Rewrite audit-ready briefing: software is not a certificate.
Some checks are pending
ci / markdown (push) Waiting to run

Open with an executive summary that HIPAA, SOC 2, and ISO 27001
are organizational programs. Verae DataCubes supply store,
communicate, timestamp, verify, and audit tools for the technical
portion only. Chapters cover transit (HPKE, visible routing), rest
(IPFS/Peergos hash-verified restore), receipts, EU Peergos
evaluations (Cure53 2019, ROS 2024), cross-blockchain timestamping,
and write-once Iceberg archive. PDF is branded with the Verae logo
top-left and Verae Inc contact in the footer; last chapters are
sourced bios for Garfinkel (FINRA CRD 5052743), Haber, and Lambert.
This commit is contained in:
George Lambert 2026-09-16 00:55:21 -04:00
parent da60402e88
commit 4fcbb9ac95
53 changed files with 6323 additions and 814 deletions

View file

@ -5,16 +5,19 @@
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>How to use this pack &#8212; Making yourself audit-ready with Verae DataCubes</title>
<title>13. How to use this briefing &#8212; Making yourself audit-ready with Verae DataCubes</title>
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=27fed22d" />
<script src="_static/documentation_options.js?v=5929fcd5"></script>
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
<script src="_static/documentation_options.js?v=250a654d"></script>
<script src="_static/doctools.js?v=fd6eb6e6"></script>
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
<link rel="icon" href="_static/VeraeFullLogo.png"/>
<link rel="index" title="Index" href="genindex.html" />
<link rel="search" title="Search" href="search.html" />
<link rel="prev" title="Audit-ready checklist" href="checklist.html" />
<link rel="next" title="14. James H. Garfinkel" href="bio-james-garfinkel.html" />
<link rel="prev" title="12. Audit-ready checklist" href="checklist.html" />
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
@ -23,51 +26,24 @@
</head><body>
<div class="document">
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="how-to-use-this-pack">
<h1>How to use this pack<a class="headerlink" href="#how-to-use-this-pack" title="Link to this heading"></a></h1>
<ol class="arabic simple">
<li><p>Read <a class="reference internal" href="verification.html"><span class="doc">Peergos verification (what was actually audited)</span></a> so you do not over-claim Peergos audits.</p></li>
<li><p>Fill <a class="reference internal" href="checklist.html"><span class="doc">Audit-ready checklist</span></a> with <strong>your</strong> instance evidence (ns1, keys, users).</p></li>
<li><p>Give <a class="reference internal" href="baa-dpa.html"><span class="doc">BAAs and DPAs when ciphertext has no host keys</span></a> to counsel with the data-flow from <a class="reference internal" href="architecture.html"><span class="doc">Architecture (audit interview)</span></a>.</p></li>
<li><p>Point auditors at live technical surfaces (do not give them private keys).</p></li>
</ol>
<ul class="simple">
<li><p><a class="reference external" href="https://pfc.georgelambert.org/health">https://pfc.georgelambert.org/health</a></p></li>
<li><p><a class="reference external" href="https://pfc.georgelambert.org/v1/npe/keys">https://pfc.georgelambert.org/v1/npe/keys</a> (public keys only)</p></li>
<li><p><a class="reference external" href="https://docs.pfc.georgelambert.org/controls.html">https://docs.pfc.georgelambert.org/controls.html</a></p></li>
<li><p><a class="reference external" href="https://docs.pfc.georgelambert.org/custody.html">https://docs.pfc.georgelambert.org/custody.html</a></p></li>
<li><p>Peergos Drive (cryptree) on your host</p></li>
<li><p><a class="reference external" href="https://git.georgelambert.org/marchon/peergos-for-compliance">https://git.georgelambert.org/marchon/peergos-for-compliance</a></p></li>
<li><p><a class="reference external" href="https://git.georgelambert.org/marchon/system-git-sync">https://git.georgelambert.org/marchon/system-git-sync</a></p></li>
<li><p><a class="reference external" href="https://git.georgelambert.org/marchon/secure-messaging">https://git.georgelambert.org/marchon/secure-messaging</a></p></li>
</ul>
<ol class="arabic simple" start="5">
<li><p>Attach the two <strong>public</strong> Peergos pentest PDFs from the Peergos
<code class="docutils literal notranslate"><span class="pre">audits/</span></code> tree as <strong>vendor security evaluations</strong>, labeled “not our
SOC 2 / ISO certificate”.</p></li>
</ol>
</section>
</div>
</div>
</div>
<div class="document">
<div class="sphinxsidebar" role="navigation" aria-label="Main">
<div class="sphinxsidebarwrapper">
<h1 class="logo"><a href="index.html">Making yourself audit-ready with Verae DataCubes</a></h1>
<p class="logo"><a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo of Making yourself audit-ready with Verae DataCubes"/>
</a></p>
<p class="logo">
<a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo" />
</a>
</p>
<p class="blurb">Tools for storage, communications, timestamping, verification, and audit — not a certificate.</p>
@ -83,19 +59,33 @@ SOC 2 / ISO certificate”.</p></li>
