10. Architecture for an audit interview¶
+9. Architecture for an audit interview¶
10.1. The picture¶
+9.1. The picture¶
Endpoint (private keys stay here / HSM)
| HPKE content (point-to-point)
| routing: destination + subject in the clear
@@ -142,7 +141,7 @@
10.2. Walkthrough, in the order an examiner usually asks¶
+9.2. Walkthrough, in the order an examiner usually asks¶
Where are the keys? On the endpoint or in the customer’s HSM. Not on the storage host. Not in the public-key directory (that directory holds public keys only). Not in @@ -171,7 +170,7 @@ k-of-n officers. The author of a change is not an officer on that change. Log-before-reveal.
10.3. Identity planes¶
+9.3. Identity planes¶
There are two login planes, and they must not be collapsed in an interview:
-
@@ -185,7 +184,7 @@ cubes.
the master key.” It is not.
10.4. NATS remains untrusted¶
+9.4. NATS remains untrusted¶
The reference message fabric is NATS. It is an honest-but-curious broker. Destinations in the clear are passthrough, not a bug. Bodies are ciphertext, or the @@ -195,7 +194,7 @@ identifiers, not payloads.
is not the same socket the internal services use.10.5. What to hand the examiner¶
+9.5. What to hand the examiner¶
this document (HTML or PDF);
the two public Peergos reports, labeled as component diff --git a/build/html/baa-dpa.html b/build/html/baa-dpa.html index 885e3a3..653627d 100644 --- a/build/html/baa-dpa.html +++ b/build/html/baa-dpa.html @@ -5,19 +5,19 @@ -
11. BAAs, DPAs, and ciphertext without host keys — Making yourself audit-ready with Verae DataCubes +10. BAAs, DPAs, and ciphertext without host keys — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,39 +61,38 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys
-
-
- 11.1. The technical fact -
- 11.2. HIPAA — Business Associate -
- 11.3. GDPR — processor versus technical measure -
- 11.4. NATS operators -
- 11.5. Verae as timestamping service -
- 11.6. Component assurance versus the organization’s report +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -114,11 +113,11 @@Related Topics
- Documentation overview
-
-
- Previous: 10. Architecture for an audit interview -
- Next: 12. Audit-ready checklist +
- Previous: 9. Architecture for an audit interview +
- Next: 11. Audit-ready checklist
- 11. BAAs, DPAs, and ciphertext without host keys¶
+10. BAAs, DPAs, and ciphertext without host keys¶
This chapter is guidance for an evidence pack. It is not legal advice. Counsel has to sign the actual determination.
- 11.1. The technical fact¶
+10.1. The technical fact¶
Data at rest lives in the encrypted Peergos cryptree. Restore uses distributed, hash-verified, encrypted IPFS blocks. Hosts and backup media see opaque blobs (and @@ -131,7 +130,7 @@ Associate and GDPR-processor conversation. It does not automatically delete the need for contracts.
- 11.2. HIPAA — Business Associate¶
+10.2. HIPAA — Business Associate¶
A Business Associate is a person who creates, receives, maintains, or transmits ePHI for a covered entity.
A technical argument the organization can document:
@@ -161,7 +160,7 @@ Iceberg credentials.- 11.3. GDPR — processor versus technical measure¶
+10.3. GDPR — processor versus technical measure¶
Encrypted data can still be personal data if it is reasonably attributable (usernames, IPs, invoice identity). GDPR Article 32 lists encryption as a security measure, not @@ -177,7 +176,7 @@ usernames, logs, or billing. Ciphertext-only storage eliminate the DPA.
- 11.4. NATS operators¶
+10.4. NATS operators¶
NATS is an untrusted broker. Content is HPKE. Destinations and subjects are in the clear. A NATS operator cannot read bodies without endpoint private keys. They can see @@ -187,7 +186,7 @@ DPA or BAA is needed depends on whether routing metadata is personal data in the relevant jurisdiction.
- 11.5. Verae as timestamping service¶
+10.5. Verae as timestamping service¶
If Verae receives only fingerprints, Verae’s role for content is not “stores the records.” Verae’s role is “registers hashes and issues receipts.” That is a narrower @@ -197,7 +196,7 @@ name, billing, operator emails), requires a DPA or a BAA. Do not let a sales sentence skip that memo.
- 11.6. Component assurance versus the organization’s report¶
+10.6. Component assurance versus the organization’s report¶
Attaching Cure53 2019 and ROS 2024 is vendor / component assurance. It is appropriate. It is not the organization’s SOC 2, ISO 27001, or HIPAA program. Those diff --git a/build/html/bio-george-lambert.html b/build/html/bio-george-lambert.html index 6f30dd0..f1e03f7 100644 --- a/build/html/bio-george-lambert.html +++ b/build/html/bio-george-lambert.html @@ -5,19 +5,19 @@ -
16. George Lambert — Making yourself audit-ready with Verae DataCubes +15. George Lambert — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,37 +61,36 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert
-
-
- 16.1. Role -
- 16.2. Internet technical architect, from 1994 -
- 16.3. New Hampshire public office -
- 16.4. Why this biography is in the briefing +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert -
- 17. Verae Inc — contact +
- 16. Verae Inc — contact
@@ -112,9 +111,9 @@Related Topics
- Documentation overview
-
-
- Previous: 15. Stuart Haber -
- Next: 17. Verae Inc — contact +
- Previous: 14. Stuart Haber +
- Next: 16. Verae Inc — contact
- 16. George Lambert¶
+15. George Lambert¶
- 16.1. Role¶
+15.1. Role¶
George Lambert is an Internet technical architect and a New Hampshire public official. Public candidate listings (BallotReady) identify him as CTO / Chief Architect, Verae @@ -125,7 +124,7 @@ public-key directory, organizational timestamping link, and write-once archive that an organization actually runs.
- 16.2. Internet technical architect, from 1994¶
+15.2. Internet technical architect, from 1994¶
Lambert’s public account of his engineering work begins in the earliest days of the commercial Internet, when shipping an application that could speak TCP/IP was still a @@ -156,7 +155,7 @@ systems, and later as founder of PodKey Solutions (2004–2010) and as an interim/contract CTO.
- 16.3. New Hampshire public office¶
+15.3. New Hampshire public office¶
Lambert is a Republican from Litchfield, New Hampshire, born 4 September 1968 in Sanford, Maine (Wikipedia; Vote Smart).
