Listen to this episode

Craig Petronella and Sanjeev Verma discuss Preveil - A highly secure, CMMC and ITAR compliant end to end encrypted email and file storage

0:0057:46

Recorded February 2021. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode of Encrypted Ambition, Craig Petronella speaks with Sanjeev Verma, chairman and co-founder of Preveil, a zero-trust, end-to-end encrypted email and file-sharing system. Verma traces the company's origins to his earlier wireless venture and his return to MIT, where cybersecurity experts convinced him that attackers will eventually reach servers, so information must stay protected even then.

He explains Preveil's passwordless design, in which private decryption keys live on user devices, eliminating remote logins, and describes biometric protection on phones. Verma argues that encryption in transit and at rest is a myth because servers can decrypt email, and he contrasts Preveil with Microsoft's GCC High, which he says is not end-to-end encrypted and takes months to deploy. He covers ITAR rules that, at the time of recording, permitted cloud storage of ITAR data under Section 120.54 provided end-to-end encryption conditions were met, and he describes approval groups, trusted communities, and a product demonstration. The two discuss CMMC compliance, the defense industrial base, and Petronella Technology Group's bundled consulting approach.

Worth remembering

Key takeaways

  1. Verma explains that Preveil was not designed for compliance; its security-first approach to data protection makes CMMC and ITAR compliance an outcome.
    “So, in a nutshell, we take a security-first approach to data protection, and compliance is an outcome of that.”
  2. Verma argues that passwords can be brute forced, guessed, or spoofed, so Preveil replaces them with device-based private keys and allows no remote login.
    “Generally speaking, it can be either brute forced, or guessed, or fished and spoofed.”
  3. Verma argues that standard email servers can decrypt messages, so encryption in transit and at rest still exposes data to attackers, admins, and unpatched servers.
    “And so, again, at the end of the day, if the server can see the information, so can the attacker.”
  4. With end-to-end encryption, Verma explains, servers hold no decryption keys, so attackers who breach them obtain only encrypted gibberish that cannot be read.
    “If you have an end to an encrypted system, the server has no key whatsoever and can never decrypt it.”
  5. Verma says Microsoft's GCC High takes a taller walls approach rather than end-to-end encryption, and he describes it as complex, expensive, and slow to deploy.
    “It's not an end-to-end encrypted system. It is a system that takes the taller walls approach to protection of your information seriously.”
  6. To limit damage from compromised admins, Verma describes approval groups that split private keys into fragments, requiring permission from multiple approvers before privileged access.
    “Think of it like the nuclear launch codes. I need approval from a certain minimum number of approvers before I get access.”
  7. Verma notes that, at the time of recording, ITAR rules allowed cloud storage of ITAR data if it is end-to-end encrypted and the provider cannot decrypt it.
    “But if, under Section 120.54, which became the law last March, a company wants to store and share ITAR data and share it with foreign, you know, subsidiaries, etc., they can do so provided the following conditions are met.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Craig Petronella of Petronella Technology Group, Inc. and compliancearmor.com and Sanjeev Verma discuss a highly secure, CMMC and ITAR compliant, end to end encrypted email and file storage solution called Preveil that helps vastly accelerate compliance mandates with regulations such as CMMC, DFARS, NIST, ITAR, HIPAA, GDPR, and more. Be sure to contact Petronella for special discounted pricing on an exclusive compliance bundle that we've created and customized for our audience that combines the power of Preveil with Petronella's policies, procedures and security controls to greatly enhance the cybersecurity maturity level and SPRS score of your firm! Get your system security plan (SSP), plan of actions and milestones (POAMs), required policies, procedures, DFARS/NIST SPRS self assessment score as high as possible in record time, with most of the mappings already done for you!

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.