Rewrite audit-ready briefing: software is not a certificate.
Some checks are pending
ci / markdown (push) Waiting to run

Open with an executive summary that HIPAA, SOC 2, and ISO 27001
are organizational programs. Verae DataCubes supply store,
communicate, timestamp, verify, and audit tools for the technical
portion only. Chapters cover transit (HPKE, visible routing), rest
(IPFS/Peergos hash-verified restore), receipts, EU Peergos
evaluations (Cure53 2019, ROS 2024), cross-blockchain timestamping,
and write-once Iceberg archive. PDF is branded with the Verae logo
top-left and Verae Inc contact in the footer; last chapters are
sourced bios for Garfinkel (FINRA CRD 5052743), Haber, and Lambert.
This commit is contained in:
George Lambert 2026-09-16 00:55:21 -04:00
parent da60402e88
commit 4fcbb9ac95
53 changed files with 6323 additions and 814 deletions

292
build/html/executive.html Normal file
View file

@ -0,0 +1,292 @@
<!DOCTYPE html>
<html lang="en" data-content_root="./">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>1. Executive summary &#8212; Making yourself audit-ready with Verae DataCubes</title>
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
<script src="_static/documentation_options.js?v=250a654d"></script>
<script src="_static/doctools.js?v=fd6eb6e6"></script>
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
<link rel="icon" href="_static/VeraeFullLogo.png"/>
<link rel="index" title="Index" href="genindex.html" />
<link rel="search" title="Search" href="search.html" />
<link rel="next" title="2. What Verae provides — and what it does not" href="what-verae-provides.html" />
<link rel="prev" title="Making yourself audit-ready with Verae DataCubes" href="index.html" />
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
</head><body>
<div class="document">
<div class="sphinxsidebar" role="navigation" aria-label="Main">
<div class="sphinxsidebarwrapper">
<p class="logo"><a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo of Making yourself audit-ready with Verae DataCubes"/>
</a></p>
<p class="logo">
<a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo" />
</a>
</p>
<p class="blurb">Tools for storage, communications, timestamping, verification, and audit — not a certificate.</p>
<search id="searchbox" style="display: none" role="search">
<div class="searchformwrapper">
<form class="search" action="search.html" method="get">
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false" placeholder="Search"/>
<input type="submit" value="Go" />
</form>
</div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
<ul class="current">
<li class="toctree-l1 current"><a class="current reference internal" href="#">1. Executive summary</a><ul>
<li class="toctree-l2"><a class="reference internal" href="#what-a-verae-datacube-server-solution-does">1.1. What a Verae DataCube Server Solution does</a></li>
<li class="toctree-l2"><a class="reference internal" href="#data-in-transit">1.2. Data in transit</a></li>
<li class="toctree-l2"><a class="reference internal" href="#data-at-rest">1.3. Data at rest</a></li>
<li class="toctree-l2"><a class="reference internal" href="#global-timestamped-receipts">1.4. Global timestamped receipts</a></li>
<li class="toctree-l2"><a class="reference internal" href="#peergos-evaluated-in-europe">1.5. Peergos, evaluated in Europe</a></li>
<li class="toctree-l2"><a class="reference internal" href="#verae-global-timestamping">1.6. Verae global timestamping</a></li>
<li class="toctree-l2"><a class="reference internal" href="#write-once-iceberg-archive">1.7. Write-once Iceberg archive</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-this-briefing-is-and-is-not">1.8. What this briefing is, and is not</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">3. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">6. Global timestamped receipts</a></li>
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">7. Peergos security evaluations in Europe</a></li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">8. Verae global timestamping — a cross-blockchain receipt</a></li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">12. Audit-ready checklist</a></li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">13. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">15. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
</ul>
<div class="relations">
<h3>Related Topics</h3>
<ul>
<li><a href="index.html">Documentation overview</a><ul>
<li>Previous: <a href="index.html" title="previous chapter">Making yourself audit-ready with Verae DataCubes</a></li>
<li>Next: <a href="what-verae-provides.html" title="next chapter"><span class="section-number">2. </span>What Verae provides — and what it does not</a></li>
</ul></li>
</ul>
</div>
</div>
</div>
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="executive-summary">
<h1><span class="section-number">1. </span>Executive summary<a class="headerlink" href="#executive-summary" title="Link to this heading"></a></h1>
<p>Software alone does not make an organization HIPAA certified, SOC 2
attested, or ISO 27001 certified.</p>
<p>That sentence is the point of this document. It is also the sentence
that is most often skipped when a vendor, an integrator, or an internal
champion shows encryption, hashing, or a pentest PDF and treats the
conversation as finished. It is not finished. Encryption is a control.
