Installation & Operation
PMXChain is deployed as a native Azure application with SharePoint integration and supports modern hybrid cloud scenarios.SharePoint remains the user interface, while encryption, integrity, and proofs are handled by the PMXChain architecture.
In the Microsoft 365 scenario, a traditional desktop client is not required. The service is accessed directly through SharePoint Online.
Yes, PMXChain can be used in both cloud-only and hybrid scenarios.
No. SharePoint is not slowed down and latency does not increase. The solution is highly efficient, migrated directly to Azure, and runs seamlessly.
File names, metadata, and status information remain accessible. A full-text search of encrypted content is not possible as long as SharePoint does not have access to the plain text. This is precisely part of the security strategy.
File Management & Deletion
Moving a file to the SharePoint recycle bin is treated as a deletion. PMXChain removes all associated data objects from blockchain management, making the file permanently deleted.
Secure destruction is done via the Erase function in the PMXChain Dashboard. Both the file and the associated cryptographic keys are completely and irreversibly deleted.
Yes. PMXChain encryption is maintained regardless of the storage location, as long as the file remains within the authorized SharePoint tenant.
Yes. The system supports cryptographic revocation, which is often preferable to data deletion. Data remains physically stored but becomes cryptographically inaccessible.
Encryption & Decryption
Directly upon saving or editing – before uploading to SharePoint or OneDrive.
In the PMXChain Dashboard, each file can be processed individually using the Encrypt and Decrypt functions. The resulting file is automatically stored in encrypted form in SharePoint.
Yes. The encryption protection is maintained even after transfer to external media.
Yes. Encrypted files can be exported and re-imported at any time without losing their security status. This allows for secure backups or migrations.
Yes. Encryption is maintained regardless of whether the download is done via the PMXChain Dashboard or directly via SharePoint.
Only authorized users with the appropriate Azure permissions. Access is additionally secured by multi-factor authentication (MFA).
Blockchain & Traceability
Only metadata on integrity and history – not the file content itself. Specifically: cryptographic hashes, pseudonymous identifiers, access control proofs, and integrity and audit metadata. No patient names, medical records, diagnoses, or personally identifiable plain-text information. On-chain data is non-reversible, non-identifying, and non-attributable without off-chain context – which is itself encrypted.
No. Entries are immutable – every action is documented in an audit-proof manner.
No incomplete or inconsistent states can occur. Transactions are atomic: they are either fully committed or fully rejected. Node failures affect availability, not integrity or confidentiality.
All security-relevant operations – including encryption, decryption, and deletions – are automatically documented in the Azure logs. All activities can be traced there in an audit-proof manner.
Permissions, Access & Traceability
Access control is handled entirely through Microsoft's built-in tools (SharePoint permissions, Azure Active Directory roles). PMXChain respects these security policies and does not introduce its own user rights.
Files can be shared externally if guest access is available and the guest also has decryption permissions. Sharing with unknown external third parties without permissions is not possible in encrypted form – the third party cannot decrypt the data.
As with any disaster scenario, a good backup strategy is essential. If such a strategy is in place, subsequent decryption is also possible. For backup purposes, data can be stored externally in encrypted form.
The instance is private. This means that each customer has their own dedicated instance at PMXChain.
Security, Compliance & Data Protection
No. PMXChain is currently not HIPAA-certified.
Collusion is prevented through strict separation of duties, cryptographic enforcement, and a zero-trust architecture:
- System administrators do not possess encryption keys and cannot decrypt data.
- Encryption keys are generated and controlled cryptographically – not administratively.
- Administrative tasks (node management, configuration, monitoring) are decoupled from data access control.
- All actions are immutably logged on-chain, making collusion attempts detectable and non-repudiable.
- Even in the event of collusion, cryptographic constraints cannot be bypassed, as access is enforced at the protocol level.
The system is designed so that no single entity can unilaterally disclose encryption keys. Keys are not stored centrally. The platform operator can neither comply with nor refuse such a request, as it technically does not possess the keys.
No. Eagle PMX staff have zero access to customer data: no encryption keys, no backdoors, no emergency overrides. Even under legal or operational pressure, Eagle PMX cannot technically access customer data.
Yes, but only through a controlled emergency access mechanism. Details regarding approval and the process are to be defined within the respective organizational policies.
Availability & Data Backup
PMXQuantum uses redundant storage architectures. Data is stored at multiple locations, ensuring access remains available even if one location fails.
Yes. PMXQuantum supports automated, encrypted backups. The backup strategy can be configured individually – by frequency, retention period, and destination (cloud or on-premises).
After the contract ends, all customer data is completely and irreversibly deleted. An export option is of course available before cancellation.
About Eagle PMX AG
Eagle PMX AG is a Swiss company headquartered in St.Gallen. The company develops and operates security solutions for document management and data encryption based on blockchain technology.
Eagle PMX serves customers in Switzerland, Germany, Austria, and other European markets. International deployments are available on request.
As a Swiss company, Eagle PMX is subject to the Swiss Federal Act on Data Protection (revFADP) and, for European customers, the GDPR. Both frameworks are fully complied with.