Locking down access to customer data

You forgot: encrypt each customer data individually, and rotate keys often. Use perfect forward secrecy.

If it takes just one roundtrip to the servers that store private keys to decrypt your data, that’s easy to miss or masquerade in the noise.

If you make it necessary to request keys for each individual customer or session, you make large-scale surveillance much harder to hide.