@@ -183,7 +182,7 @@ Borland fact as the credential for knowing what scalable architecture looks like.- 16.4. Why this biography is in the briefing¶
+15.4. Why this biography is in the briefing¶
The DataCube Server Solution is not only a timestamping API. It is a running system: keys, brokers, cryptree, replicas, admin-history, Iceberg export. Lambert is the diff --git a/build/html/bio-james-garfinkel.html b/build/html/bio-james-garfinkel.html index 5d8f7ba..fa30495 100644 --- a/build/html/bio-james-garfinkel.html +++ b/build/html/bio-james-garfinkel.html @@ -5,19 +5,19 @@ -
14. James H. Garfinkel — Making yourself audit-ready with Verae DataCubes +13. James H. Garfinkel — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,38 +61,37 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel
-
-
- 14.1. Name and sources -
- 14.2. Role at Verae -
- 14.3. FINRA BrokerCheck (CRD 5052743) -
- 14.4. Education (public professional listings) -
- 14.5. Why this biography is in the briefing +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -113,9 +112,9 @@Related Topics
- Documentation overview
-
-
- Previous: 13. How to use this briefing -
- Next: 15. Stuart Haber +
- Previous: 12. How to use this briefing +
- Next: 14. Stuart Haber
- 14. James H. Garfinkel¶
+13. James H. Garfinkel¶
- 14.1. Name and sources¶
+13.1. Name and sources¶
This chapter summarizes James H. Garfinkel (the spelling on the FINRA BrokerCheck individual report; also styled Garfinkle in some informal references). Two public sources were used, as @@ -133,7 +132,7 @@ fabricated “about the CEO” page.
- 14.2. Role at Verae¶
+13.2. Role at Verae¶
Public professional listings (including a long-standing Facebook work listing) identify Garfinkel as CEO of Verae LLC, from January 2020, based in New York, New York. @@ -150,7 +149,7 @@ timestamping, aimed at compliance and examinations rather than at operating a public chain.
- 14.3. FINRA BrokerCheck (CRD 5052743)¶
+13.3. FINRA BrokerCheck (CRD 5052743)¶
The following facts are from the public BrokerCheck report. They are registration history, not a Verae claim and not an endorsement by FINRA.
@@ -184,7 +183,7 @@ from November 2009) and MPWM Advisory Solutions LLC registration status changes.- 14.4. Education (public professional listings)¶
+13.4. Education (public professional listings)¶
Public professional listings state:
Hamilton College, B.A. Economics, class of 1980
@@ -198,7 +197,7 @@ who searches the name is not surprised. They are not used as
primary evidence of Verae corporate structure.
- 14.5. Why this biography is in the briefing¶
+13.5. Why this biography is in the briefing¶
A compliance briefing is not a pitch deck. Garfinkel’s biography is here because the user of this system is entitled to know who is on the commercial and regulatory-facing side diff --git a/build/html/bio-stuart-haber.html b/build/html/bio-stuart-haber.html index 9591ad9..2efbb25 100644 --- a/build/html/bio-stuart-haber.html +++ b/build/html/bio-stuart-haber.html @@ -5,19 +5,19 @@ -
15. Stuart Haber — Making yourself audit-ready with Verae DataCubes +14. Stuart Haber — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,38 +61,37 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber
-
-
- 15.1. Role at Verae -
- 15.2. The scientific work -
- 15.3. Surety, 1994: first commercial blockchain -
- 15.4. Other cryptographic publications -
- 15.5. Why this biography is in the briefing +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -113,9 +112,9 @@Related Topics
- Documentation overview
-
-
- Previous: 14. James H. Garfinkel -
- Next: 16. George Lambert +
- Previous: 13. James H. Garfinkel +
- Next: 15. George Lambert
- 15. Stuart Haber¶
+14. Stuart Haber¶
- 15.1. Role at Verae¶
+14.1. Role at Verae¶
Stuart Haber is a co-founder of Verae. The company’s public site introduces him as one of the creators of blockchain and as the inventor, in 1991, of cryptographic @@ -136,7 +135,7 @@ remaining in the customer’s storage and only a fingerprint being sealed.
- 15.2. The scientific work¶
+14.2. The scientific work¶
Haber is a cryptographer. He worked at Bellcore (Bell Communications Research) in Morristown, New Jersey, in the late 1980s and 1990s, in the research culture descended from @@ -173,7 +172,7 @@ data structure itself. That is a historical statement, not a claim that Verae is Bitcoin.
- 15.3. Surety, 1994: first commercial blockchain¶
+14.3. Surety, 1994: first commercial blockchain¶
Haber and Stornetta took the research into production as Surety. Surety hashed customer documents, linked those hashes in a chain of certificates, and published a weekly @@ -187,7 +186,7 @@ witnessed record, without revealing the documents — is the same idea Verae productizes for enterprise compliance.
- 15.4. Other cryptographic publications¶
+14.4. Other cryptographic publications¶
Haber’s research record is broader than timestamping. It includes work on minimum-knowledge interactive proofs, symmetric public-key encryption, and secure multi-party @@ -198,7 +197,7 @@ three Bitcoin-cited papers and the 1991 Journal of Cryptology article, then the ACM CCS 1997 paper.
- 15.5. Why this biography is in the briefing¶
+14.5. Why this biography is in the briefing¶
Timestamping in this document is not a metaphor. It is a specific scientific object — hash, time, sequence, privacy of the document from the notary — that Haber defined in diff --git a/build/html/checklist.html b/build/html/checklist.html index 676331e..326bbac 100644 --- a/build/html/checklist.html +++ b/build/html/checklist.html @@ -5,19 +5,19 @@ -
12. Audit-ready checklist — Making yourself audit-ready with Verae DataCubes +11. Audit-ready checklist — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,41 +61,40 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist
-
-
- 12.1. A. Scope and honesty -
- 12.2. B. Data in transit -
- 12.3. C. Data at rest -
- 12.4. D. Timestamping -
- 12.5. E. Write-once archive -
- 12.6. F. Access and change -
- 12.7. G. Contracts (counsel) -
- 12.8. H. Independent examination of this organization +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -116,13 +115,13 @@Related Topics
- Documentation overview
-
-
- Previous: 11. BAAs, DPAs, and ciphertext without host keys -
- Next: 13. How to use this briefing +
- Previous: 10. BAAs, DPAs, and ciphertext without host keys +
- Next: 12. How to use this briefing
@@ -107,7 +106,7 @@- 12. Audit-ready checklist¶
+11. Audit-ready checklist¶
Use this as a working list. Check an item only when evidence exists (screenshot, log export, signed policy, ticket, receipt). This list is not a certificate. Software having been installed does not tick these boxes.
