Sphinx HTML and 17-page LaTeX PDF for the audit-ready pack
Some checks are pending
ci / markdown (push) Waiting to run

source/ is the Sphinx tree. Companion PDF hrefs are relative, not Markdown.
This commit is contained in:
George Lambert 2026-09-15 23:59:54 -04:00
parent afa270a141
commit da60402e88
104 changed files with 16818 additions and 0 deletions

View file

@ -0,0 +1,607 @@
%% Generated by Sphinx.
\def\sphinxdocclass{report}
\documentclass[letterpaper,11pt,english]{sphinxmanual}
\ifdefined\pdfpxdimen
\let\sphinxpxdimen\pdfpxdimen\else\newdimen\sphinxpxdimen
\fi \sphinxpxdimen=.75bp\relax
\ifdefined\pdfimageresolution
\pdfimageresolution= \numexpr \dimexpr1in\relax/\sphinxpxdimen\relax
\fi
\newdimen\sphinxremdimen\sphinxremdimen = 11pt
%% let collapsible pdf bookmarks panel have high depth per default
\PassOptionsToPackage{bookmarksdepth=5}{hyperref}
\PassOptionsToPackage{booktabs}{sphinx}
\PassOptionsToPackage{colorrows}{sphinx}
\PassOptionsToPackage{warn}{textcomp}
\usepackage[utf8]{inputenc}
\ifdefined\DeclareUnicodeCharacter
% support both utf8 and utf8x syntaxes
\ifdefined\DeclareUnicodeCharacterAsOptional
\def\sphinxDUC#1{\DeclareUnicodeCharacter{"#1}}
\else
\let\sphinxDUC\DeclareUnicodeCharacter
\fi
\sphinxDUC{00A0}{\nobreakspace}
\sphinxDUC{2500}{\sphinxunichar{2500}}
\sphinxDUC{2502}{\sphinxunichar{2502}}
\sphinxDUC{2514}{\sphinxunichar{2514}}
\sphinxDUC{251C}{\sphinxunichar{251C}}
\sphinxDUC{2572}{\textbackslash}
\fi
\usepackage{cmap}
\usepackage[T1]{fontenc}
\usepackage{amsmath,amssymb,amstext}
\usepackage{babel}
\usepackage{tgtermes}
\usepackage{tgheros}
\renewcommand{\ttdefault}{txtt}
\usepackage[Bjarne]{fncychap}
\usepackage{sphinx}
\fvset{fontsize=auto}
\usepackage{geometry}
% Include hyperref last.
\usepackage{hyperref}
% Fix anchor placement for figures with captions.
\usepackage{hypcap}% it must be loaded after hyperref.
% Set up styles of URL: it should be placed after hyperref.
\urlstyle{same}
\usepackage{sphinxmessages}
\setcounter{tocdepth}{1}
\usepackage{hyperref}
\title{Making yourself audit-ready with Verae DataCubes}
\date{Sep 16, 2026}
\release{}
\author{Verae}
\newcommand{\sphinxlogo}{\vbox{}}
\renewcommand{\releasename}{}
\makeindex
\begin{document}
\ifdefined\shorthandoff
\ifnum\catcode`\=\string=\active\shorthandoff{=}\fi
\ifnum\catcode`\"=\active\shorthandoff{"}\fi
\fi
\pagestyle{empty}
\sphinxmaketitle
\pagestyle{plain}
\sphinxtableofcontents
\pagestyle{normal}
\phantomsection\label{\detokenize{index::doc}}
\sphinxAtStartPar
How to \sphinxstylestrong{prepare an organization} for HIPAA\sphinxhyphen{}aligned, SOC 2, or ISO 27001
work using Verae DataCubes on \sphinxstylestrong{Peergos} (encrypted cryptree + hashed
IPFS) and HPKE on an \sphinxstylestrong{untrusted NATS} broker.
\sphinxAtStartPar
\sphinxstylestrong{This document is not a HIPAA, SOC 2, or ISO certificate.}
Peergoss public pentests are \sphinxstylestrong{not} your Type II or ISO registrar
certificate. They are \sphinxstylestrong{component security evaluations} you can attach.
