Audit-ready checklist¶
Use this as a working list. Check items only when evidence exists (screenshot, log export, signed policy, ticket). This list is not a certificate.
A. Scope and data map¶
Named legal entity and systems in scope (console, Drive, NATS, IPFS, ns1)
Data-flow diagram: endpoint → HPKE/NATS → cryptree/IPFS
What is PHI / personal data vs ciphertext vs routing metadata
Peergos verification chapter attached (Peergos verification (what was actually audited))
B. Keys and encryption¶
Customer holds Peergos/Drive keys; not on storage host
NPE/HPKE endpoint keys in directory; private 0600; no xor content
Signed Ed25519 config; unsigned rejected; admin-history prev+new+diff
HSM or documented lab-to-HSM path
C. Access¶
Console
PFC_REQUIRE_AUTH=1, TOTP; Drive login separateInspect k-of-n; author is not an officer; log-before-reveal
Joiner / mover / leaver for console users
Google SSO does not unwrap cubes
D. Integrity and backup¶
Cube chain append-only JSONL; dual hash
Hash registry: first SHA-256 and receipt win
Peergos/IPFS: hash-verified encrypted blocks (restore = re-fetch CIDs)
Restore test: recover a cube from content-addressed ciphertext without plaintext backup tapes
E. Logging¶
Inspect audit events
SM summaries: codes + lookup_id only (no bodies)
Admin-history cube for config
F. Contracts (counsel)¶
Written BA / not-a-BA determination for disk, VM, backup, IPFS
DPA Art. 28 where usernames/logs/IPs are processed
NATS operator: metadata vs content in the annex
Peergos component assurance: attach Cure53 2019 + ROS 2024 PDFs (public; not your org’s ISO/SOC report)
G. Independent audit of you¶
SOC 2 Type I/II engagement or ISO 27001 registrar or HIPAA risk analysis + policies (pick the program you actually need)
Evidence window (Type II / surveillance) if applicable