storage is a question of where. Custody is a question of who holds the keys.
Data encrypted at rest by a provider who also holds the key to it is a promise rather than a boundary. It protects against an outsider. It does not change who can open the box.
The distinction rarely matters day to day. It matters entirely in a breach, a subpoena, an acquisition, or a change of terms.
Encrypted against everyone else is not the same as encrypted against the party holding the key.
What it is
An encrypted environment belonging to the person or business that uses it.
The Secure Virtual Space gives individuals and organizations their own environment for information and digital assets, rather than an account inside somebody else’s. It was patented in 2015 — U.S. 9,092,120 and CA 2,900,264 — and it has been the foundation of everything built since.
It was filed after a career spent watching organizations pay for the same missing capability in a dozen separate ways, and it has been rebuilt more than once since. Infrastructure does not finish. It evolves.
Filed in 2015. Still the floor everything stands on.
How access works
Access is granted, and access is revoked.
Permission runs down to the individual data element rather than the whole account. What was shared can be withdrawn. What was viewed can be shown to have been viewed.
Every access is recorded — who, when, under what authority, on whose delegation. An auditor reads that record and is given proofs rather than contents.
Oversight without exposure.
What changes above it
When information stays in one place, applications stop needing their own copy.
A service asks the space for what it needs and is given an answer, instead of keeping its own copy of you to consult. Identity travels with the person. The ever-larger central store stops being a requirement, which means it also stops being a target.
Consolidating information into fewer, larger stores has been the default answer for thirty years. This is the other answer, and it removes the target rather than defending it.
One space, many services.
What it comes to
Ownership is the ability to grant and to revoke. Everything else is hosting.
A great deal of digital life is described as ownership when what is actually on offer is tenancy with good terms. The difference only becomes visible when somebody wants something back.
Held, not hosted.