</div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="verification.html">Peergos verification (what was actually audited)</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">Architecture (audit interview)</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">BAAs and DPAs when ciphertext has no host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">Audit-ready checklist</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">How to use this pack</a></li>
<li class="toctree-l1"><a class="reference internal" href="executive.html">1. Executive summary</a></li>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">3. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">6. Global timestamped receipts</a></li>
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">7. Peergos security evaluations in Europe</a></li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">8. Verae global timestamping — a cross-blockchain receipt</a></li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">12. Audit-ready checklist</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">13. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">15. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
</ul>
<div class="relations">
<h3>Related Topics</h3>
<ul>
<li><a href="index.html">Documentation overview</a><ul>
<li>Previous: <a href="checklist.html" title="previous chapter">Audit-ready checklist</a></li>
<li>Previous: <a href="checklist.html" title="previous chapter"><span class="section-number">12. </span>Audit-ready checklist</a></li>
<li>Next: <a href="bio-james-garfinkel.html" title="next chapter"><span class="section-number">14. </span>James H. Garfinkel</a></li>
</ul></li>
</ul>
</div>
@ -109,22 +99,81 @@ SOC 2 / ISO certificate”.</p></li>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="how-to-use-this-briefing">
<h1><span class="section-number">13. </span>How to use this briefing<a class="headerlink" href="#how-to-use-this-briefing" title="Link to this heading"></a></h1>
<ol class="arabic simple">
<li><p>Read the <strong>executive summary</strong> aloud in the first five
minutes of any vendor, board, or auditor meeting that
touches this system. If anyone says “so we are certified,”
stop and reread Chapter 1.</p></li>
<li><p>Read <strong>What Verae provides</strong> so the five verbs (store,
communicate, timestamp, verify, audit) are not confused
with an ISMS, a Type II, or a HIPAA program.</p></li>
<li><p>Read the <strong>transit</strong>, <strong>rest</strong>, <strong>receipts</strong>, <strong>Peergos
evaluations</strong>, <strong>timestamping</strong>, and <strong>Iceberg</strong> chapters
in that order. They are the technical portion, in the
order an examiner usually probes: “can the wire read it,
can the disk read it, can you prove when, who looked at
the crypto, can you produce it later.”</p></li>
<li><p>Fill the <strong>checklist</strong> with <strong>this instances</strong> evidence.
Empty checkboxes are not a moral failing; they are the
work remaining.</p></li>
<li><p>Give <strong>BAAs and DPAs</strong> to counsel with the architecture
diagram. Do not let engineering declare a vendor “not a
BA.”</p></li>
<li><p>Attach the two <strong>public</strong> Peergos reports as <strong>vendor
security evaluations</strong>, with a cover slip that says they
are not the organizations SOC 2, ISO 27001, or HIPAA
certification.</p></li>
<li><p>Point auditors at <strong>live technical surfaces</strong> (health,
public-key listing, Drive). Do not give them private
keys. Do not give them a story that the pentest PDF is
the Type II.</p></li>
<li><p>Keep the <strong>biographies</strong> at the back of the PDF for
provenance — who built the timestamping science, who
is building the product, who architected the internet
integration and the DataCube server side — without
substituting biography for controls.</p></li>
</ol>
<p>Reference instance (not a certificate):</p>
<ul class="simple">
<li><p><a class="reference external" href="https://pfc.georgelambert.org/health">https://pfc.georgelambert.org/health</a></p></li>
<li><p><a class="reference external" href="https://pfc.georgelambert.org/v1/npe/keys">https://pfc.georgelambert.org/v1/npe/keys</a> (public keys only)</p></li>
<li><p><a class="reference external" href="https://docs.pfc.georgelambert.org/controls.html">https://docs.pfc.georgelambert.org/controls.html</a></p></li>
<li><p><a class="reference external" href="https://docs.pfc.georgelambert.org/custody.html">https://docs.pfc.georgelambert.org/custody.html</a></p></li>
<li><p><a class="reference external" href="https://git.georgelambert.org/marchon/peergos-making-yourself-audit-ready-with-verae-datacubes">https://git.georgelambert.org/marchon/peergos-making-yourself-audit-ready-with-verae-datacubes</a></p></li>
<li><p><a class="reference external" href="https://www.verae.com">https://www.verae.com</a></p></li>
</ul>
</section>
</div>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="verae-page-footer">
<strong>Verae Inc</strong>
&middot; <a href="https://www.verae.com">https://www.verae.com</a>
&middot; Book a call at <a href="https://www.verae.com">verae.com</a>
&middot; <a href="https://app.verae.com">app.verae.com</a>
</div>
<div class="footer">
&#169;2026, Verae.
&#169;2026, Verae Inc.
|
Powered by <a href="https://www.sphinx-doc.org/">Sphinx 9.1.0</a>
&amp; <a href="https://alabaster.readthedocs.io">Alabaster 1.0.0</a>
|
<a href="_sources/howto.rst.txt"
rel="nofollow">Page source</a>
</div>
</body>
</html>