\sphinxstepscope
\chapter{Peergos verification (what was actually audited)}
\label{\detokenize{verification:peergos-verification-what-was-actually-audited}}\label{\detokenize{verification::doc}}
\sphinxAtStartPar
This chapter records \sphinxstylestrong{sourced} facts. It does \sphinxstylestrong{not} turn Peergos, Verae,
or DataCubes into a HIPAA, SOC 2, or ISO 27001 certificate.
\section{Claim to check}
\label{\detokenize{verification:claim-to-check}}
\sphinxAtStartPar
Data at rest is stored in an encrypted append\sphinxhyphen{}only Peergos filesystem;
backup/restore is managed via a distributed, hashed, encrypted Peergos
IPFS system, designed and evaluated in the EU as an audited secure
filesystem.
\section{Independent security audits (Europe)}
\label{\detokenize{verification:independent-security-audits-europe}}
\sphinxAtStartPar
\sphinxstylestrong{2019 — Cure53 (Berlin, Germany).}
Pentest, source\sphinxhyphen{}code audit, \sphinxstylestrong{crypto/design review} (May\textendash{}June 2019).
No fundamental architectural or cryptographic problems; issues fixed.
Cure53: the platform \sphinxstylestrong{passed this evaluation}.
\sphinxAtStartPar
\sphinxstylestrong{2024 — Radically Open Security B.V. (Amsterdam, Netherlands).}
Crystal\sphinxhyphen{}box pentest + code audit of Peergos web\sphinxhyphen{}ui (Sep\textendash{}Nov 2024).
\sphinxstylestrong{0} extreme / high / elevated; \sphinxstylestrong{2} moderate, \sphinxstylestrong{6} low; Peergos
states all fixed; no data exposure or integrity compromise (mostly UI
crashes).
\sphinxAtStartPar
Both firms are \sphinxstylestrong{EU\sphinxhyphen{}based}. Both full reports are \sphinxstylestrong{public}. That is a
\sphinxstylestrong{security evaluation of the Peergos protocol/implementation}, not a
HIPAA/SOC 2/ISO management\sphinxhyphen{}system certificate.
\section{EU funding / NLnet}
\label{\detokenize{verification:eu-funding-nlnet}}\begin{itemize}
\item {}
\sphinxAtStartPar
Peergos received funding from the \sphinxstylestrong{European Union Horizon 2020}
programme under \sphinxstylestrong{NGI\sphinxhyphen{}POINTER}, grant \sphinxstylestrong{871528} (stated on the 2024
audit post).
\item {}
\sphinxAtStartPar
The 2024 audit was supported by \sphinxstylestrong{NLnet} (Netherlands).
\end{itemize}
\section{Hosted instance location}
\label{\detokenize{verification:hosted-instance-location}}
\sphinxAtStartPar
Peergoss hosted privacy notice states peergos.net uses servers in
\sphinxstylestrong{Germany}. \sphinxstylestrong{Self\sphinxhyphen{}hosted ns1 / customer cryptree is a different
processing location} and must be documented in \sphinxstyleemphasis{your} RoPA / BAA pack.
\section{Encrypted filesystem + hashed IPFS (design)}
\label{\detokenize{verification:encrypted-filesystem-hashed-ipfs-design}}\begin{itemize}
\item {}
\sphinxAtStartPar
\sphinxstylestrong{Cryptree}: tree of symmetric keys; fine\sphinxhyphen{}grained read/write caps;
sibling names hidden; writes \sphinxstylestrong{signed}.
\item {}
\sphinxAtStartPar
\sphinxstylestrong{Chunks}: up to 5 MiB, padded, independently encrypted
(Salsa20\sphinxhyphen{}Poly1305); random 256\sphinxhyphen{}bit keys (not convergent).
\item {}
\sphinxAtStartPar
\sphinxstylestrong{IPFS}: content\sphinxhyphen{}addressed blocks. Peergos \sphinxstylestrong{verifies the hash} of
every block read from or written to IPFS. Clients verify hashes and
signatures from a Peergos server.
\item {}
\sphinxAtStartPar
\sphinxstylestrong{CHAMP}: encrypted cryptree nodes under \sphinxstylestrong{random 32\sphinxhyphen{}byte labels}.