A pentest is an evaluation of a component. A certificate, an attestation,
or a covered-entity determination is a statement about <strong>an organization</strong>
— its legal entity, its people, its written policies, its operating
procedures, its internal controls, the evidence those controls produce,
and the independent party that examined that evidence.</p>
<p>The Verae DataCube Solution gives an organization tools to <strong>store</strong>,
<strong>communicate</strong>, <strong>timestamp</strong>, <strong>verify</strong>, and <strong>audit</strong> for compliance.
Those tools are real, they are specific, and they are described in the
chapters that follow. They are still only tools. To obtain HIPAA-aligned
status as a covered entity or business associate with a defensible
program, a SOC 2 Type I or Type II report, or an ISO 27001 certificate,
the organization must still:</p>
<ul class="simple">
<li><p>write and live by <strong>policies</strong> (what the organization says it will do);</p></li>
<li><p>operate <strong>procedures</strong> (how staff actually do it, every day);</p></li>
<li><p>design and test <strong>internal controls</strong> (the checks that catch failure);</p></li>
<li><p>retain <strong>evidence</strong> (logs, tickets, screenshots, signed approvals,
restore tests, training records);</p></li>
<li><p>engage an <strong>independent auditor</strong>, CPA firm, or ISO registrar, as the
chosen program requires.</p></li>
</ul>
<p>Verae cannot issue those certificates. Verae cannot sit in the
organizations chair during an OCR investigation, a SOC 2 fieldwork
week, or an ISO Stage 2 audit. What Verae can do — and what this
briefing is written to make precise — is provide the <strong>tools</strong>, the
<strong>background</strong>, and the <strong>software infrastructure</strong> that make it easier
to implement the <strong>technical portion</strong> of those programs.</p>
<section id="what-a-verae-datacube-server-solution-does">
<h2><span class="section-number">1.1. </span>What a Verae DataCube Server Solution does<a class="headerlink" href="#what-a-verae-datacube-server-solution-does" title="Link to this heading"></a></h2>
<p>A Verae DataCube Server Solution provides <strong>secure communications and
storage</strong> for two classical information-security states:</p>
<ul class="simple">
<li><p><strong>Data in transit</strong> — messages, objects, and control traffic while
they move from one endpoint to another.</p></li>
<li><p><strong>Data at rest</strong> — messages, objects, metadata, and receipts while
they sit on disk, in a replica, or in an archive.</p></li>
</ul>
<p>Those two states are not the same problem, and they are not solved by
the same mechanism. This document treats them separately on purpose.</p>
</section>
<section id="data-in-transit">
<h2><span class="section-number">1.2. </span>Data in transit<a class="headerlink" href="#data-in-transit" title="Link to this heading"></a></h2>
<p>Verae uses best-in-class encryption for messaging <strong>from point to
point</strong>. The content of a message is sealed so that only the intended
endpoints can open it. Routing, however, <strong>must remain visible</strong>: a
message that cannot be addressed cannot be delivered. Subjects,
destination handles, and size or timing metadata are therefore
visible to the transport. The transport is treated as
<strong>honest-but-curious</strong>. It can drop, delay, or copy ciphertext. It
cannot read the body if it does not hold endpoint private keys.</p>
</section>
<section id="data-at-rest">
<h2><span class="section-number">1.3. </span>Data at rest<a class="headerlink" href="#data-at-rest" title="Link to this heading"></a></h2>
<p>Encryption at rest is performed through <strong>IPFS content-addressed
blocks</strong>. Each block is named by its hash. Peergos verifies those
hashes on read and on write. A restore is therefore
<strong>tamper-evident</strong>: if a block was altered, its hash no longer
matches, and the client refuses it. This is not a plaintext tape
backup. It is a re-fetch of hashed ciphertext plus a verification
that the bits are the bits that were stored.</p>
</section>
<section id="global-timestamped-receipts">
<h2><span class="section-number">1.4. </span>Global timestamped receipts<a class="headerlink" href="#global-timestamped-receipts" title="Link to this heading"></a></h2>
<p>Independently of who stores the bytes, Verae issues <strong>global
timestamped receipts</strong> based on <strong>document hashes</strong>. A receipt is
proof of the <strong>time and sequence of the first registration</strong> of a
block of digital information — a message, an image, a document, or
any other digital object that can be stored in digital media. The
receipt does not require Verae to see the object. It requires a
fingerprint of the object, registered at a time that can later be
shown to third parties.</p>
</section>
<section id="peergos-evaluated-in-europe">
<h2><span class="section-number">1.5. </span>Peergos, evaluated in Europe<a class="headerlink" href="#peergos-evaluated-in-europe" title="Link to this heading"></a></h2>
<p>The offline storage and replication system used with Peergos was
<strong>audited twice in Europe</strong>, and the protocol was designed under
work that was independently reviewed:</p>
<ul class="simple">
<li><p><strong>2019 — Cure53, Berlin, Germany.</strong> Pentest, source-code audit,
and <strong>crypto/design review</strong> (MayJune 2019). No fundamental
architectural or cryptographic problems. Issues found were fixed.
