I was wondering, how is crypto-shredding implemented in an environment, where data backups/mirroring is mandatory for the "key database" - as it must not be possible to lose the machine/db with all the keys and shred everything by accident :-).
I always get in my mental model to the point, where I delete the encryption key for the given entry...but it still exists in some kind of offline backup. Or is there a restriction that for crypto-shredding all replicas of the "key database" are online and the DB may not be snapshotted?