\item {}
\sphinxAtStartPar
Sharing: hybrid \sphinxstylestrong{X25519 + ML\sphinxhyphen{}KEM\sphinxhyphen{}1024}.
\end{itemize}
\sphinxAtStartPar
“Append\sphinxhyphen{}only” in Verae DataCubes is the \sphinxstylestrong{cube chain JSONL} (application
integrity). Peergos uses signed updates and immutable blocks. Do not
conflate the two layers in an audit interview.
\section{Not verified / do not claim}
\label{\detokenize{verification:not-verified-do-not-claim}}\begin{itemize}
\item {}
\sphinxAtStartPar
“Peergos is HIPAA certified” — \sphinxstylestrong{false.} HIPAA is not a product certificate.
\item {}
\sphinxAtStartPar
“Peergos is SOC 2 / ISO 27001 certified” — \sphinxstylestrong{not shown.} Published
work is pentest/code audit, not Type II or ISO registrar.
\item {}
\sphinxAtStartPar
“EU certified Peergos as a government\sphinxhyphen{}standard filesystem” —
\sphinxstylestrong{overstated.} What exists: EU grant funding, NLNet\sphinxhyphen{}funded ROS
pentest, Cure53 Berlin design+code audit.
\item {}
\sphinxAtStartPar
“Hosts with disk/backup never need a BAA/DPA” — \sphinxstylestrong{legal conclusion,
not a technical fact.} See {\hyperref[\detokenize{baa-dpa::doc}]{\sphinxcrossref{\DUrole{doc}{BAAs and DPAs when ciphertext has no host keys}}}}.
\end{itemize}
\sphinxstepscope
\chapter{Architecture (audit interview)}
\label{\detokenize{architecture:architecture-audit-interview}}\label{\detokenize{architecture::doc}}
\begin{sphinxVerbatim}[commandchars=\\\{\}]
Endpoint (keys stay here / HSM)
│ HPKE content (NPE suite)
│ routing: dest + subject in the clear
Untrusted NATS (cannot read bodies)
Verae DataCube chain (append\PYGZhy{}only hashes)
│ written through Peergos client
Peergos cryptree (encrypted names, sizes, graph)
│ chunks \(\rightarrow\) CID / hash
IPFS (distributed, hash\PYGZhy{}verified ciphertext)
\end{sphinxVerbatim}
\begin{itemize}
\item {}
\sphinxAtStartPar
\sphinxstylestrong{At rest:} Peergos cryptree + IPFS. Hosts with disk/backup see
\sphinxstylestrong{opaque hashed ciphertext}, not PHI, if they lack keys.
\item {}
\sphinxAtStartPar
\sphinxstylestrong{In transit (NATS):} HPKE\sphinxhyphen{}Base to directory public keys. Broker is
honest\sphinxhyphen{}but\sphinxhyphen{}curious: destinations yes, bodies no.
\item {}
\sphinxAtStartPar
\sphinxstylestrong{Integrity:} cube JSONL chain + dual hash + IPFS CID check on
restore (re\sphinxhyphen{}fetch blocks, re\sphinxhyphen{}verify hashes — not a plaintext tape).
\end{itemize}
\sphinxAtStartPar
NATS remains an untrusted router. Production E2E is NPE/HPKE.
Passthrough means destination in the clear; the body is ciphertext.
\sphinxAtStartPar
See companion \sphinxcode{\sphinxupquote{peergos\sphinxhyphen{}for\sphinxhyphen{}compliance.pdf}} (same folder) for
controls, custody, and variables chapters.
\href{peergos-for-compliance.pdf}{peergos-for-compliance.pdf}
\sphinxstepscope
\chapter{BAAs and DPAs when ciphertext has no host keys}
\label{\detokenize{baa-dpa:baas-and-dpas-when-ciphertext-has-no-host-keys}}\label{\detokenize{baa-dpa::doc}}
\sphinxAtStartPar
This is \sphinxstylestrong{guidance for an evidence pack}, not legal advice.