Cure53 stated that the platform <strong>passed this evaluation</strong>.</p></li>
<li><p><strong>2024 — Radically Open Security B.V., Amsterdam, Netherlands.</strong>
Crystal-box pentest plus code audit of the Peergos web UI
(SeptemberNovember 2024). <strong>Zero</strong> findings rated extreme, high,
or elevated; <strong>two</strong> moderate; <strong>six</strong> low. Peergos states all
were fixed. No data exposure and no integrity compromise (the
issues were mostly UI crashes).</p></li>
</ul>
<p>Both firms are <strong>EU-based</strong>. Both full reports are <strong>public</strong>. That
is a <strong>security evaluation of the Peergos protocol and
implementation</strong>. It is <strong>not</strong> a HIPAA certificate, a SOC 2 report,
or an ISO 27001 certificate for Peergos, for Verae, or for any
customer.</p>
</section>
<section id="verae-global-timestamping">
<h2><span class="section-number">1.6. </span>Verae global timestamping<a class="headerlink" href="#verae-global-timestamping" title="Link to this heading"></a></h2>
<p>The Verae Global Timestamping and receipt solution is a
<strong>cross-blockchain</strong> design. It certifies the time and date stamp of
a digital object and stores that information in a <strong>digital bundle</strong>
that can carry private metadata, attached files, and an internal
blockchain. That organizational chain is <strong>cross-verified</strong> either:</p>
<ul class="simple">
<li><p>from an organizational server <strong>linked to the central Verae
server</strong>, or</p></li>
<li><p>by <strong>directly syncing</strong> with Veraes central timestamping server.</p></li>
</ul>
<p>The result is <strong>proof of existence</strong> of a digital object at a
specific time and date. When the organization wants the object
itself stored — not only its fingerprint — the object can live
inside an <strong>encrypted Peergos DataCube</strong>.</p>
</section>
<section id="write-once-iceberg-archive">
<h2><span class="section-number">1.7. </span>Write-once Iceberg archive<a class="headerlink" href="#write-once-iceberg-archive" title="Link to this heading"></a></h2>
<p>Those DataCubes are archived into a <strong>write-once external Iceberg
file-storage solution</strong> for compliance reasons. The archive is
designed to sit <strong>outside the deletion control of any single
party</strong>. That is a retention and legal-hold property, not a
marketing slogan: once a cube is committed to the write-once tier,
neither the customer operator, nor Verae, nor a hosting vendor
should be able to quietly erase it.</p>
</section>
<section id="what-this-briefing-is-and-is-not">
<h2><span class="section-number">1.8. </span>What this briefing is, and is not<a class="headerlink" href="#what-this-briefing-is-and-is-not" title="Link to this heading"></a></h2>
<p>This briefing describes the <strong>technical portion</strong> of a compliance
program that an organization can build with Verae DataCubes. It
indexes each of the points above as its own chapter, in enough
detail that a CISO, a CCO, outside counsel, or an auditor can
distinguish:</p>
<ul class="simple">
<li><p>what the software <strong>does</strong>;</p></li>
<li><p>what the independent <strong>Peergos evaluations</strong> actually said;</p></li>
<li><p>what <strong>Verae timestamping</strong> actually proves;</p></li>
<li><p>what the organization <strong>must still write, operate, and have
examined</strong>.</p></li>
</ul>
<p>It does not claim that installing this software finishes HIPAA,
SOC 2, or ISO 27001. Anyone who says otherwise is not describing
this product honestly.</p>
</section>
</section>
</div>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="verae-page-footer">
<strong>Verae Inc</strong>
&middot; <a href="https://www.verae.com">https://www.verae.com</a>
&middot; Book a call at <a href="https://www.verae.com">verae.com</a>
&middot; <a href="https://app.verae.com">app.verae.com</a>
</div>
<div class="footer">
&#169;2026, Verae Inc.
</div>
</body>
</html>