Put the executive summary on page 2, before the table of contents.
Some checks are pending
ci / markdown (push) Waiting to run

The cover stays page 1. Numbered chapters now start at What Verae
provides. The TOC lists Executive summary at page 2.
This commit is contained in:
George Lambert 2026-09-16 01:21:05 -04:00
parent 5df7ed87d5
commit 8496ef8338
23 changed files with 759 additions and 723 deletions

View file

@ -5,19 +5,19 @@
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>6. Global timestamped receipts &#8212; Making yourself audit-ready with Verae DataCubes</title>
<title>5. Global timestamped receipts &#8212; Making yourself audit-ready with Verae DataCubes</title>
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=2d7b7068" />
<script src="_static/documentation_options.js?v=250a654d"></script>
<script src="_static/doctools.js?v=fd6eb6e6"></script>
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
<link rel="icon" href="_static/VeraeFullLogo.png"/>
<link rel="index" title="Index" href="genindex.html" />
<link rel="search" title="Search" href="search.html" />
<link rel="next" title="7. Peergos security evaluations in Europe" href="peergos-eu-evaluations.html" />
<link rel="prev" title="5. Encryption at rest — IPFS blocks and Peergos" href="data-at-rest.html" />
<link rel="next" title="6. Peergos security evaluations in Europe" href="peergos-eu-evaluations.html" />
<link rel="prev" title="4. Encryption at rest — IPFS blocks and Peergos" href="data-at-rest.html" />
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
@ -61,40 +61,39 @@
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="executive.html">1. Executive summary</a></li>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">3. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">6. Global timestamped receipts</a><ul>
<li class="toctree-l2"><a class="reference internal" href="#why-hashes-are-not-enough-by-themselves">6.1. Why hashes are not enough by themselves</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-a-verae-receipt-is">6.2. What a Verae receipt is</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-is-registered-and-what-is-not">6.3. What is registered, and what is not</a></li>
<li class="toctree-l2"><a class="reference internal" href="#first-registration-wins">6.4. First registration wins</a></li>
<li class="toctree-l2"><a class="reference internal" href="#sequence">6.5. Sequence</a></li>
<li class="toctree-l2"><a class="reference internal" href="#bundles">6.6. Bundles</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-a-receipt-does-not-prove">6.7. What a receipt does not prove</a></li>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">1. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">2. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">3. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">4. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">5. Global timestamped receipts</a><ul>
<li class="toctree-l2"><a class="reference internal" href="#why-hashes-are-not-enough-by-themselves">5.1. Why hashes are not enough by themselves</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-a-verae-receipt-is">5.2. What a Verae receipt is</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-is-registered-and-what-is-not">5.3. What is registered, and what is not</a></li>
<li class="toctree-l2"><a class="reference internal" href="#first-registration-wins">5.4. First registration wins</a></li>
<li class="toctree-l2"><a class="reference internal" href="#sequence">5.5. Sequence</a></li>
<li class="toctree-l2"><a class="reference internal" href="#bundles">5.6. Bundles</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-a-receipt-does-not-prove">5.7. What a receipt does not prove</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">7. Peergos security evaluations in Europe</a></li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">8. Verae global timestamping — a cross-blockchain receipt</a></li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">12. Audit-ready checklist</a></li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">13. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">15. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">6. Peergos security evaluations in Europe</a></li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">7. Verae global timestamping — a cross-blockchain receipt</a></li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">8. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">9. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">10. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">11. Audit-ready checklist</a></li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">12. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">13. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">14. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">15. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">16. Verae Inc — contact</a></li>
</ul>
<div class="relations">
<h3>Related Topics</h3>
<ul>
<li><a href="index.html">Documentation overview</a><ul>
<li>Previous: <a href="data-at-rest.html" title="previous chapter"><span class="section-number">5. </span>Encryption at rest — IPFS blocks and Peergos</a></li>