\section{The operator statement}
\label{\detokenize{baa-dpa:the-operator-statement}}
\sphinxAtStartPar
Data at rest lives in the \sphinxstylestrong{encrypted Peergos cryptree}. Restore uses
\sphinxstylestrong{distributed, hash\sphinxhyphen{}verified, encrypted IPFS blocks}. Hosts and backup
media see \sphinxstylestrong{opaque blobs} (and random CHAMP labels), not filenames, not
PHI, not social graph — if keys never leave the client / customer HSM.
\sphinxAtStartPar
That is \sphinxstylestrong{true of the Peergos design} (see {\hyperref[\detokenize{verification::doc}]{\sphinxcrossref{\DUrole{doc}{Peergos verification (what was actually audited)}}}}).
It \sphinxstylestrong{changes the BAA/DPA conversation}. It does \sphinxstylestrong{not} auto\sphinxhyphen{}delete the
need for contracts.
\section{HIPAA (US) — Business Associate}
\label{\detokenize{baa-dpa:hipaa-us-business-associate}}
\sphinxAtStartPar
A Business Associate is a person who \sphinxstylestrong{creates, receives, maintains, or
transmits ePHI} for a covered entity.
\sphinxAtStartPar
\sphinxstylestrong{Technical argument you can make (and should document):}
\begin{enumerate}
\sphinxsetlistlabels{\arabic}{enumi}{enumii}{}{.}%
\item {}
\sphinxAtStartPar
ePHI is encrypted \sphinxstylestrong{before} it leaves the endpoint (Peergos client /
DataCube writer).
\item {}
\sphinxAtStartPar
The storage node, IPFS, disk, and backup hold \sphinxstylestrong{ciphertext + hashes}.
\item {}
\sphinxAtStartPar
Private keys \sphinxstylestrong{do not} reside on the storage host (customer HSM /
client). Hash verification detects tampering.
\item {}
\sphinxAtStartPar
Therefore the host \sphinxstylestrong{cannot maintain ePHI in intelligible form}.
\end{enumerate}
\sphinxAtStartPar
HHS distinguishes \sphinxstylestrong{conduits} and parties that never have access to
ePHI. Many programs still \sphinxstylestrong{sign a BAA} when a vendor touches
infrastructure, because misconfiguration, support exports, or logs could
later expose plaintext. OCR looks at \sphinxstylestrong{your} risk analysis.
\sphinxAtStartPar
\sphinxstylestrong{Practical pack:} risk analysis memo citing cryptree + IPFS hash checks
+ key custody; BAA \sphinxstylestrong{or} written determination that the vendor is
\sphinxstylestrong{not} a BA because they cannot decrypt; list every party with
disk/backup (ns1, IPFS cluster, offsite replica).
\section{GDPR (EU/UK) — processor vs technical measure}
\label{\detokenize{baa-dpa:gdpr-eu-uk-processor-vs-technical-measure}}
\sphinxAtStartPar
Encrypted data can still be \sphinxstylestrong{personal data} if it is reasonably
attributable (usernames, IPs, invoice identity). GDPR \sphinxstylestrong{Art. 32} lists
encryption as a security measure.
\sphinxAtStartPar
Peergos is designed so the \sphinxstylestrong{server is an adversary} for content and
most metadata. EU\sphinxhyphen{}based \sphinxstylestrong{independent pentests} (Cure53 DE, ROS NL)
evaluated that design. Processing location for \sphinxstylestrong{self\sphinxhyphen{}host} is \sphinxstyleemphasis{your}
ns1 / customer region, not peergos.nets Germany hosting, unless you use
peergos.net.
\sphinxAtStartPar
You may still need a \sphinxstylestrong{DPA (Art. 28)} with anyone who \sphinxstylestrong{processes}
personal data (usernames, logs, billing). Ciphertext\sphinxhyphen{}only storage
\sphinxstylestrong{narrows} the DPAs technical annex.
\section{NATS operators}
\label{\detokenize{baa-dpa:nats-operators}}
\sphinxAtStartPar
NATS is an \sphinxstylestrong{untrusted broker}. Content is HPKE; destinations and
subjects are in the clear. A NATS operator \sphinxstylestrong{cannot} read bodies without
endpoint private keys; \sphinxstylestrong{can} see routing metadata; \sphinxstylestrong{can} drop/delay
copy \sphinxstylestrong{ciphertext}. Treat like a transit provider: DPA/BAA depends on
whether routing metadata is personal data in your jurisdiction.
