Initial pack: Peergos EU audit verification and DataCube audit-ready checklist
Some checks are pending
ci / markdown (push) Waiting to run
Some checks are pending
ci / markdown (push) Waiting to run
Cure53 Berlin 2019 and ROS Amsterdam 2024 are pentests, not HIPAA/SOC2/ISO certificates. BAA/DPA guidance for ciphertext-at-rest on cryptree+IPFS.
This commit is contained in:
commit
afa270a141
9 changed files with 392 additions and 0 deletions
33
MODULE.md
Normal file
33
MODULE.md
Normal file
|
|
@ -0,0 +1,33 @@
|
|||
# MODULE — peergos-making-yourself-audit-ready-with-verae-datacubes
|
||||
|
||||
Git: https://git.georgelambert.org/marchon/peergos-making-yourself-audit-ready-with-verae-datacubes
|
||||
|
||||
This is **not** a HIPAA/SOC 2/ISO certificate.
|
||||
|
||||
## What this module is
|
||||
|
||||
Documentation pack: how an organization uses Verae DataCubes on Peergos
|
||||
to **prepare for** an audit. Includes sourced verification of Peergos’s
|
||||
EU security evaluations and a BAA/DPA discussion for ciphertext-at-rest.
|
||||
|
||||
## Who calls this module and why
|
||||
|
||||
Compliance, counsel, and auditors. No runtime NATS publisher.
|
||||
|
||||
## Messages — from / to
|
||||
|
||||
None. Static git + rendered docs.
|
||||
|
||||
## Filters / security
|
||||
|
||||
Do not claim Peergos pentests are your ISO/SOC certificate. Do not commit
|
||||
private keys. Public key directory URLs only.
|
||||
|
||||
## Errors and timeouts
|
||||
|
||||
n/a
|
||||
|
||||
## Where data is stored
|
||||
|
||||
This repo on git.georgelambert.org. Live cubes remain on Peergos cryptree
|
||||
+ IPFS; NATS carries HPKE content.
|
||||
Loading…
Add table
Add a link
Reference in a new issue