Put the executive summary on page 2, before the table of contents.
Some checks are pending
ci / markdown (push) Waiting to run

The cover stays page 1. Numbered chapters now start at What Verae
provides. The TOC lists Executive summary at page 2.
This commit is contained in:
George Lambert 2026-09-16 01:21:05 -04:00
parent 5df7ed87d5
commit 8496ef8338
23 changed files with 759 additions and 723 deletions

View file

@ -5,19 +5,19 @@
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>7. Peergos security evaluations in Europe &#8212; Making yourself audit-ready with Verae DataCubes</title>
<title>6. Peergos security evaluations in Europe &#8212; Making yourself audit-ready with Verae DataCubes</title>
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=2d7b7068" />
<script src="_static/documentation_options.js?v=250a654d"></script>
<script src="_static/doctools.js?v=fd6eb6e6"></script>
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
<link rel="icon" href="_static/VeraeFullLogo.png"/>
<link rel="index" title="Index" href="genindex.html" />
<link rel="search" title="Search" href="search.html" />
<link rel="next" title="8. Verae global timestamping — a cross-blockchain receipt" href="global-timestamping.html" />
<link rel="prev" title="6. Global timestamped receipts" href="timestamped-receipts.html" />
<link rel="next" title="7. Verae global timestamping — a cross-blockchain receipt" href="global-timestamping.html" />
<link rel="prev" title="5. Global timestamped receipts" href="timestamped-receipts.html" />
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
@ -61,39 +61,38 @@
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="executive.html">1. Executive summary</a></li>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">3. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">6. Global timestamped receipts</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">7. Peergos security evaluations in Europe</a><ul>
<li class="toctree-l2"><a class="reference internal" href="#what-was-evaluated">7.1. What was evaluated</a></li>
<li class="toctree-l2"><a class="reference internal" href="#cure53-berlin-germany">7.2. 2019 — Cure53, Berlin, Germany</a></li>
<li class="toctree-l2"><a class="reference internal" href="#radically-open-security-b-v-amsterdam">7.3. 2024 — Radically Open Security B.V., Amsterdam</a></li>
<li class="toctree-l2"><a class="reference internal" href="#how-to-present-these-reports-to-an-auditor">7.4. How to present these reports to an auditor</a></li>
<li class="toctree-l2"><a class="reference internal" href="#hosted-peergos-versus-self-hosted-datacubes">7.5. Hosted Peergos versus self-hosted DataCubes</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-designed-under-funding-from-cure53-ros-is-not">7.6. What “designed under funding from Cure53 / ROS” is not</a></li>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">1. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">2. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">3. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">4. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">5. Global timestamped receipts</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">6. Peergos security evaluations in Europe</a><ul>
<li class="toctree-l2"><a class="reference internal" href="#what-was-evaluated">6.1. What was evaluated</a></li>
<li class="toctree-l2"><a class="reference internal" href="#cure53-berlin-germany">6.2. 2019 — Cure53, Berlin, Germany</a></li>
<li class="toctree-l2"><a class="reference internal" href="#radically-open-security-b-v-amsterdam">6.3. 2024 — Radically Open Security B.V., Amsterdam</a></li>
<li class="toctree-l2"><a class="reference internal" href="#how-to-present-these-reports-to-an-auditor">6.4. How to present these reports to an auditor</a></li>
<li class="toctree-l2"><a class="reference internal" href="#hosted-peergos-versus-self-hosted-datacubes">6.5. Hosted Peergos versus self-hosted DataCubes</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-designed-under-funding-from-cure53-ros-is-not">6.6. What “designed under funding from Cure53 / ROS” is not</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">8. Verae global timestamping — a cross-blockchain receipt</a></li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">12. Audit-ready checklist</a></li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">13. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">15. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">7. Verae global timestamping — a cross-blockchain receipt</a></li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">8. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">9. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">10. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">11. Audit-ready checklist</a></li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">12. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">13. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">14. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">15. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">16. Verae Inc — contact</a></li>
</ul>
<div class="relations">
<h3>Related Topics</h3>
<ul>
