Rewrite audit-ready briefing: software is not a certificate.
Some checks are pending
ci / markdown (push) Waiting to run
Some checks are pending
ci / markdown (push) Waiting to run
Open with an executive summary that HIPAA, SOC 2, and ISO 27001 are organizational programs. Verae DataCubes supply store, communicate, timestamp, verify, and audit tools for the technical portion only. Chapters cover transit (HPKE, visible routing), rest (IPFS/Peergos hash-verified restore), receipts, EU Peergos evaluations (Cure53 2019, ROS 2024), cross-blockchain timestamping, and write-once Iceberg archive. PDF is branded with the Verae logo top-left and Verae Inc contact in the footer; last chapters are sourced bios for Garfinkel (FINRA CRD 5052743), Haber, and Lambert.
This commit is contained in:
parent
da60402e88
commit
4fcbb9ac95
53 changed files with 6323 additions and 814 deletions
266
build/html/global-timestamping.html
Normal file
266
build/html/global-timestamping.html
Normal file
|
|
@ -0,0 +1,266 @@
|
|||
<!DOCTYPE html>
|
||||
|
||||
<html lang="en" data-content_root="./">
|
||||
<head>
|
||||
<meta charset="utf-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
|
||||
|
||||
<title>8. Verae global timestamping — a cross-blockchain receipt — Making yourself audit-ready with Verae DataCubes</title>
|
||||
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
|
||||
<script src="_static/documentation_options.js?v=250a654d"></script>
|
||||
<script src="_static/doctools.js?v=fd6eb6e6"></script>
|
||||
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
|
||||
<link rel="icon" href="_static/VeraeFullLogo.png"/>
|
||||
<link rel="index" title="Index" href="genindex.html" />
|
||||
<link rel="search" title="Search" href="search.html" />
|
||||
<link rel="next" title="9. Write-once Iceberg archive" href="iceberg-archive.html" />
|
||||
<link rel="prev" title="7. Peergos security evaluations in Europe" href="peergos-eu-evaluations.html" />
|
||||
|
||||
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
</head><body>
|
||||
<div class="document">
|
||||
|
||||
<div class="sphinxsidebar" role="navigation" aria-label="Main">
|
||||
<div class="sphinxsidebarwrapper">
|
||||
<p class="logo"><a href="index.html">
|
||||
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo of Making yourself audit-ready with Verae DataCubes"/>
|
||||
</a></p>
|
||||
<p class="logo">
|
||||
<a href="index.html">
|
||||
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo" />
|
||||
|
||||
</a>
|
||||
</p>
|
||||
|
||||
|
||||
|
||||
<p class="blurb">Tools for storage, communications, timestamping, verification, and audit — not a certificate.</p>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
<search id="searchbox" style="display: none" role="search">
|
||||
<div class="searchformwrapper">
|
||||
<form class="search" action="search.html" method="get">
|
||||
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false" placeholder="Search"/>
|
||||
<input type="submit" value="Go" />
|
||||
</form>
|
||||
</div>
|
||||
</search>
|
||||
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
|
||||
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
|
||||
<ul class="current">
|
||||
<li class="toctree-l1"><a class="reference internal" href="executive.html">1. Executive summary</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">3. The Verae DataCube Server Solution</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">6. Global timestamped receipts</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">7. Peergos security evaluations in Europe</a></li>
|
||||
<li class="toctree-l1 current"><a class="current reference internal" href="#">8. Verae global timestamping — a cross-blockchain receipt</a><ul>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#lineage">8.1. Lineage</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#what-cross-blockchain-means-here">8.2. What “cross-blockchain” means here</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#two-deployment-patterns">8.3. Two deployment patterns</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#the-digital-bundle">8.4. The digital bundle</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#proof-of-existence-versus-proof-of-custody">8.5. Proof of existence versus proof of custody</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#what-this-does-and-does-not-satisfy">8.6. What this does, and does not, satisfy</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="checklist.html">12. Audit-ready checklist</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="howto.html">13. How to use this briefing</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">15. Stuart Haber</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
|
||||