- 12.1. A. Scope and honesty¶
+11.1. A. Scope and honesty¶
Named legal entity and systems in scope (console, Drive, message fabric, IPFS, timestamping link, Iceberg archive)
@@ -137,7 +136,7 @@ security evaluation
- 12.2. B. Data in transit¶
+11.2. B. Data in transit¶
Production algorithm is HPKE (or documented successor), not a lab construction
@@ -150,7 +149,7 @@ mode 0600 or HSM
- 12.3. C. Data at rest¶
+11.3. C. Data at rest¶
Customer holds Peergos / Drive keys; not on storage host
Peergos hash verification on write and on read, evidenced
@@ -160,7 +159,7 @@ ciphertext without a plaintext tape
- 12.4. D. Timestamping¶
+11.4. D. Timestamping¶
First-registration rule documented and tested (second submit returns original receipt)
@@ -173,7 +172,7 @@ the data map
- 12.5. E. Write-once archive¶
+11.5. E. Write-once archive¶
Iceberg (or equivalent) export job exists and has a dated last-run
@@ -185,7 +184,7 @@ engineering folklore
- 12.6. F. Access and change¶
+11.6. F. Access and change¶
Console requires authentication (TOTP or equivalent); Drive login is a separate plane
@@ -197,7 +196,7 @@ prev + new + diff
- 12.7. G. Contracts (counsel)¶
+11.7. G. Contracts (counsel)¶
Written BA / not-a-BA determination for disk, VM, backup, IPFS, Iceberg
@@ -208,7 +207,7 @@ IPFS, Iceberg
- 12.8. H. Independent examination of this organization¶
+11.8. H. Independent examination of this organization¶
SOC 2 Type I/II engagement, or ISO 27001 registrar, or HIPAA risk analysis plus policies — the program diff --git a/build/html/contact.html b/build/html/contact.html index f31ab1d..6834fa3 100644 --- a/build/html/contact.html +++ b/build/html/contact.html @@ -5,18 +5,18 @@ -
17. Verae Inc — contact — Making yourself audit-ready with Verae DataCubes +16. Verae Inc — contact — Making yourself audit-ready with Verae DataCubes - + - + @@ -60,24 +60,23 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact
-
-
- 17.1. Closing reminder +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
Related Topics
- Documentation overview
-
-
- Previous: 16. George Lambert +
- Previous: 15. George Lambert
- 17. Verae Inc — contact¶
+16. Verae Inc — contact¶
This page is the contact block that also appears in the footer of every page of the PDF edition and at the bottom of every HTML chapter.
@@ -129,7 +128,7 @@ here. If a procurement file requires them, take them from a current Verae engagement letter, W-9, or the form on verae.com, not from this paragraph.- 17.1. Closing reminder¶
+16.1. Closing reminder¶
Software alone does not make an organization HIPAA certified, SOC 2 attested, or ISO 27001 certified.
The Verae DataCube Solution gives you tools to store, diff --git a/build/html/data-at-rest.html b/build/html/data-at-rest.html index 8192a1a..f798296 100644 --- a/build/html/data-at-rest.html +++ b/build/html/data-at-rest.html @@ -5,19 +5,19 @@ -
5. Encryption at rest — IPFS blocks and Peergos — Making yourself audit-ready with Verae DataCubes +4. Encryption at rest — IPFS blocks and Peergos — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,40 +61,39 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos
-
-
- 5.1. The problem -
- 5.2. Content-addressed blocks -
- 5.3. Peergos on top of IPFS -
- 5.4. Tamper-evident restore -
- 5.5. Append-only at the cube layer -
- 5.6. What a disk operator sees -
- 5.7. What this does, and does not, satisfy +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -115,9 +114,9 @@Related Topics
- Documentation overview
-
-
- Previous: 4. Secure communications — data in transit -
- Next: 6. Global timestamped receipts +
- Previous: 3. Secure communications — data in transit +
- Next: 5. Global timestamped receipts
- 5. Encryption at rest — IPFS blocks and Peergos¶
+4. Encryption at rest — IPFS blocks and Peergos¶
- 5.1. The problem¶
+4.1. The problem¶
Bytes that are no longer moving still have to live somewhere: a disk, a replica, a backup, a cold archive. The people who operate those surfaces — hosting providers, backup operators, someone @@ -132,7 +131,7 @@ even if it keeps confidentiality.
verifying hashes on the way in and the way out.- 5.2. Content-addressed blocks¶
+4.2. Content-addressed blocks¶
IPFS names a block by a cryptographic hash of its contents (a Content Identifier, or CID). Two properties follow immediately:
-
@@ -148,7 +147,7 @@ prevent a hostile replica from refusing to serve a block
serving a substitute and hoping nobody notices (integrity).
- 5.3. Peergos on top of IPFS¶
+4.3. Peergos on top of IPFS¶
Peergos is not “IPFS with a folder UI.” It is an encrypted filesystem — a cryptree — whose nodes and file chunks are stored as IPFS blocks. The properties that matter for an @@ -177,7 +176,7 @@ without placing the chunk key on the server.
- 5.4. Tamper-evident restore¶
+4.4. Tamper-evident restore¶
“Backup” in this architecture does not mean a second plaintext copy in a different building. It means:
-
@@ -194,7 +193,7 @@ plaintext it had. Helpfulness of that kind is how silent
corruption and silent substitution enter an evidence set.
- 5.5. Append-only at the cube layer¶
+4.5. Append-only at the cube layer¶
Peergos itself uses signed updates and immutable blocks. The Verae DataCube adds an application-level chain: a JSONL history in which each record hashes the previous record. Dual @@ -212,7 +211,7 @@ of writes is append-only at the application layer.
Both are needed. Neither is a SOC 2 report.
- 5.6. What a disk operator sees¶
+4.6. What a disk operator sees¶
If keys never leave the client or the customer’s HSM, a disk operator, a VM snapshot operator, and an offsite replica operator see opaque hashed ciphertext. They do not see PHI, they do @@ -224,7 +223,7 @@ addresses, billing identity, and support logs can still be personal data. Chapter 11 takes that up.