<li><a href="index.html">Documentation overview</a><ul>
<li>Previous: <a href="timestamped-receipts.html" title="previous chapter"><span class="section-number">6. </span>Global timestamped receipts</a></li>
<li>Next: <a href="global-timestamping.html" title="next chapter"><span class="section-number">8. </span>Verae global timestamping — a cross-blockchain receipt</a></li>
<li>Previous: <a href="timestamped-receipts.html" title="previous chapter"><span class="section-number">5. </span>Global timestamped receipts</a></li>
<li>Next: <a href="global-timestamping.html" title="next chapter"><span class="section-number">7. </span>Verae global timestamping — a cross-blockchain receipt</a></li>
</ul></li>
</ul>
</div>
@ -114,9 +113,9 @@
<div class="body" role="main">
<section id="peergos-security-evaluations-in-europe">
<h1><span class="section-number">7. </span>Peergos security evaluations in Europe<a class="headerlink" href="#peergos-security-evaluations-in-europe" title="Link to this heading"></a></h1>
<h1><span class="section-number">6. </span>Peergos security evaluations in Europe<a class="headerlink" href="#peergos-security-evaluations-in-europe" title="Link to this heading"></a></h1>
<section id="what-was-evaluated">
<h2><span class="section-number">7.1. </span>What was evaluated<a class="headerlink" href="#what-was-evaluated" title="Link to this heading"></a></h2>
<h2><span class="section-number">6.1. </span>What was evaluated<a class="headerlink" href="#what-was-evaluated" title="Link to this heading"></a></h2>
<p>The offline storage and replication system used with Verae
DataCubes is <strong>Peergos</strong>: an encrypted, peer-to-peer filesystem
whose blocks live on IPFS. Peergos was designed as a
@ -139,7 +138,7 @@ is unusual and is worth attaching to a vendor-assurance file,
<strong>labeled correctly</strong>.</p>
</section>
<section id="cure53-berlin-germany">
<h2><span class="section-number">7.2. </span>2019 — Cure53, Berlin, Germany<a class="headerlink" href="#cure53-berlin-germany" title="Link to this heading"></a></h2>
<h2><span class="section-number">6.2. </span>2019 — Cure53, Berlin, Germany<a class="headerlink" href="#cure53-berlin-germany" title="Link to this heading"></a></h2>
<ul class="simple">
<li><p><strong>Firm:</strong> Cure53</p></li>
<li><p><strong>Location:</strong> Berlin, Germany</p></li>
@ -167,7 +166,7 @@ did find were addressed.</p>
</ul>
</section>
<section id="radically-open-security-b-v-amsterdam">
<h2><span class="section-number">7.3. </span>2024 — Radically Open Security B.V., Amsterdam<a class="headerlink" href="#radically-open-security-b-v-amsterdam" title="Link to this heading"></a></h2>
<h2><span class="section-number">6.3. </span>2024 — Radically Open Security B.V., Amsterdam<a class="headerlink" href="#radically-open-security-b-v-amsterdam" title="Link to this heading"></a></h2>
<ul class="simple">
<li><p><strong>Firm:</strong> Radically Open Security B.V.</p></li>
<li><p><strong>Location:</strong> Amsterdam, Netherlands</p></li>
@ -198,7 +197,7 @@ still not a customers Type II.</p>
</ul>
</section>
<section id="how-to-present-these-reports-to-an-auditor">
<h2><span class="section-number">7.4. </span>How to present these reports to an auditor<a class="headerlink" href="#how-to-present-these-reports-to-an-auditor" title="Link to this heading"></a></h2>
<h2><span class="section-number">6.4. </span>How to present these reports to an auditor<a class="headerlink" href="#how-to-present-these-reports-to-an-auditor" title="Link to this heading"></a></h2>
<p>Correct:</p>
<blockquote>
<div><p>“Our at-rest layer is Peergos. Peergos was independently
@ -221,7 +220,7 @@ is a research-and-innovation funding fact. It is worth
listing under “provenance.” It is not a registrars mark.</p>
</section>
<section id="hosted-peergos-versus-self-hosted-datacubes">
<h2><span class="section-number">7.5. </span>Hosted Peergos versus self-hosted DataCubes<a class="headerlink" href="#hosted-peergos-versus-self-hosted-datacubes" title="Link to this heading"></a></h2>
<h2><span class="section-number">6.5. </span>Hosted Peergos versus self-hosted DataCubes<a class="headerlink" href="#hosted-peergos-versus-self-hosted-datacubes" title="Link to this heading"></a></h2>
<p>Peergoss hosted privacy notice has stated that peergos.net
uses servers in <strong>Germany</strong>. A <strong>self-hosted</strong> organizational
DataCube is a <strong>different processing location</strong>. The
@ -234,7 +233,7 @@ implementation</strong>. Location of processing is an
organizational fact on top.</p>
</section>
<section id="what-designed-under-funding-from-cure53-ros-is-not">
<h2><span class="section-number">7.6. </span>What “designed under funding from Cure53 / ROS” is not<a class="headerlink" href="#what-designed-under-funding-from-cure53-ros-is-not" title="Link to this heading"></a></h2>
<h2><span class="section-number">6.6. </span>What “designed under funding from Cure53 / ROS” is not<a class="headerlink" href="#what-designed-under-funding-from-cure53-ros-is-not" title="Link to this heading"></a></h2>
<p>The 2019 Cure53 work and the 2024 ROS work are <strong>evaluations</strong>
of a system that was designed by the Peergos authors. They
are not a claim that Cure53 or Radically Open Security