<li>Next: <a href="peergos-eu-evaluations.html" title="next chapter"><span class="section-number">7. </span>Peergos security evaluations in Europe</a></li>
<li>Previous: <a href="data-at-rest.html" title="previous chapter"><span class="section-number">4. </span>Encryption at rest — IPFS blocks and Peergos</a></li>
<li>Next: <a href="peergos-eu-evaluations.html" title="next chapter"><span class="section-number">6. </span>Peergos security evaluations in Europe</a></li>
</ul></li>
</ul>
</div>
@ -115,9 +114,9 @@
<div class="body" role="main">
<section id="global-timestamped-receipts">
<h1><span class="section-number">6. </span>Global timestamped receipts<a class="headerlink" href="#global-timestamped-receipts" title="Link to this heading"></a></h1>
<h1><span class="section-number">5. </span>Global timestamped receipts<a class="headerlink" href="#global-timestamped-receipts" title="Link to this heading"></a></h1>
<section id="why-hashes-are-not-enough-by-themselves">
<h2><span class="section-number">6.1. </span>Why hashes are not enough by themselves<a class="headerlink" href="#why-hashes-are-not-enough-by-themselves" title="Link to this heading"></a></h2>
<h2><span class="section-number">5.1. </span>Why hashes are not enough by themselves<a class="headerlink" href="#why-hashes-are-not-enough-by-themselves" title="Link to this heading"></a></h2>
<p>A cryptographic hash of a document proves that two copies are
bit-for-bit the same, or that they are not. It does <strong>not</strong> prove
<strong>when</strong> the document first existed. Anyone can hash a file
@ -132,7 +131,7 @@ the hash, that a later examiner can check without trusting the
files custodian.</strong></p>
</section>
<section id="what-a-verae-receipt-is">
<h2><span class="section-number">6.2. </span>What a Verae receipt is<a class="headerlink" href="#what-a-verae-receipt-is" title="Link to this heading"></a></h2>
<h2><span class="section-number">5.2. </span>What a Verae receipt is<a class="headerlink" href="#what-a-verae-receipt-is" title="Link to this heading"></a></h2>
<p>A Verae <strong>global timestamped receipt</strong> is proof of:</p>
<ul class="simple">
<li><p>the <strong>hash</strong> of a block of digital information;</p></li>
@ -149,7 +148,7 @@ from 1991, applied here as a product: time-stamp the data, not
the disk.</p>
</section>
<section id="what-is-registered-and-what-is-not">
<h2><span class="section-number">6.3. </span>What is registered, and what is not<a class="headerlink" href="#what-is-registered-and-what-is-not" title="Link to this heading"></a></h2>
<h2><span class="section-number">5.3. </span>What is registered, and what is not<a class="headerlink" href="#what-is-registered-and-what-is-not" title="Link to this heading"></a></h2>
<p>Veraes public description of sealing is that <strong>only a
fingerprint leaves the customers systems</strong>. The object itself
can remain in the customers DataCube. The central service
@ -164,7 +163,7 @@ For HIPAA, GDPR, and ordinary commercial secrecy, that is the
desired shape.</p>
</section>
<section id="first-registration-wins">
<h2><span class="section-number">6.4. </span>First registration wins<a class="headerlink" href="#first-registration-wins" title="Link to this heading"></a></h2>
<h2><span class="section-number">5.4. </span>First registration wins<a class="headerlink" href="#first-registration-wins" title="Link to this heading"></a></h2>
<p>A hash registry that allowed a later write to overwrite the
timestamp of an earlier write would be a forgery machine. The
rule is: <strong>the first SHA-256 (and companion hash) and its
@ -174,7 +173,7 @@ which is exactly how a revision should be modeled. Revisions
get their own receipts. They do not steal the originals time.</p>
</section>
<section id="sequence">
<h2><span class="section-number">6.5. </span>Sequence<a class="headerlink" href="#sequence" title="Link to this heading"></a></h2>
<h2><span class="section-number">5.5. </span>Sequence<a class="headerlink" href="#sequence" title="Link to this heading"></a></h2>
<p>Time on a wall clock is a social convention and a NTP
configuration. Sequence inside a registration service is a
data-structure fact: this hash was committed after that hash,
@ -184,7 +183,7 @@ order even when two wall-clock stamps are close enough to argue
about.</p>
</section>
<section id="bundles">
<h2><span class="section-number">6.6. </span>Bundles<a class="headerlink" href="#bundles" title="Link to this heading"></a></h2>
<h2><span class="section-number">5.6. </span>Bundles<a class="headerlink" href="#bundles" title="Link to this heading"></a></h2>
<p>A receipt does not have to travel as a bare timestamp. It can
travel inside a <strong>digital bundle</strong> that also holds:</p>
<ul class="simple">
@ -200,7 +199,7 @@ the metadata we claim goes with it, here is the verification
path.”</p>
</section>
<section id="what-a-receipt-does-not-prove">
<h2><span class="section-number">6.7. </span>What a receipt does not prove<a class="headerlink" href="#what-a-receipt-does-not-prove" title="Link to this heading"></a></h2>
<h2><span class="section-number">5.7. </span>What a receipt does not prove<a class="headerlink" href="#what-a-receipt-does-not-prove" title="Link to this heading"></a></h2>
<p>A receipt does not prove that the person who registered the
hash was authorized to do so. That is an access-control and
identity problem.</p>