Rewrite audit-ready briefing: software is not a certificate.
Some checks are pending
ci / markdown (push) Waiting to run

Open with an executive summary that HIPAA, SOC 2, and ISO 27001
are organizational programs. Verae DataCubes supply store,
communicate, timestamp, verify, and audit tools for the technical
portion only. Chapters cover transit (HPKE, visible routing), rest
(IPFS/Peergos hash-verified restore), receipts, EU Peergos
evaluations (Cure53 2019, ROS 2024), cross-blockchain timestamping,
and write-once Iceberg archive. PDF is branded with the Verae logo
top-left and Verae Inc contact in the footer; last chapters are
sourced bios for Garfinkel (FINRA CRD 5052743), Haber, and Lambert.
This commit is contained in:
George Lambert 2026-09-16 00:55:21 -04:00
parent da60402e88
commit 4fcbb9ac95
53 changed files with 6323 additions and 814 deletions

View file

@ -1,61 +1,40 @@
Making yourself audit-ready with Verae DataCubes
================================================
How to **prepare an organization** for HIPAA-aligned, SOC 2, or ISO 27001
work using Verae DataCubes on **Peergos** (encrypted cryptree + hashed
IPFS) and HPKE on an **untrusted NATS** broker.
.. only:: html
**This document is not a HIPAA, SOC 2, or ISO certificate.**
Peergoss public pentests are **not** your Type II or ISO registrar
certificate. They are **component security evaluations** you can attach.
.. image:: _static/VeraeFullLogo.png
:width: 280px
:alt: Verae
:class: logo
This volume is a technical briefing. It is **not** a certificate.
The table of contents below is the document map. In the PDF edition,
each chapter starts on a new page and the contents list includes
**section titles with page numbers**. In HTML, each chapter is its own
page with the Verae wordmark in the sidebar and Verae Inc contact
information in the footer.
.. toctree::
:maxdepth: 2
:numbered:
:caption: Contents
verification
executive
what-verae-provides
datacube-server
data-in-transit
data-at-rest
timestamped-receipts
peergos-eu-evaluations
global-timestamping
iceberg-archive
architecture
baa-dpa
checklist
howto
What we verified about Peergos (EU)
-----------------------------------
See the full sourced table in :doc:`verification`.
* Encrypted client-side filesystem (cryptree); keys not on the storage
server — **yes** (Peergos book + Cure53 design review).
* IPFS blocks content-addressed; Peergos verifies hashes — **yes**.
* Independent **EU** security audits, reports published — **yes, two:**
Cure53 Berlin (2019); Radically Open Security Amsterdam (2024).
* “Peergos is HIPAA/SOC 2/ISO certified” — **no.** Those audits are
pentest/code/design reviews, not management-system certificates.
Peergos **was designed as a trust-minimized encrypted filesystem**,
**evaluated in Europe** by two specialist firms, with **public reports**.
That supports the **at-rest / backup** story. It does **not** finish
*your* audit.
.. only:: html
Live technical surfaces:
* https://pfc.georgelambert.org/health
* https://pfc.georgelambert.org/v1/npe/keys
* https://docs.pfc.georgelambert.org/controls.html
* https://git.georgelambert.org/marchon/peergos-making-yourself-audit-ready-with-verae-datacubes
Companion system docs (HTML): https://docs.pfc.georgelambert.org/
.. only:: latex
Companion PDFs in the **same directory** as this file (relative PDF
links, not Markdown):
.. raw:: latex
\begin{itemize}
\item \href{peergos-for-compliance.pdf}{peergos-for-compliance.pdf}
\item \href{nats-service-endpoints.pdf}{nats-service-endpoints.pdf}
\item \href{secure-messaging.pdf}{secure-messaging.pdf}
\end{itemize}
bio-james-garfinkel
bio-stuart-haber
bio-george-lambert
contact