- 5.7. What this does, and does not, satisfy¶
+4.7. What this does, and does not, satisfy¶
For HIPAA encryption of ePHI at rest, for SOC 2 CC6 encryption of stored data, and for ISO 27001 Annex A cryptography and storage, this is the technical control: ciphertext on diff --git a/build/html/data-in-transit.html b/build/html/data-in-transit.html index 71f9a27..289e732 100644 --- a/build/html/data-in-transit.html +++ b/build/html/data-in-transit.html @@ -5,19 +5,19 @@ -
4. Secure communications — data in transit — Making yourself audit-ready with Verae DataCubes +3. Secure communications — data in transit — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,39 +61,38 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit
-
-
- 4.1. The problem -
- 4.2. Point-to-point encryption -
- 4.3. Visible routing -
- 4.4. Error handling without leaking content -
- 4.5. The public-key directory -
- 4.6. What this does, and does not, satisfy +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -114,9 +113,9 @@Related Topics
- 4. Secure communications — data in transit¶
+3. Secure communications — data in transit¶
- 4.1. The problem¶
+3.1. The problem¶
A message that leaves one machine and arrives at another crosses infrastructure the endpoints do not own: routers, load balancers, message brokers, TLS terminators, packet-capture appliances, and @@ -129,7 +128,7 @@ they see, and what will they be able to do with it.”
that routing must be visible.- 4.2. Point-to-point encryption¶
+3.2. Point-to-point encryption¶
“Best in class” here is not a slogan; it names a concrete choice. Production content is sealed with HPKE (Hybrid Public Key Encryption, RFC 9180), in the HPKE-Base mode, using a suite such as @@ -152,7 +151,7 @@ configurations reject it.
- 4.3. Visible routing¶
+3.3. Visible routing¶
A network that cannot see a destination cannot deliver a message. The DataCube Server Solution therefore does not claim anonymous, metadata-free messaging. The following remain visible @@ -171,7 +170,7 @@ broker forwards what it is given; it is not trusted with content, and it is not trusted not to log destinations.
- 4.4. Error handling without leaking content¶
+3.4. Error handling without leaking content¶
Failures have to be reported. A bounce that includes the original body would undo the encryption. The design therefore returns error metadata: an error code, a lookup identifier, a @@ -183,7 +182,7 @@ without broadcasting the payload to operators who should never see it.
- 4.5. The public-key directory¶
+3.5. The public-key directory¶
Point-to-point encryption is only as good as the lookup of public keys. The server solution publishes a directory of public keys so that availability of those keys is visible to all E2E services. @@ -194,7 +193,7 @@ never returned by the public listing API.
never be given a private key.- 4.6. What this does, and does not, satisfy¶
+3.6. What this does, and does not, satisfy¶
For HIPAA Security Rule addressable encryption of ePHI in transit, for SOC 2 CC6 cryptographic transmission, and for ISO 27001 Annex A transmission security, this design is the diff --git a/build/html/datacube-server.html b/build/html/datacube-server.html index cf0d9b5..27ad0af 100644 --- a/build/html/datacube-server.html +++ b/build/html/datacube-server.html @@ -5,19 +5,19 @@ -
3. The Verae DataCube Server Solution — Making yourself audit-ready with Verae DataCubes +2. The Verae DataCube Server Solution — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,38 +61,37 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution
-
-
- 3.1. Purpose -
- 3.2. The DataCube as a container -
- 3.3. Two information states, one operational picture -
- 3.4. What “server” means in practice -
- 3.5. What the server solution is not +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -113,9 +112,9 @@Related Topics
- 3. The Verae DataCube Server Solution¶
+2. The Verae DataCube Server Solution¶
- 3.1. Purpose¶
+2.1. Purpose¶
A Verae DataCube Server Solution is the on-premises or customer-hosted assembly that gives an organization a place to put sensitive digital objects, a way to move them, a way to prove when @@ -129,7 +128,7 @@ not a single binary, and it is not a cloud folder with a padlock icon.
- 3.2. The DataCube as a container¶
+2.2. The DataCube as a container¶
A DataCube is a customer-controlled container for digital objects and for the metadata that makes those objects examinable. Typical contents include:
@@ -150,7 +149,7 @@ records stay in storage the customer controls; Verae seals a that split operational rather than rhetorical.- 3.3. Two information states, one operational picture¶
+2.3. Two information states, one operational picture¶
Classical security training divides information into data in transit and data at rest. The DataCube Server Solution is built around that division.
@@ -174,7 +173,7 @@ receipts (Chapter 6) and the cross-blockchain timestamping architecture (Chapter 8) address that.- 3.4. What “server” means in practice¶
+2.4. What “server” means in practice¶
In a typical deployment the organization runs, or links:
a Peergos instance (or equivalent cryptree client) that @@ -200,7 +199,7 @@ serves a wrong block (detected by hash), a timestamping link that is down, an archive job that did not run.
- 3.5. What the server solution is not¶
+2.5. What the server solution is not¶
It is not a substitute for workforce training. It is not a substitute for a Business Associate Agreement analysis. It is not a substitute for access reviews. It is not, by itself, “the HIPAA diff --git a/build/html/genindex.html b/build/html/genindex.html index 74a85f5..7a7a1ed 100644 --- a/build/html/genindex.html +++ b/build/html/genindex.html @@ -8,7 +8,7 @@ - + @@ -58,23 +58,22 @@
Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
diff --git a/build/html/global-timestamping.html b/build/html/global-timestamping.html index 5799bfa..afde23b 100644 --- a/build/html/global-timestamping.html +++ b/build/html/global-timestamping.html @@ -5,19 +5,19 @@ -8. Verae global timestamping — a cross-blockchain receipt — Making yourself audit-ready with Verae DataCubes +7. Verae global timestamping — a cross-blockchain receipt — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,39 +61,38 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt
-
-
- 8.1. Lineage -
- 8.2. What “cross-blockchain” means here -
- 8.3. Two deployment patterns -
- 8.4. The digital bundle -
- 8.5. Proof of existence versus proof of custody -
- 8.6. What this does, and does not, satisfy +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -114,9 +113,9 @@Related Topics
- Documentation overview
-
-
- Previous: 7. Peergos security evaluations in Europe -
- Next: 9. Write-once Iceberg archive +
- Previous: 6. Peergos security evaluations in Europe +
- Next: 8. Write-once Iceberg archive
- 8. Verae global timestamping — a cross-blockchain receipt¶
+7. Verae global timestamping — a cross-blockchain receipt¶
- 8.1. Lineage¶
+7.1. Lineage¶
The scientific problem Verae is productizing is not new. In 1991, Stuart Haber and W. Scott Stornetta published “How to Time-Stamp a Digital Document” in the Journal of @@ -142,7 +141,7 @@ blockchain accessible to enterprises without having to deal with the complexity of blockchain.”
