Home / Companies / Duality / Blog / August 2026

August 2026 Summaries

4 posts from Duality

Filter
Month: Year:
Post Summaries Back to Blog
Zero trust data security replaces perimeter-based defenses with continuous authentication, authorization, least-privilege access, segmentation, encryption, and monitoring across five CISA pillars: identity, devices, networks, applications and workloads, and data, supported by analytics, automation, and governance. It is particularly relevant to healthcare, financial services, and government organizations, where stolen credentials, regulatory obligations, and sensitive data-sharing needs make traditional network trust inadequate. While zero trust can protect data at rest and in transit and limit lateral movement after a breach, the text argues that it leaves a significant gap when data must be decrypted for processing, especially in collaboration between organizations that cannot fully trust one another. Privacy-enhancing technologies such as fully homomorphic encryption, trusted execution environments, secure multi-party computation, federated learning, and differential privacy are presented as complementary tools that can protect data during use, although they differ in performance, trust assumptions, and suitable workloads. The text positions Duality’s platform as one approach for combining these technologies with governance and auditability to enable secure cross-organizational analytics and AI without exposing raw data.
Aug 11, 2026 4,258 words in the original blog post.
Data security protects information against unauthorized access, alteration, loss, and theft through measures such as encryption, authentication, access controls, monitoring, and incident response, while data privacy governs whether personal data may be collected, used, retained, shared, or transferred under lawful and clearly defined purposes. The distinction is central to GDPR, which addresses security primarily through Article 32 and privacy through Articles 5 and 25, requiring lawful processing, data minimization, purpose limitation, and privacy by design in addition to risk-appropriate safeguards. An organization can therefore maintain strong technical protections yet still violate privacy rules by collecting data without a lawful basis, retaining it too long, or using it beyond the agreed purpose. Regulated sectors such as healthcare, financial services, and government commonly manage security and privacy through separate but coordinated controls, owners, and compliance frameworks. The discussion also highlights privacy-enhancing technologies—including confidential computing, federated learning, secure multi-party computation, and fully homomorphic encryption—as approaches intended to enable analytics and AI collaboration while reducing exposure of sensitive data during processing.
Aug 11, 2026 3,149 words in the original blog post.
Data localization refers to legal requirements that certain data be stored, and sometimes processed, within a country’s borders, driven by privacy, security, law-enforcement access, digital sovereignty, and economic policy goals. It differs from data residency, which is a voluntary choice about physical storage location, and data sovereignty, which concerns the laws governing data regardless of location. Restrictions have expanded globally, with Russia, China, and India among the countries enforcing particularly strict rules, while many others apply sector-specific mandates to payment, health, telecom, or government data. GDPR does not require EU data to remain in Europe but instead regulates international transfers through adequacy decisions and safeguards. The discussion argues that building separate local infrastructure for every jurisdiction can create costly data silos that limit analytics, fraud detection, research, and AI development. It presents compute-to-data approaches and privacy-enhancing technologies, including federated learning, homomorphic encryption, secure multi-party computation, and confidential computing, as ways to keep raw data in required locations while allowing protected insights or model updates to be shared. As localization rules are expected to extend further into AI training and governance, organizations are encouraged to design systems in which sensitive data remains local while authorized, non-identifying outputs can move across borders.
Aug 10, 2026 2,953 words in the original blog post.
Sovereign cloud is presented as a model that aims to keep data, infrastructure, and operations under the exclusive legal and operational control of one jurisdiction, distinguishing it from simple data residency, which only determines where servers are located. The discussion argues that many offerings remain vulnerable to foreign legal demands because laws such as the US CLOUD Act can compel US-controlled providers to disclose data held abroad, while European initiatives and locally controlled subsidiaries seek to reduce this exposure without necessarily eliminating it. It identifies data residency, locally controlled operations, and technical sovereignty as three required layers, with the last relying on customer-held encryption keys and privacy-enhancing technologies to prevent providers from accessing readable data even during computation. Technologies including confidential computing, fully homomorphic encryption, and secure multi-party computation are described as ways to enable protected cloud processing and cross-border collaboration. Organizations with especially sensitive government, defense, health, or critical-infrastructure workloads may build their own sovereign clouds, although this entails substantial cost and operational tradeoffs; other organizations are encouraged to assess providers’ jurisdictional exposure, access to plaintext, key control, operational independence, and audit evidence.
Aug 10, 2026 2,804 words in the original blog post.