Peergos verification (what was actually audited)
================================================

This chapter records **sourced** facts. It does **not** turn Peergos, Verae,
or DataCubes into a HIPAA, SOC 2, or ISO 27001 certificate.

Claim to check
--------------

Data at rest is stored in an encrypted append-only Peergos filesystem;
backup/restore is managed via a distributed, hashed, encrypted Peergos
IPFS system, designed and evaluated in the EU as an audited secure
filesystem.

Independent security audits (Europe)
------------------------------------

**2019 — Cure53 (Berlin, Germany).**
Pentest, source-code audit, **crypto/design review** (May–June 2019).
No fundamental architectural or cryptographic problems; issues fixed.
Cure53: the platform **passed this evaluation**.

**2024 — Radically Open Security B.V. (Amsterdam, Netherlands).**
Crystal-box pentest + code audit of Peergos web-ui (Sep–Nov 2024).
**0** extreme / high / elevated; **2** moderate, **6** low; Peergos
states all fixed; no data exposure or integrity compromise (mostly UI
crashes).

Both firms are **EU-based**. Both full reports are **public**. That is a
**security evaluation of the Peergos protocol/implementation**, not a
HIPAA/SOC 2/ISO management-system certificate.

.. only:: html

   Primary sources:

   * https://peergos.org/posts/security-audit
   * https://cure53.de/pentest-report_peergos.pdf
   * https://peergos.org/posts/security-audit-2024
   * https://github.com/Peergos/Peergos/tree/master/audits

EU funding / NLnet
------------------

* Peergos received funding from the **European Union Horizon 2020**
  programme under **NGI-POINTER**, grant **871528** (stated on the 2024
  audit post).
* The 2024 audit was supported by **NLnet** (Netherlands).

Hosted instance location
------------------------

Peergos’s hosted privacy notice states peergos.net uses servers in
**Germany**. **Self-hosted ns1 / customer cryptree is a different
processing location** and must be documented in *your* RoPA / BAA pack.

Encrypted filesystem + hashed IPFS (design)
-------------------------------------------

* **Cryptree**: tree of symmetric keys; fine-grained read/write caps;
  sibling names hidden; writes **signed**.
* **Chunks**: up to 5 MiB, padded, independently encrypted
  (Salsa20-Poly1305); random 256-bit keys (not convergent).
* **IPFS**: content-addressed blocks. Peergos **verifies the hash** of
  every block read from or written to IPFS. Clients verify hashes and
  signatures from a Peergos server.
* **CHAMP**: encrypted cryptree nodes under **random 32-byte labels**.
* Sharing: hybrid **X25519 + ML-KEM-1024**.

“Append-only” in Verae DataCubes is the **cube chain JSONL** (application
integrity). Peergos uses signed updates and immutable blocks. Do not
conflate the two layers in an audit interview.

Not verified / do not claim
---------------------------

* “Peergos is HIPAA certified” — **false.** HIPAA is not a product certificate.
* “Peergos is SOC 2 / ISO 27001 certified” — **not shown.** Published
  work is pentest/code audit, not Type II or ISO registrar.
* “EU certified Peergos as a government-standard filesystem” —
  **overstated.** What exists: EU grant funding, NLNet-funded ROS
  pentest, Cure53 Berlin design+code audit.
* “Hosts with disk/backup never need a BAA/DPA” — **legal conclusion,
  not a technical fact.** See :doc:`baa-dpa`.