</ul>
|
||||
|
||||
<div class="relations">
|
||||
<h3>Related Topics</h3>
|
||||
<ul>
|
||||
<li><a href="index.html">Documentation overview</a><ul>
|
||||
<li>Previous: <a href="peergos-eu-evaluations.html" title="previous chapter"><span class="section-number">7. </span>Peergos security evaluations in Europe</a></li>
|
||||
<li>Next: <a href="iceberg-archive.html" title="next chapter"><span class="section-number">9. </span>Write-once Iceberg archive</a></li>
|
||||
</ul></li>
|
||||
</ul>
|
||||
</div>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
</div>
|
||||
</div>
|
||||
<div class="documentwrapper">
|
||||
<div class="bodywrapper">
|
||||
|
||||
|
||||
<div class="body" role="main">
|
||||
|
||||
<section id="verae-global-timestamping-a-cross-blockchain-receipt">
|
||||
<h1><span class="section-number">8. </span>Verae global timestamping — a cross-blockchain receipt<a class="headerlink" href="#verae-global-timestamping-a-cross-blockchain-receipt" title="Link to this heading">¶</a></h1>
|
||||
<section id="lineage">
|
||||
<h2><span class="section-number">8.1. </span>Lineage<a class="headerlink" href="#lineage" title="Link to this heading">¶</a></h2>
|
||||
<p>The scientific problem Verae is productizing is not new. In
|
||||
1991, Stuart Haber and W. Scott Stornetta published “How to
|
||||
Time-Stamp a Digital Document” in the <em>Journal of
|
||||
Cryptology</em>. They asked how to certify when a digital
|
||||
document was created or last changed <strong>without trusting the
|
||||
medium</strong> and <strong>without giving the timestamping service the
|
||||
document</strong>. In 1993, with Dave Bayer, they showed how Merkle
|
||||
trees make that efficient. In 1997 they published “Secure
|
||||
names for bit-strings.” Satoshi Nakamoto’s 2008 Bitcoin
|
||||
white paper cites those three papers as references [3], [4],
|
||||
and [5] — three of the eight citations in that document.</p>
|
||||
<p>Haber co-founded <strong>Surety</strong> in 1994, widely described as the
|
||||
first commercial blockchain: a hash-linked chain of document
|
||||
certificates, with a weekly summary published in the Sunday
|
||||
<em>New York Times</em> so that the day’s commitments sat in a
|
||||
public, widely archived analog record.</p>
|
||||
<p>Haber is a <strong>co-founder of Verae</strong>. Verae’s public site
|
||||
states the aim directly: make that proof simple enough for a
|
||||
compliance team and precise enough for an SEC exam, without
|
||||
forcing the enterprise to operate a public blockchain. The
|
||||
quote on verae.com is: “I co-founded Verae to make
|
||||
blockchain accessible to enterprises without having to deal
|
||||
with the complexity of blockchain.”</p>
|
||||
</section>
|
||||
<section id="what-cross-blockchain-means-here">
|
||||
<h2><span class="section-number">8.2. </span>What “cross-blockchain” means here<a class="headerlink" href="#what-cross-blockchain-means-here" title="Link to this heading">¶</a></h2>
|
||||
<p>A single private log, held only by the vendor, is a vendor
|
||||
assurance letter with extra steps. A single public chain may
|
||||
be operationally and commercially the wrong place to put an
|
||||
enterprise’s registration traffic. Verae’s design is
|
||||
<strong>cross-blockchain</strong> in the following sense:</p>
|
||||
<ul class="simple">
|
||||
<li><p>an <strong>organizational chain</strong> runs at the customer, inside
|
||||
or beside the DataCube, recording hashes, metadata, and
|
||||
sequence;</p></li>
|
||||
<li><p>a <strong>central Verae chain</strong> records fingerprints and issues
|
||||
receipts;</p></li>
|
||||
<li><p>the two are <strong>cross-verified</strong>, so that neither side can
|
||||
rewrite history without the other side’s record disagreeing;</p></li>
|
||||
<li><p>when policy calls for it, commitments can be <strong>anchored
|
||||
further</strong> — additional public or consortium chains — so
|
||||
that proof of existence does not collapse if one operator
|
||||
disappears.</p></li>
|
||||
</ul>
|
||||
<p>The customer does not have to become a blockchain operator
|
||||
to use this. That is the product claim. The examiner does
|
||||
not have to trust a single vendor’s database to verify a
|
||||
receipt. That is the scientific claim, inherited from
|
||||
Haber–Stornetta.</p>
|
||||
</section>
|
||||
<section id="two-deployment-patterns">
|
||||
<h2><span class="section-number">8.3. </span>Two deployment patterns<a class="headerlink" href="#two-deployment-patterns" title="Link to this heading">¶</a></h2>
|
||||
<p><strong>Linked organizational server.</strong> The organization runs a
|
||||
timestamping node next to its DataCube server. That node is
|
||||
linked to the central Verae timestamping server. Local
|
