Rewrite audit-ready briefing: software is not a certificate.
Some checks are pending
ci / markdown (push) Waiting to run

Open with an executive summary that HIPAA, SOC 2, and ISO 27001
are organizational programs. Verae DataCubes supply store,
communicate, timestamp, verify, and audit tools for the technical
portion only. Chapters cover transit (HPKE, visible routing), rest
(IPFS/Peergos hash-verified restore), receipts, EU Peergos
evaluations (Cure53 2019, ROS 2024), cross-blockchain timestamping,
and write-once Iceberg archive. PDF is branded with the Verae logo
top-left and Verae Inc contact in the footer; last chapters are
sourced bios for Garfinkel (FINRA CRD 5052743), Haber, and Lambert.
This commit is contained in:
George Lambert 2026-09-16 00:55:21 -04:00
parent da60402e88
commit 4fcbb9ac95
53 changed files with 6323 additions and 814 deletions

View file

@ -0,0 +1,274 @@
<!DOCTYPE html>
<html lang="en" data-content_root="./">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>7. Peergos security evaluations in Europe &#8212; Making yourself audit-ready with Verae DataCubes</title>
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
<script src="_static/documentation_options.js?v=250a654d"></script>
<script src="_static/doctools.js?v=fd6eb6e6"></script>
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
<link rel="icon" href="_static/VeraeFullLogo.png"/>
<link rel="index" title="Index" href="genindex.html" />
<link rel="search" title="Search" href="search.html" />
<link rel="next" title="8. Verae global timestamping — a cross-blockchain receipt" href="global-timestamping.html" />
<link rel="prev" title="6. Global timestamped receipts" href="timestamped-receipts.html" />
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
</head><body>
<div class="document">
<div class="sphinxsidebar" role="navigation" aria-label="Main">
<div class="sphinxsidebarwrapper">
<p class="logo"><a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo of Making yourself audit-ready with Verae DataCubes"/>
</a></p>
<p class="logo">
<a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo" />
</a>
</p>
<p class="blurb">Tools for storage, communications, timestamping, verification, and audit — not a certificate.</p>
<search id="searchbox" style="display: none" role="search">
<div class="searchformwrapper">
<form class="search" action="search.html" method="get">
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false" placeholder="Search"/>
<input type="submit" value="Go" />
</form>
</div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="executive.html">1. Executive summary</a></li>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">3. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">6. Global timestamped receipts</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">7. Peergos security evaluations in Europe</a><ul>
<li class="toctree-l2"><a class="reference internal" href="#what-was-evaluated">7.1. What was evaluated</a></li>
<li class="toctree-l2"><a class="reference internal" href="#cure53-berlin-germany">7.2. 2019 — Cure53, Berlin, Germany</a></li>
<li class="toctree-l2"><a class="reference internal" href="#radically-open-security-b-v-amsterdam">7.3. 2024 — Radically Open Security B.V., Amsterdam</a></li>
<li class="toctree-l2"><a class="reference internal" href="#how-to-present-these-reports-to-an-auditor">7.4. How to present these reports to an auditor</a></li>
<li class="toctree-l2"><a class="reference internal" href="#hosted-peergos-versus-self-hosted-datacubes">7.5. Hosted Peergos versus self-hosted DataCubes</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-designed-under-funding-from-cure53-ros-is-not">7.6. What “designed under funding from Cure53 / ROS” is not</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">8. Verae global timestamping — a cross-blockchain receipt</a></li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">12. Audit-ready checklist</a></li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">13. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">15. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
</ul>
<div class="relations">
<h3>Related Topics</h3>
<ul>
<li><a href="index.html">Documentation overview</a><ul>
<li>Previous: <a href="timestamped-receipts.html" title="previous chapter"><span class="section-number">6. </span>Global timestamped receipts</a></li>
<li>Next: <a href="global-timestamping.html" title="next chapter"><span class="section-number">8. </span>Verae global timestamping — a cross-blockchain receipt</a></li>
</ul></li>
</ul>
</div>
</div>
</div>
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="peergos-security-evaluations-in-europe">
<h1><span class="section-number">7. </span>Peergos security evaluations in Europe<a class="headerlink" href="#peergos-security-evaluations-in-europe" title="Link to this heading"></a></h1>
<section id="what-was-evaluated">
<h2><span class="section-number">7.1. </span>What was evaluated<a class="headerlink" href="#what-was-evaluated" title="Link to this heading"></a></h2>
<p>The offline storage and replication system used with Verae
DataCubes is <strong>Peergos</strong>: an encrypted, peer-to-peer filesystem
whose blocks live on IPFS. Peergos was designed as a
trust-minimized store — the server is treated as an adversary
for content and for most metadata — and that design was
submitted to independent European security firms <strong>twice</strong>.</p>
<p>Those engagements are <strong>security evaluations of the Peergos
protocol and implementation</strong>. They are pentests, source-code
audits, and (in 2019) a cryptographic and design review. They
are <strong>not</strong>:</p>
<ul class="simple">
<li><p>a HIPAA certification of Peergos, Verae, or any customer;</p></li>
<li><p>a SOC 2 Type I or Type II report;</p></li>
<li><p>an ISO 27001 certificate of an ISMS;</p></li>
<li><p>a government “certified filesystem” designation.</p></li>
</ul>
<p>Both firms are <strong>EU-based</strong>. Both full reports are <strong>public</strong>.