\section{What “making yourself audit\sphinxhyphen{}ready” means}
\label{\detokenize{baa-dpa:what-making-yourself-audit-ready-means}}
\sphinxAtStartPar
You are \sphinxstylestrong{not} buying Peergoss Cure53/ROS reports as \sphinxstyleemphasis{your} SOC 2.
You are \sphinxstylestrong{reusing} those public evaluations as \sphinxstylestrong{vendor/component
assurance}, then adding your scope, RoPA, key\sphinxhyphen{}custody, inspect k\sphinxhyphen{}of\sphinxhyphen{}n,
admin\sphinxhyphen{}history, instance evidence, and contracts that match who can
actually see plaintext.
\sphinxstepscope
\chapter{Audit\sphinxhyphen{}ready checklist}
\label{\detokenize{checklist:audit-ready-checklist}}\label{\detokenize{checklist::doc}}
\sphinxAtStartPar
Use this as a working list. Check items only when \sphinxstylestrong{evidence exists}
(screenshot, log export, signed policy, ticket). This list is not a
certificate.
\section{A. Scope and data map}
\label{\detokenize{checklist:a-scope-and-data-map}}\begin{itemize}
\item {}
\sphinxAtStartPar
Named legal entity and systems in scope (console, Drive, NATS, IPFS, ns1)
\item {}
\sphinxAtStartPar
Data\sphinxhyphen{}flow diagram: endpoint \(\rightarrow\) HPKE/NATS \(\rightarrow\) cryptree/IPFS
\item {}
\sphinxAtStartPar
What is PHI / personal data vs ciphertext vs routing metadata
\item {}
\sphinxAtStartPar
Peergos verification chapter attached ({\hyperref[\detokenize{verification::doc}]{\sphinxcrossref{\DUrole{doc}{Peergos verification (what was actually audited)}}}})
\end{itemize}
\section{B. Keys and encryption}
\label{\detokenize{checklist:b-keys-and-encryption}}\begin{itemize}
\item {}
\sphinxAtStartPar
Customer holds Peergos/Drive keys; not on storage host
\item {}
\sphinxAtStartPar
NPE/HPKE endpoint keys in directory; private 0600; no xor content
\item {}
\sphinxAtStartPar
Signed Ed25519 config; unsigned rejected; admin\sphinxhyphen{}history prev+new+diff
\item {}
\sphinxAtStartPar
HSM or documented lab\sphinxhyphen{}to\sphinxhyphen{}HSM path
\end{itemize}
\section{C. Access}
\label{\detokenize{checklist:c-access}}\begin{itemize}
\item {}
\sphinxAtStartPar
Console \sphinxcode{\sphinxupquote{PFC\_REQUIRE\_AUTH=1}}, TOTP; Drive login separate
\item {}
\sphinxAtStartPar
Inspect k\sphinxhyphen{}of\sphinxhyphen{}n; author is not an officer; log\sphinxhyphen{}before\sphinxhyphen{}reveal
\item {}
\sphinxAtStartPar
Joiner / mover / leaver for console users
\item {}
\sphinxAtStartPar
Google SSO does \sphinxstylestrong{not} unwrap cubes
\end{itemize}
\section{D. Integrity and backup}
\label{\detokenize{checklist:d-integrity-and-backup}}\begin{itemize}
\item {}
\sphinxAtStartPar
Cube chain append\sphinxhyphen{}only JSONL; dual hash
\item {}
\sphinxAtStartPar
Hash registry: first SHA\sphinxhyphen{}256 and receipt win
\item {}
\sphinxAtStartPar
Peergos/IPFS: hash\sphinxhyphen{}verified encrypted blocks (restore = re\sphinxhyphen{}fetch CIDs)
\item {}
\sphinxAtStartPar
Restore test: recover a cube from content\sphinxhyphen{}addressed ciphertext without
plaintext backup tapes
\end{itemize}
\section{E. Logging}
\label{\detokenize{checklist:e-logging}}\begin{itemize}
\item {}
\sphinxAtStartPar
Inspect audit events
\item {}