- 8.2. What “cross-blockchain” means here¶
+7.2. What “cross-blockchain” means here¶
A single private log, held only by the vendor, is a vendor assurance letter with extra steps. A single public chain may be operationally and commercially the wrong place to put an @@ -168,7 +167,7 @@ receipt. That is the scientific claim, inherited from Haber–Stornetta.
- 8.3. Two deployment patterns¶
+7.3. Two deployment patterns¶
Linked organizational server. The organization runs a timestamping node next to its DataCube server. That node is linked to the central Verae timestamping server. Local @@ -187,7 +186,7 @@ where the organizational metadata lives and in how much infrastructure the customer operates.
- 8.4. The digital bundle¶
+7.4. The digital bundle¶
The unit of production is a digital bundle:
the receipt (hash, time, sequence, verification path);
@@ -203,7 +202,7 @@ without being given a login to the production console and
without Verae ever having seen the object bytes.
- 8.5. Proof of existence versus proof of custody¶
+7.5. Proof of existence versus proof of custody¶
Timestamping answers: did these bits exist by this time?
The DataCube answers: does the organization still have them, encrypted, hash-checkable?
@@ -215,7 +214,7 @@ receipt is a pile of files with a clock on the filesystem that the administrator can set.- 8.6. What this does, and does not, satisfy¶
+7.6. What this does, and does not, satisfy¶
For SEC Rule 17a-4, FINRA books-and-records, and similar regimes that demand records in a non-rewriteable, non-erasable form with the ability to produce the diff --git a/build/html/howto.html b/build/html/howto.html index 23bf1d3..78f6815 100644 --- a/build/html/howto.html +++ b/build/html/howto.html @@ -5,19 +5,19 @@ -
13. How to use this briefing — Making yourself audit-ready with Verae DataCubes +12. How to use this briefing — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,31 +61,30 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -106,7 +105,7 @@Related Topics
- Documentation overview
-
-
- Previous: 12. Audit-ready checklist -
- Next: 14. James H. Garfinkel +
- Previous: 11. Audit-ready checklist +
- Next: 13. James H. Garfinkel
- 13. How to use this briefing¶
+12. How to use this briefing¶
Read the executive summary aloud in the first five minutes of any vendor, board, or auditor meeting that diff --git a/build/html/iceberg-archive.html b/build/html/iceberg-archive.html index 940e11c..de2c800 100644 --- a/build/html/iceberg-archive.html +++ b/build/html/iceberg-archive.html @@ -5,19 +5,19 @@ -
9. Write-once Iceberg archive — Making yourself audit-ready with Verae DataCubes +8. Write-once Iceberg archive — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,38 +61,37 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive
-
-
- 9.1. The deletion problem -
- 9.2. What “write-once Iceberg” means in this solution -
- 9.3. How cubes move into the archive -
- 9.4. Relation to classical WORM -
- 9.5. What this does, and does not, satisfy +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -113,9 +112,9 @@Related Topics
- 9. Write-once Iceberg archive¶
+8. Write-once Iceberg archive¶
- 9.1. The deletion problem¶
+8.1. The deletion problem¶
Encryption at rest stops a disk operator from reading. Hash verification stops a replica from substituting. Timestamped receipts stop a custodian from back-dating. @@ -131,7 +130,7 @@ that cannot be produced.
administrative power does not include delete.- 9.2. What “write-once Iceberg” means in this solution¶
+8.2. What “write-once Iceberg” means in this solution¶
DataCubes — the encrypted, hash-chained containers — are archived into an external, write-once file-storage solution built on the Iceberg table/file model (a @@ -159,7 +158,7 @@ require it — not because it is a convenient backup.
- 9.3. How cubes move into the archive¶
+8.3. How cubes move into the archive¶
A live DataCube is an operational object: it receives new writes, it is replicated as encrypted IPFS blocks, it is readable by holders of the right capabilities. On a schedule @@ -207,7 +206,7 @@ legally permitted at all.
retention schedule. Counsel and the records officer do that.- 9.4. Relation to classical WORM¶
+8.4. Relation to classical WORM¶
Broker-dealer Rule 17a-4 and similar texts speak of non-rewriteable, non-erasable media, originally meaning optical WORM, later allowing disk with object-lock semantics @@ -221,7 +220,7 @@ receipt even if they do not trust the vendor’s “WORM was on” screenshot.
- 9.5. What this does, and does not, satisfy¶
+8.5. What this does, and does not, satisfy¶
This is the technical portion of retention and production: committed cubes are not under a single delete key, they are hash-checkable, and they carry a time of diff --git a/build/html/index.html b/build/html/index.html index 8d7e0f4..12efc6e 100644 --- a/build/html/index.html +++ b/build/html/index.html @@ -9,14 +9,14 @@ - + - + @@ -60,30 +60,29 @@
Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -107,150 +106,166 @@Related Topics
Making yourself audit-ready with Verae DataCubes¶
-This volume is a technical briefing. It is not a certificate.
-The table of contents below is the document map. In the PDF edition, -each chapter starts on a new page and the contents list includes -section titles with page numbers. In HTML, each chapter is its own -page with the Verae wordmark in the sidebar and Verae Inc contact -information in the footer.
+Software alone does not make an organization HIPAA certified, SOC 2 +attested, or ISO 27001 certified.
+That sentence is the point of this document. It is also the sentence +that is most often skipped when a vendor, an integrator, or an internal +champion shows encryption, hashing, or a pentest PDF and treats the +conversation as finished. It is not finished. Encryption is a control. +A pentest is an evaluation of a component. A certificate, an attestation, +or a covered-entity determination is a statement about an organization +— its legal entity, its people, its written policies, its operating +procedures, its internal controls, the evidence those controls produce, +and the independent party that examined that evidence.
+The Verae DataCube Solution gives an organization tools to store, +communicate, timestamp, verify, and audit for compliance. +Those tools are real, they are specific, and they are described in the +chapters that follow. They are still only tools. To obtain HIPAA-aligned +status as a covered entity or business associate with a defensible +program, a SOC 2 Type I or Type II report, or an ISO 27001 certificate, +the organization must still:
+-
+
write and live by policies (what the organization says it will do);
+operate procedures (how staff actually do it, every day);
+design and test internal controls (the checks that catch failure);
+retain evidence (logs, tickets, screenshots, signed approvals, +restore tests, training records);
+engage an independent auditor, CPA firm, or ISO registrar, as the +chosen program requires.