That combination — independent, European, public, repeat —
is unusual and is worth attaching to a vendor-assurance file,
<strong>labeled correctly</strong>.</p>
</section>
<section id="cure53-berlin-germany">
<h2><span class="section-number">7.2. </span>2019 — Cure53, Berlin, Germany<a class="headerlink" href="#cure53-berlin-germany" title="Link to this heading"></a></h2>
<ul class="simple">
<li><p><strong>Firm:</strong> Cure53</p></li>
<li><p><strong>Location:</strong> Berlin, Germany</p></li>
<li><p><strong>When:</strong> MayJune 2019</p></li>
<li><p><strong>Scope:</strong> pentest, source-code audit, and
<strong>crypto / design review</strong></p></li>
<li><p><strong>Outcome:</strong> no fundamental architectural or cryptographic
problems were identified. Issues that were identified were
fixed. Cure53 stated that the platform <strong>passed this
evaluation</strong>.</p></li>
</ul>
<p>A crypto/design review is a stronger statement than a
black-box pentest of a web form. It is an expert reading of
whether the cryptree, the chunk encryption, the identity
model, and the threat model hang together. “Passed” in
Cure53s language is not an ISO mark. It is a specialist
firm saying: we looked at the cryptography and the
architecture, we did not find a fatal flaw, and the issues we
did find were addressed.</p>
<p>Primary sources (public):</p>
<ul class="simple">
<li><p><a class="reference external" href="https://peergos.org/posts/security-audit">https://peergos.org/posts/security-audit</a></p></li>
<li><p><a class="reference external" href="https://cure53.de/pentest-report_peergos.pdf">https://cure53.de/pentest-report_peergos.pdf</a></p></li>
<li><p><a class="reference external" href="https://github.com/Peergos/Peergos/tree/master/audits">https://github.com/Peergos/Peergos/tree/master/audits</a></p></li>
</ul>
</section>
<section id="radically-open-security-b-v-amsterdam">
<h2><span class="section-number">7.3. </span>2024 — Radically Open Security B.V., Amsterdam<a class="headerlink" href="#radically-open-security-b-v-amsterdam" title="Link to this heading"></a></h2>
<ul class="simple">
<li><p><strong>Firm:</strong> Radically Open Security B.V.</p></li>
<li><p><strong>Location:</strong> Amsterdam, Netherlands</p></li>
<li><p><strong>When:</strong> SeptemberNovember 2024</p></li>
<li><p><strong>Scope:</strong> crystal-box pentest plus code audit of the
Peergos <strong>web UI</strong></p></li>
<li><p><strong>Funding context:</strong> the 2024 audit post states support
from <strong>NLnet</strong> (Netherlands) and refers to European Union
Horizon 2020 <strong>NGI-POINTER</strong>, grant <strong>871528</strong>.</p></li>
<li><p><strong>Outcome:</strong> <strong>0</strong> findings rated extreme, high, or
elevated; <strong>2</strong> moderate; <strong>6</strong> low. Peergos states that
all were fixed. There was <strong>no data exposure</strong> and <strong>no
integrity compromise</strong>. The issues were described as
mostly UI crashes.</p></li>
</ul>
<p>A crystal-box (clear-box) engagement means the testers had
source. A web-UI scope is narrower than the 2019
crypto/design review: it is evidence about the interface
that humans actually click, which is where many “encrypted
backend” products fail in practice. Zero high-severity
findings, no data exposure, no integrity compromise, and a
public report are the facts. They are good facts. They are
still not a customers Type II.</p>
<p>Primary sources (public):</p>
<ul class="simple">
