Zero Security Theatre

Experiments

Each experiment runs in a real environment and produces a measured result. The limits beside it say what that result can prove.

End-to-end deletion verification

Does a deletion request remove the data everywhere the notice implies?

Method

  1. Seed a synthetic subject through the ordinary front door and let it propagate for a full reporting cycle.
  2. Submit a deletion request through the published channel.
  3. Search for the identifiers in primary stores, warehouses, logs, caches, ticketing systems, exports, backups, and vendor environments.
  4. Record what remains, why, and whether it is consistent with the published notice.

What is measured

  • Stores with residual data
  • Time to full propagation
  • Undocumented destinations discovered

Limits
Proves one property. It does not address access control, consent enforcement, or re-identification.

Under The dangers of data privacy theatre

Consent enforcement probe

Does a withheld consent change what downstream systems do?

Method

  1. Create test records with consent withheld for each governed purpose.
  2. Attempt every downstream use the consent governs, including analytics, export, vendor transfer, and secondary internal use.
  3. Record each hop where the record still appears.

What is measured

  • Hops where enforcement holds
  • Systems ignoring the flag

Limits
Tests the systems that are known. Undiscovered pipelines are the usual source of surprises.

Under The dangers of data privacy theatre, GRC engineering