+
Verae cannot issue those certificates. Verae cannot sit in the +organization’s chair during an OCR investigation, a SOC 2 fieldwork +week, or an ISO Stage 2 audit. What Verae can do — and what this +briefing is written to make precise — is provide the tools, the +background, and the software infrastructure that make it easier +to implement the technical portion of those programs.
Contents
-
-
- 1. Executive summary
-
-
- 1.1. What a Verae DataCube Server Solution does -
- 1.2. Data in transit -
- 1.3. Data at rest -
- 1.4. Global timestamped receipts -
- 1.5. Peergos, evaluated in Europe -
- 1.6. Verae global timestamping -
- 1.7. Write-once Iceberg archive -
- 1.8. What this briefing is, and is not +
- 1. What Verae provides — and what it does not -
- 2. What Verae provides — and what it does not
-
-
- 2.1. The boundary -
- 2.2. The tools -
- 2.3. What the organization must still do -
- 2.4. Why the distinction matters in an exam +
- 2. The Verae DataCube Server Solution -
- 3. The Verae DataCube Server Solution
-
-
- 3.1. Purpose -
- 3.2. The DataCube as a container -
- 3.3. Two information states, one operational picture -
- 3.4. What “server” means in practice -
- 3.5. What the server solution is not +
- 3. Secure communications — data in transit -
- 4. Secure communications — data in transit
-
-
- 4.1. The problem -
- 4.2. Point-to-point encryption -
- 4.3. Visible routing -
- 4.4. Error handling without leaking content -
- 4.5. The public-key directory -
- 4.6. What this does, and does not, satisfy +
- 4. Encryption at rest — IPFS blocks and Peergos -
- 5. Encryption at rest — IPFS blocks and Peergos
-
-
- 5.1. The problem -
- 5.2. Content-addressed blocks -
- 5.3. Peergos on top of IPFS -
- 5.4. Tamper-evident restore -
- 5.5. Append-only at the cube layer -
- 5.6. What a disk operator sees -
- 5.7. What this does, and does not, satisfy +
- 5. Global timestamped receipts -
- 6. Global timestamped receipts
-
-
- 6.1. Why hashes are not enough by themselves -
- 6.2. What a Verae receipt is -
- 6.3. What is registered, and what is not -
- 6.4. First registration wins -
- 6.5. Sequence -
- 6.6. Bundles -
- 6.7. What a receipt does not prove +
- 6. Peergos security evaluations in Europe -
- 7. Peergos security evaluations in Europe
-
-
- 7.1. What was evaluated -
- 7.2. 2019 — Cure53, Berlin, Germany -
- 7.3. 2024 — Radically Open Security B.V., Amsterdam -
- 7.4. How to present these reports to an auditor -
- 7.5. Hosted Peergos versus self-hosted DataCubes -
- 7.6. What “designed under funding from Cure53 / ROS” is not +
- 7. Verae global timestamping — a cross-blockchain receipt -
- 8. Verae global timestamping — a cross-blockchain receipt
-
-
- 8.1. Lineage -
- 8.2. What “cross-blockchain” means here -
- 8.3. Two deployment patterns -
- 8.4. The digital bundle -
- 8.5. Proof of existence versus proof of custody -
- 8.6. What this does, and does not, satisfy +
- 8. Write-once Iceberg archive -
- 9. Write-once Iceberg archive
-
-
- 9.1. The deletion problem -
- 9.2. What “write-once Iceberg” means in this solution -
- 9.3. How cubes move into the archive -
- 9.4. Relation to classical WORM -
- 9.5. What this does, and does not, satisfy +
- 9. Architecture for an audit interview -
- 10. Architecture for an audit interview
-
-
- 10.1. The picture -
- 10.2. Walkthrough, in the order an examiner usually asks -
- 10.3. Identity planes -
- 10.4. NATS remains untrusted -
- 10.5. What to hand the examiner +
- 10. BAAs, DPAs, and ciphertext without host keys -
- 11. BAAs, DPAs, and ciphertext without host keys
-
-
- 11.1. The technical fact -
- 11.2. HIPAA — Business Associate -
- 11.3. GDPR — processor versus technical measure -
- 11.4. NATS operators -
- 11.5. Verae as timestamping service -
- 11.6. Component assurance versus the organization’s report +
- 11. Audit-ready checklist -
- 12. Audit-ready checklist
-
-
- 12.1. A. Scope and honesty -
- 12.2. B. Data in transit -
- 12.3. C. Data at rest -
- 12.4. D. Timestamping -
- 12.5. E. Write-once archive -
- 12.6. F. Access and change -
- 12.7. G. Contracts (counsel) -
- 12.8. H. Independent examination of this organization +
- 12. How to use this briefing +
- 13. James H. Garfinkel -
- 13. How to use this briefing -
- 14. James H. Garfinkel
-
-
- 14.1. Name and sources -
- 14.2. Role at Verae -
- 14.3. FINRA BrokerCheck (CRD 5052743) -
- 14.4. Education (public professional listings) -
- 14.5. Why this biography is in the briefing +
- 14. Stuart Haber -
- 15. Stuart Haber
-
-
- 15.1. Role at Verae -
- 15.2. The scientific work -
- 15.3. Surety, 1994: first commercial blockchain -
- 15.4. Other cryptographic publications -
- 15.5. Why this biography is in the briefing +
- 15. George Lambert -
- 16. George Lambert - -
- 17. Verae Inc — contact
diff --git a/build/html/peergos-eu-evaluations.html b/build/html/peergos-eu-evaluations.html
index 487c8f9..8c8ef1c 100644
--- a/build/html/peergos-eu-evaluations.html
+++ b/build/html/peergos-eu-evaluations.html
@@ -5,19 +5,19 @@
-
7. Peergos security evaluations in Europe — Making yourself audit-ready with Verae DataCubes +6. Peergos security evaluations in Europe — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,39 +61,38 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe
-
-
- 7.1. What was evaluated -
- 7.2. 2019 — Cure53, Berlin, Germany -
- 7.3. 2024 — Radically Open Security B.V., Amsterdam -
- 7.4. How to present these reports to an auditor -
- 7.5. Hosted Peergos versus self-hosted DataCubes -
- 7.6. What “designed under funding from Cure53 / ROS” is not +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -114,9 +113,9 @@Related Topics
- 7. Peergos security evaluations in Europe¶
+6. Peergos security evaluations in Europe¶
- 7.1. What was evaluated¶
+6.1. What was evaluated¶
The offline storage and replication system used with Verae DataCubes is Peergos: an encrypted, peer-to-peer filesystem whose blocks live on IPFS. Peergos was designed as a @@ -139,7 +138,7 @@ is unusual and is worth attaching to a vendor-assurance file, labeled correctly.
