Initial pack: Peergos EU audit verification and DataCube audit-ready checklist
Some checks are pending
ci / markdown (push) Waiting to run

Cure53 Berlin 2019 and ROS Amsterdam 2024 are pentests, not HIPAA/SOC2/ISO
certificates. BAA/DPA guidance for ciphertext-at-rest on cryptree+IPFS.
This commit is contained in:
George Lambert 2026-09-15 23:57:04 -04:00
commit afa270a141
9 changed files with 392 additions and 0 deletions

33
MODULE.md Normal file
View file

@ -0,0 +1,33 @@
# MODULE — peergos-making-yourself-audit-ready-with-verae-datacubes
Git: https://git.georgelambert.org/marchon/peergos-making-yourself-audit-ready-with-verae-datacubes
This is **not** a HIPAA/SOC 2/ISO certificate.
## What this module is
Documentation pack: how an organization uses Verae DataCubes on Peergos
to **prepare for** an audit. Includes sourced verification of Peergoss
EU security evaluations and a BAA/DPA discussion for ciphertext-at-rest.
## Who calls this module and why
Compliance, counsel, and auditors. No runtime NATS publisher.
## Messages — from / to
None. Static git + rendered docs.
## Filters / security
Do not claim Peergos pentests are your ISO/SOC certificate. Do not commit
private keys. Public key directory URLs only.
## Errors and timeouts
n/a
## Where data is stored
This repo on git.georgelambert.org. Live cubes remain on Peergos cryptree
+ IPFS; NATS carries HPKE content.