Making yourself audit-ready with Verae DataCubes¶
How to prepare an organization for HIPAA-aligned, SOC 2, or ISO 27001 work using Verae DataCubes on Peergos (encrypted cryptree + hashed IPFS) and HPKE on an untrusted NATS broker.
This document is not a HIPAA, SOC 2, or ISO certificate. Peergos’s public pentests are not your Type II or ISO registrar certificate. They are component security evaluations you can attach.
What we verified about Peergos (EU)¶
See the full sourced table in Peergos verification (what was actually audited).
Encrypted client-side filesystem (cryptree); keys not on the storage server — yes (Peergos book + Cure53 design review).
IPFS blocks content-addressed; Peergos verifies hashes — yes.
Independent EU security audits, reports published — yes, two: Cure53 Berlin (2019); Radically Open Security Amsterdam (2024).
“Peergos is HIPAA/SOC 2/ISO certified” — no. Those audits are pentest/code/design reviews, not management-system certificates.
Peergos was designed as a trust-minimized encrypted filesystem, evaluated in Europe by two specialist firms, with public reports. That supports the at-rest / backup story. It does not finish your audit.
Live technical surfaces:
Companion system docs (HTML): https://docs.pfc.georgelambert.org/