- 7.2. 2019 — Cure53, Berlin, Germany¶
+6.2. 2019 — Cure53, Berlin, Germany¶
Firm: Cure53
Location: Berlin, Germany
@@ -167,7 +166,7 @@ did find were addressed.
- 7.3. 2024 — Radically Open Security B.V., Amsterdam¶
+6.3. 2024 — Radically Open Security B.V., Amsterdam¶
Firm: Radically Open Security B.V.
Location: Amsterdam, Netherlands
@@ -198,7 +197,7 @@ still not a customer’s Type II.
- 7.4. How to present these reports to an auditor¶
+6.4. How to present these reports to an auditor¶
Correct:
“Our at-rest layer is Peergos. Peergos was independently @@ -221,7 +220,7 @@ is a research-and-innovation funding fact. It is worth listing under “provenance.” It is not a registrar’s mark.
- 7.5. Hosted Peergos versus self-hosted DataCubes¶
+6.5. Hosted Peergos versus self-hosted DataCubes¶
Peergos’s hosted privacy notice has stated that peergos.net uses servers in Germany. A self-hosted organizational DataCube is a different processing location. The @@ -234,7 +233,7 @@ implementation. Location of processing is an organizational fact on top.
- 7.6. What “designed under funding from Cure53 / ROS” is not¶
+6.6. What “designed under funding from Cure53 / ROS” is not¶
The 2019 Cure53 work and the 2024 ROS work are evaluations of a system that was designed by the Peergos authors. They are not a claim that Cure53 or Radically Open Security diff --git a/build/html/peergos-making-yourself-audit-ready-with-verae-datacubes.pdf b/build/html/peergos-making-yourself-audit-ready-with-verae-datacubes.pdf index b5a5499..25b067e 100644 Binary files a/build/html/peergos-making-yourself-audit-ready-with-verae-datacubes.pdf and b/build/html/peergos-making-yourself-audit-ready-with-verae-datacubes.pdf differ diff --git a/build/html/search.html b/build/html/search.html index 3f6cc49..28696ad 100644 --- a/build/html/search.html +++ b/build/html/search.html @@ -8,7 +8,7 @@ - + @@ -56,23 +56,22 @@
Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
diff --git a/build/html/timestamped-receipts.html b/build/html/timestamped-receipts.html index 4a87db3..ea4d8ba 100644 --- a/build/html/timestamped-receipts.html +++ b/build/html/timestamped-receipts.html @@ -5,19 +5,19 @@ -6. Global timestamped receipts — Making yourself audit-ready with Verae DataCubes +5. Global timestamped receipts — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,40 +61,39 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts
-
-
- 6.1. Why hashes are not enough by themselves -
- 6.2. What a Verae receipt is -
- 6.3. What is registered, and what is not -
- 6.4. First registration wins -
- 6.5. Sequence -
- 6.6. Bundles -
- 6.7. What a receipt does not prove +
- 1. What Verae provides — and what it does not +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -115,9 +114,9 @@Related Topics
- 6. Global timestamped receipts¶
+5. Global timestamped receipts¶
- 6.1. Why hashes are not enough by themselves¶
+5.1. Why hashes are not enough by themselves¶
A cryptographic hash of a document proves that two copies are bit-for-bit the same, or that they are not. It does not prove when the document first existed. Anyone can hash a file @@ -132,7 +131,7 @@ the hash, that a later examiner can check without trusting the file’s custodian.
- 6.2. What a Verae receipt is¶
+5.2. What a Verae receipt is¶
A Verae global timestamped receipt is proof of:
the hash of a block of digital information;
@@ -149,7 +148,7 @@ from 1991, applied here as a product: time-stamp the data, not
the disk.
- 6.3. What is registered, and what is not¶
+5.3. What is registered, and what is not¶
Verae’s public description of sealing is that only a fingerprint leaves the customer’s systems. The object itself can remain in the customer’s DataCube. The central service @@ -164,7 +163,7 @@ For HIPAA, GDPR, and ordinary commercial secrecy, that is the desired shape.
- 6.4. First registration wins¶
+5.4. First registration wins¶
A hash registry that allowed a later write to overwrite the timestamp of an earlier write would be a forgery machine. The rule is: the first SHA-256 (and companion hash) and its @@ -174,7 +173,7 @@ which is exactly how a revision should be modeled. Revisions get their own receipts. They do not steal the original’s time.
- 6.5. Sequence¶
+5.5. Sequence¶
Time on a wall clock is a social convention and a NTP configuration. Sequence inside a registration service is a data-structure fact: this hash was committed after that hash, @@ -184,7 +183,7 @@ order even when two wall-clock stamps are close enough to argue about.
- 6.6. Bundles¶
+5.6. Bundles¶
A receipt does not have to travel as a bare timestamp. It can travel inside a digital bundle that also holds:
-
@@ -200,7 +199,7 @@ the metadata we claim goes with it, here is the verification
path.”
- 6.7. What a receipt does not prove¶
+5.7. What a receipt does not prove¶
A receipt does not prove that the person who registered the hash was authorized to do so. That is an access-control and identity problem.
