Initial pack: Peergos EU audit verification and DataCube audit-ready checklist
Some checks are pending
ci / markdown (push) Waiting to run

Cure53 Berlin 2019 and ROS Amsterdam 2024 are pentests, not HIPAA/SOC2/ISO
certificates. BAA/DPA guidance for ciphertext-at-rest on cryptree+IPFS.
This commit is contained in:
George Lambert 2026-09-15 23:57:04 -04:00
commit afa270a141
9 changed files with 392 additions and 0 deletions

73
README.md Normal file
View file

@ -0,0 +1,73 @@
# Making yourself audit-ready with Verae DataCubes
How to **prepare an organization** for HIPAA-aligned, SOC 2, or ISO 27001
work using Verae DataCubes on **Peergos** (encrypted cryptree + hashed
IPFS) and HPKE on an **untrusted NATS** broker.
**This repository is not a HIPAA, SOC 2, or ISO certificate.**
Peergoss public pentests are **not** your Type II or ISO registrar
certificate. They are **component security evaluations** you can attach.
## What we verified about Peergos (EU)
Full sources: [`PEERGOS-VERIFICATION.md`](PEERGOS-VERIFICATION.md).
| Fact | Verified? |
|---|---|
| Encrypted client-side filesystem (cryptree); keys not on the storage server | Yes — Peergos book + Cure53 design review |
| IPFS blocks content-addressed; Peergos verifies hashes (tamper-evident restore) | Yes — [trust-free layers](https://book.peergos.org/security/trust.html) |
| Independent **EU** security audits, reports published | **Yes — two:** Cure53 **Berlin** (2019); Radically Open Security **Amsterdam** (2024, NLnet; EU Horizon 2020 NGI-POINTER mentioned on the post) |
| “Peergos is HIPAA/SOC 2/ISO certified” | **No.** Those audits are pentest/code/design reviews, not management-system certificates |
So: Peergos **was designed as a trust-minimized encrypted filesystem**,
**evaluated in Europe** by two specialist firms, with **public reports**.
That supports the **at-rest / backup** story. It does **not** finish
*your* audit.
## Architecture (audit interview in one page)
```
Endpoint (keys stay here / HSM)
│ HPKE content (NPE suite)
│ routing: dest + subject in the clear
Untrusted NATS (cannot read bodies)
Verae DataCube chain (append-only hashes)
│ written through Peergos client
Peergos cryptree (encrypted names, sizes, graph)
│ chunks → CID / hash
IPFS (distributed, hash-verified ciphertext)
```
- **At rest:** Peergos cryptree + IPFS. Hosts with disk/backup see
**opaque hashed ciphertext**, not PHI, if they lack keys.
- **In transit (NATS):** HPKE-Base to directory public keys. Broker is
honest-but-curious: destinations yes, bodies no.
- **Integrity:** cube JSONL chain + dual hash + IPFS CID check on
restore (re-fetch blocks, re-verify hashes — not a plaintext tape).
## BAAs / DPAs
Ciphertext-without-keys **narrows** who is a Business Associate or
GDPR processor for **content**. It does **not** automatically delete
contracts for VMs, usernames, or logs. See [`BAA-DPA.md`](BAA-DPA.md).
## Pack
| File | Use |
|---|---|
| `PEERGOS-VERIFICATION.md` | Sourced Peergos/EU audit facts |
| `BAA-DPA.md` | Counsel briefing |
| `CHECKLIST.md` | Evidence list |
| `HOWTO.md` | How to hand this to an auditor |
| `MODULE.md` | Callers / non-runtime |
Live technical surfaces (ns1): https://pfc.georgelambert.org/health ·
https://pfc.georgelambert.org/v1/npe/keys ·
https://docs.pfc.georgelambert.org/controls.html
Related: https://git.georgelambert.org/marchon/system-git-sync