||||
registrations are committed locally (low latency, private
|
||||
metadata stays home) and cross-verified centrally (receipt
|
||||
the rest of the world can check).</p>
|
||||
<p><strong>Direct sync.</strong> An organization that does not want to run
|
||||
the organizational node can sync registrations directly with
|
||||
Verae’s central timestamping server. Proof of existence at a
|
||||
specific date and time still issues. Private metadata and
|
||||
attached files, if any, remain the organization’s problem to
|
||||
store — typically in the encrypted Peergos DataCube.</p>
|
||||
<p>Both patterns produce the same external artifact: a receipt
|
||||
bound to a hash, a time, and a sequence. They differ in
|
||||
where the organizational metadata lives and in how much
|
||||
infrastructure the customer operates.</p>
|
||||
</section>
|
||||
<section id="the-digital-bundle">
|
||||
<h2><span class="section-number">8.4. </span>The digital bundle<a class="headerlink" href="#the-digital-bundle" title="Link to this heading">¶</a></h2>
|
||||
<p>The unit of production is a <strong>digital bundle</strong>:</p>
|
||||
<ul class="simple">
|
||||
<li><p>the <strong>receipt</strong> (hash, time, sequence, verification path);</p></li>
|
||||
<li><p><strong>private metadata</strong> (classification, matter, hold,
|
||||
internal identifiers) that need not be on a public chain;</p></li>
|
||||
<li><p><strong>attached files</strong> that should be produced together;</p></li>
|
||||
<li><p>a pointer or capability to the object in the encrypted
|
||||
DataCube, when the organization chose to store the object
|
||||
and not only its fingerprint.</p></li>
|
||||
</ul>
|
||||
<p>An examiner can be given the bundle, or a redacted bundle,
|
||||
without being given a login to the production console and
|
||||
without Verae ever having seen the object bytes.</p>
|
||||
</section>
|
||||
<section id="proof-of-existence-versus-proof-of-custody">
|
||||
<h2><span class="section-number">8.5. </span>Proof of existence versus proof of custody<a class="headerlink" href="#proof-of-existence-versus-proof-of-custody" title="Link to this heading">¶</a></h2>
|
||||
<p>Timestamping answers: <strong>did these bits exist by this time?</strong></p>
|
||||
<p>The DataCube answers: <strong>does the organization still have
|
||||
them, encrypted, hash-checkable?</strong></p>
|
||||
<p>The Iceberg write-once tier answers: <strong>can anyone quietly
|
||||
delete them anyway?</strong></p>
|
||||
<p>A complete production to a regulator often needs all three.
|
||||
Timestamping alone is not an archive. An archive without a
|
||||
receipt is a pile of files with a clock on the filesystem
|
||||
that the administrator can set.</p>
|
||||
</section>
|
||||
<section id="what-this-does-and-does-not-satisfy">
|
||||
<h2><span class="section-number">8.6. </span>What this does, and does not, satisfy<a class="headerlink" href="#what-this-does-and-does-not-satisfy" title="Link to this heading">¶</a></h2>
|
||||
<p>For SEC Rule 17a-4, FINRA books-and-records, and similar
|
||||
regimes that demand records in a non-rewriteable,
|
||||
non-erasable form <strong>with the ability to produce the
|
||||
original</strong>, timestamped receipts plus write-once archive are
|
||||
the <strong>technical portion</strong> of the answer: you can show when
|
||||
the record was sealed, that the bits match, and that the
|
||||
archive copy is not under ordinary delete.</p>
|
||||
<p>They do not satisfy:</p>
|
||||
<ul class="simple">
|
||||
<li><p>the requirement to <strong>capture the channel in the first
|
||||
place</strong> (if the team used an unsealed tool, there is
|
||||
nothing to timestamp);</p></li>
|
||||
<li><p>the requirement to have <strong>written procedures</strong> for
|
||||
production, legal hold, and supervision;</p></li>
|
||||
<li><p>the requirement that a <strong>named principal</strong> own the
|
||||
recordkeeping obligation.</p></li>
|
||||
</ul>
|
||||
<p>Software seals what it is shown. The organization must still
|
||||
show it the right things, on time, under a policy someone
|
||||
will sign.</p>
|
||||
</section>
|
||||
</section>
|
||||
|
||||
|
||||
</div>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
<div class="clearer"></div>
|
||||
</div>
|
||||
<div class="verae-page-footer">
|
||||
<strong>Verae Inc</strong>
|
||||
· <a href="https://www.verae.com">https://www.verae.com</a>
|
||||
· Book a call at <a href="https://www.verae.com">verae.com</a>
|
||||
· <a href="https://app.verae.com">app.verae.com</a>
|
||||
</div>
|
||||
|
||||
<div class="footer">
|
||||
©2026, Verae Inc.
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
</body>
|
||||
</html>
|
||||
Loading…
Add table
Add a link
Reference in a new issue