diff --git a/build/html/what-verae-provides.html b/build/html/what-verae-provides.html index 53c3822..2c7969c 100644 --- a/build/html/what-verae-provides.html +++ b/build/html/what-verae-provides.html @@ -5,19 +5,19 @@ -2. What Verae provides — and what it does not — Making yourself audit-ready with Verae DataCubes +1. What Verae provides — and what it does not — Making yourself audit-ready with Verae DataCubes - + - - + + @@ -61,37 +61,36 @@Navigation
Contents
-
-
- 1. Executive summary -
- 2. What Verae provides — and what it does not
-
-
- 2.1. The boundary -
- 2.2. The tools -
- 2.3. What the organization must still do -
- 2.4. Why the distinction matters in an exam +
- 1. What Verae provides — and what it does not -
- 3. The Verae DataCube Server Solution -
- 4. Secure communications — data in transit -
- 5. Encryption at rest — IPFS blocks and Peergos -
- 6. Global timestamped receipts -
- 7. Peergos security evaluations in Europe -
- 8. Verae global timestamping — a cross-blockchain receipt -
- 9. Write-once Iceberg archive -
- 10. Architecture for an audit interview -
- 11. BAAs, DPAs, and ciphertext without host keys -
- 12. Audit-ready checklist -
- 13. How to use this briefing -
- 14. James H. Garfinkel -
- 15. Stuart Haber -
- 16. George Lambert -
- 17. Verae Inc — contact +
- 2. The Verae DataCube Server Solution +
- 3. Secure communications — data in transit +
- 4. Encryption at rest — IPFS blocks and Peergos +
- 5. Global timestamped receipts +
- 6. Peergos security evaluations in Europe +
- 7. Verae global timestamping — a cross-blockchain receipt +
- 8. Write-once Iceberg archive +
- 9. Architecture for an audit interview +
- 10. BAAs, DPAs, and ciphertext without host keys +
- 11. Audit-ready checklist +
- 12. How to use this briefing +
- 13. James H. Garfinkel +
- 14. Stuart Haber +
- 15. George Lambert +
- 16. Verae Inc — contact
@@ -112,9 +111,9 @@Related Topics
- Documentation overview
-
-
- Previous: 1. Executive summary -
- Next: 3. The Verae DataCube Server Solution +
- Previous: Making yourself audit-ready with Verae DataCubes +
- Next: 2. The Verae DataCube Server Solution
- 2. What Verae provides — and what it does not¶
+1. What Verae provides — and what it does not¶
- 2.1. The boundary¶
+1.1. The boundary¶
Verae sells and operates software infrastructure and a timestamping service. Customers use that infrastructure to store objects, to send messages, to register hashes, to verify receipts, @@ -140,7 +139,7 @@ an Information Security Management System (ISMS) over a named scope. Installing a DataCube does not create an ISMS.
- 2.2. The tools¶
+1.2. The tools¶
Within that boundary, the Verae DataCube Solution is built to make the technical work of those programs less painful. Concretely, it gives the organization the ability to:
@@ -170,7 +169,7 @@ without the log itself becoming a second copy of the sensitive payload.- 2.3. What the organization must still do¶
+1.3. What the organization must still do¶
Those five verbs — store, communicate, timestamp, verify, audit — are the technical portion. The rest of a certification or attestation program is organizational:
@@ -194,7 +193,7 @@ They will ask for evidence that the controls ran during the period, not that a vendor has a nice architecture diagram.- 2.4. Why the distinction matters in an exam¶
+1.4. Why the distinction matters in an exam¶
Examiners are trained to notice category errors. If a firm says “we are SOC 2 because our storage vendor was pentested in Berlin,” the next hour of the meeting is spent unwinding that claim. If a diff --git a/build/latex/peergos-making-yourself-audit-ready-with-verae-datacubes.pdf b/build/latex/peergos-making-yourself-audit-ready-with-verae-datacubes.pdf index b5a5499..25b067e 100644 Binary files a/build/latex/peergos-making-yourself-audit-ready-with-verae-datacubes.pdf and b/build/latex/peergos-making-yourself-audit-ready-with-verae-datacubes.pdf differ diff --git a/source/conf.py b/source/conf.py index bc7bb6b..cd700ad 100644 --- a/source/conf.py +++ b/source/conf.py @@ -9,7 +9,7 @@ version = "2.0" extensions = [] templates_path = ["_templates"] -exclude_patterns = ["verification.rst"] +exclude_patterns = ["verification.rst", "executive.rst"] html_theme = "alabaster" html_static_path = ["_static"] @@ -134,8 +134,6 @@ app.verae.com\par} \end{titlepage} \clearpage """, - "tableofcontents": r""" -\tableofcontents -\clearpage -""", + # TOC is emitted from index.rst *after* the page-2 executive summary. + "tableofcontents": "", } diff --git a/source/index.rst b/source/index.rst index f0023b0..b87a99c 100644 --- a/source/index.rst +++ b/source/index.rst @@ -8,20 +8,61 @@ Making yourself audit-ready with Verae DataCubes :alt: Verae :class: logo -This volume is a technical briefing. It is **not** a certificate. +.. raw:: latex -The table of contents below is the document map. In the PDF edition, -each chapter starts on a new page and the contents list includes -**section titles with page numbers**. In HTML, each chapter is its own -page with the Verae wordmark in the sidebar and Verae Inc contact -information in the footer. + \thispagestyle{plain} + \vspace*{0.15cm} + {\LARGE\bfseries\color{veraepurple}Executive summary\par} + \vspace{0.85em} + \addcontentsline{toc}{chapter}{Executive summary} + +Software alone does not make an organization HIPAA certified, SOC 2 +attested, or ISO 27001 certified. + +That sentence is the point of this document. It is also the sentence +that is most often skipped when a vendor, an integrator, or an internal +champion shows encryption, hashing, or a pentest PDF and treats the +conversation as finished. It is not finished. Encryption is a control. +A pentest is an evaluation of a component. A certificate, an attestation, +or a covered-entity determination is a statement about **an organization** +--- its legal entity, its people, its written policies, its operating +procedures, its internal controls, the evidence those controls produce, +and the independent party that examined that evidence. + +The Verae DataCube Solution gives an organization tools to **store**, +**communicate**, **timestamp**, **verify**, and **audit** for compliance. +Those tools are real, they are specific, and they are described in the +chapters that follow. They are still only tools. To obtain HIPAA-aligned +status as a covered entity or business associate with a defensible +program, a SOC 2 Type I or Type II report, or an ISO 27001 certificate, +the organization must still: + +* write and live by **policies** (what the organization says it will do); +* operate **procedures** (how staff actually do it, every day); +* design and test **internal controls** (the checks that catch failure); +* retain **evidence** (logs, tickets, screenshots, signed approvals, + restore tests, training records); +* engage an **independent auditor**, CPA firm, or ISO registrar, as the + chosen program requires. + +Verae cannot issue those certificates. Verae cannot sit in the +organization's chair during an OCR investigation, a SOC 2 fieldwork +week, or an ISO Stage 2 audit. What Verae can do --- and what this +briefing is written to make precise --- is provide the **tools**, the +**background**, and the **software infrastructure** that make it easier +to implement the **technical portion** of those programs. + +.. raw:: latex + + \clearpage + \tableofcontents + \clearpage .. toctree:: :maxdepth: 2 :numbered: :caption: Contents - executive what-verae-provides datacube-server data-in-transit