<li><p><a class="reference external" href="https://peergos.org/posts/security-audit-2024">https://peergos.org/posts/security-audit-2024</a></p></li>
<li><p><a class="reference external" href="https://github.com/Peergos/Peergos/tree/master/audits">https://github.com/Peergos/Peergos/tree/master/audits</a></p></li>
</ul>
</section>
<section id="how-to-present-these-reports-to-an-auditor">
<h2><span class="section-number">7.4. </span>How to present these reports to an auditor<a class="headerlink" href="#how-to-present-these-reports-to-an-auditor" title="Link to this heading"></a></h2>
<p>Correct:</p>
<blockquote>
<div><p>“Our at-rest layer is Peergos. Peergos was independently
evaluated in Berlin in 2019 (crypto and design) and in
Amsterdam in 2024 (web UI, crystal box). Both reports are
public. We attach them as <strong>component security
evaluations</strong>. They are not our SOC 2, not our ISO 27001,
and not a HIPAA certification. Our own controls, our own
period of examination, and our own auditor are separate.”</p>
</div></blockquote>
<p>Incorrect:</p>
<blockquote>
<div><p>“We are HIPAA certified because Peergos was audited in
Europe.”</p>
<p>“Peergos is ISO 27001.”</p>
<p>“The EU certified this filesystem.”</p>
</div></blockquote>
<p>EU funding is not a certification. NGI-POINTER grant 871528
is a research-and-innovation funding fact. It is worth
listing under “provenance.” It is not a registrars mark.</p>
</section>
<section id="hosted-peergos-versus-self-hosted-datacubes">
<h2><span class="section-number">7.5. </span>Hosted Peergos versus self-hosted DataCubes<a class="headerlink" href="#hosted-peergos-versus-self-hosted-datacubes" title="Link to this heading"></a></h2>
<p>Peergoss hosted privacy notice has stated that peergos.net
uses servers in <strong>Germany</strong>. A <strong>self-hosted</strong> organizational
DataCube is a <strong>different processing location</strong>. The
customers Record of Processing, BAA pack, and ISO scope
must name <em>that</em> location — the customers ns1, region, or
chosen host — not peergos.nets Germany, unless the
customer actually uses peergos.net.</p>
<p>The evaluations still apply to the <strong>protocol and
implementation</strong>. Location of processing is an
organizational fact on top.</p>
</section>
<section id="what-designed-under-funding-from-cure53-ros-is-not">
<h2><span class="section-number">7.6. </span>What “designed under funding from Cure53 / ROS” is not<a class="headerlink" href="#what-designed-under-funding-from-cure53-ros-is-not" title="Link to this heading"></a></h2>
<p>The 2019 Cure53 work and the 2024 ROS work are <strong>evaluations</strong>
of a system that was designed by the Peergos authors. They
are not a claim that Cure53 or Radically Open Security
designed Peergos. The accurate statement is: the storage and
replication system was <strong>independently audited twice in
Europe</strong>, by Cure53 in Berlin (2019) and by Radically Open
Security in Amsterdam (2024), with public reports, and the
2019 work included a cryptographic and design review of the
architecture that Verae DataCubes rely on for data at rest.</p>
</section>
</section>
</div>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="verae-page-footer">
<strong>Verae Inc</strong>
&middot; <a href="https://www.verae.com">https://www.verae.com</a>
&middot; Book a call at <a href="https://www.verae.com">verae.com</a>
&middot; <a href="https://app.verae.com">app.verae.com</a>
</div>
<div class="footer">
&#169;2026, Verae Inc.
</div>
</body>
</html>