Rewrite audit-ready briefing: software is not a certificate.
Some checks are pending
ci / markdown (push) Waiting to run

Open with an executive summary that HIPAA, SOC 2, and ISO 27001
are organizational programs. Verae DataCubes supply store,
communicate, timestamp, verify, and audit tools for the technical
portion only. Chapters cover transit (HPKE, visible routing), rest
(IPFS/Peergos hash-verified restore), receipts, EU Peergos
evaluations (Cure53 2019, ROS 2024), cross-blockchain timestamping,
and write-once Iceberg archive. PDF is branded with the Verae logo
top-left and Verae Inc contact in the footer; last chapters are
sourced bios for Garfinkel (FINRA CRD 5052743), Haber, and Lambert.
This commit is contained in:
George Lambert 2026-09-16 00:55:21 -04:00
parent da60402e88
commit 4fcbb9ac95
53 changed files with 6323 additions and 814 deletions

View file

@ -0,0 +1,266 @@
<!DOCTYPE html>
<html lang="en" data-content_root="./">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>8. Verae global timestamping — a cross-blockchain receipt &#8212; Making yourself audit-ready with Verae DataCubes</title>
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
<script src="_static/documentation_options.js?v=250a654d"></script>
<script src="_static/doctools.js?v=fd6eb6e6"></script>
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
<link rel="icon" href="_static/VeraeFullLogo.png"/>
<link rel="index" title="Index" href="genindex.html" />
<link rel="search" title="Search" href="search.html" />
<link rel="next" title="9. Write-once Iceberg archive" href="iceberg-archive.html" />
<link rel="prev" title="7. Peergos security evaluations in Europe" href="peergos-eu-evaluations.html" />
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
</head><body>
<div class="document">
<div class="sphinxsidebar" role="navigation" aria-label="Main">
<div class="sphinxsidebarwrapper">
<p class="logo"><a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo of Making yourself audit-ready with Verae DataCubes"/>
</a></p>
<p class="logo">
<a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo" />
</a>
</p>
<p class="blurb">Tools for storage, communications, timestamping, verification, and audit — not a certificate.</p>
<search id="searchbox" style="display: none" role="search">
<div class="searchformwrapper">
<form class="search" action="search.html" method="get">
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false" placeholder="Search"/>
<input type="submit" value="Go" />
</form>
</div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="executive.html">1. Executive summary</a></li>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">3. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">6. Global timestamped receipts</a></li>
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">7. Peergos security evaluations in Europe</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">8. Verae global timestamping — a cross-blockchain receipt</a><ul>
<li class="toctree-l2"><a class="reference internal" href="#lineage">8.1. Lineage</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-cross-blockchain-means-here">8.2. What “cross-blockchain” means here</a></li>
<li class="toctree-l2"><a class="reference internal" href="#two-deployment-patterns">8.3. Two deployment patterns</a></li>
<li class="toctree-l2"><a class="reference internal" href="#the-digital-bundle">8.4. The digital bundle</a></li>
<li class="toctree-l2"><a class="reference internal" href="#proof-of-existence-versus-proof-of-custody">8.5. Proof of existence versus proof of custody</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-this-does-and-does-not-satisfy">8.6. What this does, and does not, satisfy</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">12. Audit-ready checklist</a></li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">13. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">15. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
</ul>
<div class="relations">
<h3>Related Topics</h3>
<ul>
<li><a href="index.html">Documentation overview</a><ul>
<li>Previous: <a href="peergos-eu-evaluations.html" title="previous chapter"><span class="section-number">7. </span>Peergos security evaluations in Europe</a></li>
<li>Next: <a href="iceberg-archive.html" title="next chapter"><span class="section-number">9. </span>Write-once Iceberg archive</a></li>
</ul></li>
</ul>
</div>
</div>
</div>
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="verae-global-timestamping-a-cross-blockchain-receipt">
<h1><span class="section-number">8. </span>Verae global timestamping — a cross-blockchain receipt<a class="headerlink" href="#verae-global-timestamping-a-cross-blockchain-receipt" title="Link to this heading"></a></h1>
<section id="lineage">
<h2><span class="section-number">8.1. </span>Lineage<a class="headerlink" href="#lineage" title="Link to this heading"></a></h2>
<p>The scientific problem Verae is productizing is not new. In
1991, Stuart Haber and W. Scott Stornetta published “How to
Time-Stamp a Digital Document” in the <em>Journal of
Cryptology</em>. They asked how to certify when a digital
document was created or last changed <strong>without trusting the
medium</strong> and <strong>without giving the timestamping service the
document</strong>. In 1993, with Dave Bayer, they showed how Merkle
trees make that efficient. In 1997 they published “Secure
names for bit-strings.” Satoshi Nakamotos 2008 Bitcoin
white paper cites those three papers as references [3], [4],
and [5] — three of the eight citations in that document.</p>
<p>Haber co-founded <strong>Surety</strong> in 1994, widely described as the
first commercial blockchain: a hash-linked chain of document
certificates, with a weekly summary published in the Sunday
<em>New York Times</em> so that the days commitments sat in a
public, widely archived analog record.</p>
<p>Haber is a <strong>co-founder of Verae</strong>. Veraes public site
states the aim directly: make that proof simple enough for a
compliance team and precise enough for an SEC exam, without
