Privacy & Security

Privacy engineering, security architecture, data governance, and cryptographic systems.

3 papers·October 2026
01

The Right to Be Forgotten Is Impossible on a Blockchain

TELOSIS-RP-2026-011·October 2026

Blockchain technology is promoted as a tool for transparency, trust, and decentralization. Its defining feature is immutability: once data is written to a blockchain, it cannot be altered or removed. This paper argues that immutability makes blockchain fundamentally incompatible with the right to be forgotten, a privacy right recognized in the GDPR, the Indian DPDP Act, and similar data protection laws worldwide. A blockchain that stores personal data creates a permanent record that no individual can delete and no court can order removed. We examine the legal collision between immutability and erasure rights, identify real blockchain applications that already violate data protection law, and argue that blockchain is not a privacy technology. It is a permanence technology. Permanence and privacy are opposites.

Read paper →
02

The Case Against Multi-Tenant Architecture for Privacy Systems

TELOSIS-RP-2026-004·July 2026

Multi-tenancy is the default architectural choice for most SaaS products. It reduces infrastructure cost, simplifies operations, and enables rapid provisioning. But for systems that handle sensitive data - identity, legal agreements, financial records, personal communications - multi-tenancy introduces structural privacy risks that cannot be fully mitigated at the application layer. This paper argues that single-tenant isolation should be the default for privacy-sensitive systems. We examine the trade-offs, define when multi-tenancy is acceptable, and provide patterns for building single-tenant systems without sacrificing operational efficiency.

Read paper →
03

Privacy-Preserving Architectures for Modern Infrastructure

TELOSIS-RP-2026-005·July 2026

Privacy is often treated as a compliance requirement - a checklist of controls to satisfy auditors. This paper argues that privacy is an architectural property, not a compliance artifact. We present four patterns for privacy-preserving infrastructure: encryption at rest with customer-managed keys, encryption in transit with forward secrecy, zero-access architectures where the provider cannot access user data, and metadata minimization to reduce the surface area of surveillance. We also address the limits of technical privacy: what architecture cannot protect, and where law, policy, and user behavior must fill the gap.

Read paper →