forcing the enterprise to operate a public blockchain. The
quote on verae.com is: “I co-founded Verae to make
blockchain accessible to enterprises without having to deal
with the complexity of blockchain.”</p>
</section>
<section id="what-cross-blockchain-means-here">
<h2><span class="section-number">8.2. </span>What “cross-blockchain” means here<a class="headerlink" href="#what-cross-blockchain-means-here" title="Link to this heading"></a></h2>
<p>A single private log, held only by the vendor, is a vendor
assurance letter with extra steps. A single public chain may
be operationally and commercially the wrong place to put an
enterprises registration traffic. Veraes design is
<strong>cross-blockchain</strong> in the following sense:</p>
<ul class="simple">
<li><p>an <strong>organizational chain</strong> runs at the customer, inside
or beside the DataCube, recording hashes, metadata, and
sequence;</p></li>
<li><p>a <strong>central Verae chain</strong> records fingerprints and issues
receipts;</p></li>
<li><p>the two are <strong>cross-verified</strong>, so that neither side can
rewrite history without the other sides record disagreeing;</p></li>
<li><p>when policy calls for it, commitments can be <strong>anchored
further</strong> — additional public or consortium chains — so
that proof of existence does not collapse if one operator
disappears.</p></li>
</ul>
<p>The customer does not have to become a blockchain operator
to use this. That is the product claim. The examiner does
not have to trust a single vendors database to verify a
receipt. That is the scientific claim, inherited from
HaberStornetta.</p>
</section>
<section id="two-deployment-patterns">
<h2><span class="section-number">8.3. </span>Two deployment patterns<a class="headerlink" href="#two-deployment-patterns" title="Link to this heading"></a></h2>
<p><strong>Linked organizational server.</strong> The organization runs a
timestamping node next to its DataCube server. That node is
linked to the central Verae timestamping server. Local
registrations are committed locally (low latency, private
metadata stays home) and cross-verified centrally (receipt
the rest of the world can check).</p>
<p><strong>Direct sync.</strong> An organization that does not want to run
the organizational node can sync registrations directly with
Veraes central timestamping server. Proof of existence at a
specific date and time still issues. Private metadata and
attached files, if any, remain the organizations problem to
store — typically in the encrypted Peergos DataCube.</p>
<p>Both patterns produce the same external artifact: a receipt
bound to a hash, a time, and a sequence. They differ in
where the organizational metadata lives and in how much
infrastructure the customer operates.</p>
</section>
<section id="the-digital-bundle">
<h2><span class="section-number">8.4. </span>The digital bundle<a class="headerlink" href="#the-digital-bundle" title="Link to this heading"></a></h2>
<p>The unit of production is a <strong>digital bundle</strong>:</p>
<ul class="simple">
<li><p>the <strong>receipt</strong> (hash, time, sequence, verification path);</p></li>
<li><p><strong>private metadata</strong> (classification, matter, hold,
internal identifiers) that need not be on a public chain;</p></li>
<li><p><strong>attached files</strong> that should be produced together;</p></li>
<li><p>a pointer or capability to the object in the encrypted
DataCube, when the organization chose to store the object
and not only its fingerprint.</p></li>
</ul>
<p>An examiner can be given the bundle, or a redacted bundle,
without being given a login to the production console and
without Verae ever having seen the object bytes.</p>
</section>
<section id="proof-of-existence-versus-proof-of-custody">
<h2><span class="section-number">8.5. </span>Proof of existence versus proof of custody<a class="headerlink" href="#proof-of-existence-versus-proof-of-custody" title="Link to this heading"></a></h2>
<p>Timestamping answers: <strong>did these bits exist by this time?</strong></p>
<p>The DataCube answers: <strong>does the organization still have
them, encrypted, hash-checkable?</strong></p>
<p>The Iceberg write-once tier answers: <strong>can anyone quietly
delete them anyway?</strong></p>
<p>A complete production to a regulator often needs all three.
Timestamping alone is not an archive. An archive without a
receipt is a pile of files with a clock on the filesystem
that the administrator can set.</p>
</section>
<section id="what-this-does-and-does-not-satisfy">
<h2><span class="section-number">8.6. </span>What this does, and does not, satisfy<a class="headerlink" href="#what-this-does-and-does-not-satisfy" title="Link to this heading"></a></h2>
<p>For SEC Rule 17a-4, FINRA books-and-records, and similar
regimes that demand records in a non-rewriteable,
non-erasable form <strong>with the ability to produce the
original</strong>, timestamped receipts plus write-once archive are
the <strong>technical portion</strong> of the answer: you can show when
the record was sealed, that the bits match, and that the
archive copy is not under ordinary delete.</p>
<p>They do not satisfy:</p>
<ul class="simple">
<li><p>the requirement to <strong>capture the channel in the first
place</strong> (if the team used an unsealed tool, there is
nothing to timestamp);</p></li>
<li><p>the requirement to have <strong>written procedures</strong> for
production, legal hold, and supervision;</p></li>
<li><p>the requirement that a <strong>named principal</strong> own the
recordkeeping obligation.</p></li>
</ul>
<p>Software seals what it is shown. The organization must still
show it the right things, on time, under a policy someone
will sign.</p>
</section>
</section>
</div>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="verae-page-footer">
<strong>Verae Inc</strong>
&middot; <a href="https://www.verae.com">https://www.verae.com</a>
&middot; Book a call at <a href="https://www.verae.com">verae.com</a>
&middot; <a href="https://app.verae.com">app.verae.com</a>
</div>
<div class="footer">
&#169;2026, Verae Inc.
</div>
</body>
</html>