\sphinxAtStartPar
SM summaries: codes + lookup\_id only (no bodies)
\item {}
\sphinxAtStartPar
Admin\sphinxhyphen{}history cube for config
\end{itemize}
\section{F. Contracts (counsel)}
\label{\detokenize{checklist:f-contracts-counsel}}\begin{itemize}
\item {}
\sphinxAtStartPar
Written BA / not\sphinxhyphen{}a\sphinxhyphen{}BA determination for disk, VM, backup, IPFS
\item {}
\sphinxAtStartPar
DPA Art. 28 where usernames/logs/IPs are processed
\item {}
\sphinxAtStartPar
NATS operator: metadata vs content in the annex
\item {}
\sphinxAtStartPar
Peergos component assurance: attach Cure53 2019 + ROS 2024 PDFs
(public; not your orgs ISO/SOC report)
\end{itemize}
\section{G. Independent audit of \sphinxstyleemphasis{you}}
\label{\detokenize{checklist:g-independent-audit-of-you}}\begin{itemize}
\item {}
\sphinxAtStartPar
SOC 2 Type I/II engagement \sphinxstylestrong{or} ISO 27001 registrar \sphinxstylestrong{or} HIPAA
risk analysis + policies (pick the program you actually need)
\item {}
\sphinxAtStartPar
Evidence window (Type II / surveillance) if applicable
\end{itemize}
\sphinxstepscope
\chapter{How to use this pack}
\label{\detokenize{howto:how-to-use-this-pack}}\label{\detokenize{howto::doc}}\begin{enumerate}
\sphinxsetlistlabels{\arabic}{enumi}{enumii}{}{.}%
\item {}
\sphinxAtStartPar
Read {\hyperref[\detokenize{verification::doc}]{\sphinxcrossref{\DUrole{doc}{Peergos verification (what was actually audited)}}}} so you do not over\sphinxhyphen{}claim Peergos audits.
\item {}
\sphinxAtStartPar
Fill {\hyperref[\detokenize{checklist::doc}]{\sphinxcrossref{\DUrole{doc}{Audit\sphinxhyphen{}ready checklist}}}} with \sphinxstylestrong{your} instance evidence (ns1, keys, users).
\item {}
\sphinxAtStartPar
Give {\hyperref[\detokenize{baa-dpa::doc}]{\sphinxcrossref{\DUrole{doc}{BAAs and DPAs when ciphertext has no host keys}}}} to counsel with the data\sphinxhyphen{}flow from {\hyperref[\detokenize{architecture::doc}]{\sphinxcrossref{\DUrole{doc}{Architecture (audit interview)}}}}.
\item {}
\sphinxAtStartPar
Point auditors at live technical surfaces (do not give them private keys).
\end{enumerate}
\begin{enumerate}
\sphinxsetlistlabels{\arabic}{enumi}{enumii}{}{.}%
\setcounter{enumi}{4}
\item {}
\sphinxAtStartPar
Attach the two \sphinxstylestrong{public} Peergos pentest PDFs from the Peergos
\sphinxcode{\sphinxupquote{audits/}} tree as \sphinxstylestrong{vendor security evaluations}, labeled “not our
SOC 2 / ISO certificate”.
\end{enumerate}
\sphinxAtStartPar
Companion system PDF (same folder):
\href{peergos-for-compliance.pdf}{peergos-for-compliance.pdf}
\chapter{What we verified about Peergos (EU)}
\label{\detokenize{index:what-we-verified-about-peergos-eu}}
\sphinxAtStartPar
See the full sourced table in {\hyperref[\detokenize{verification::doc}]{\sphinxcrossref{\DUrole{doc}{Peergos verification (what was actually audited)}}}}.
\begin{itemize}
\item {}
\sphinxAtStartPar
Encrypted client\sphinxhyphen{}side filesystem (cryptree); keys not on the storage
server — \sphinxstylestrong{yes} (Peergos book + Cure53 design review).
\item {}
\sphinxAtStartPar
IPFS blocks content\sphinxhyphen{}addressed; Peergos verifies hashes — \sphinxstylestrong{yes}.
\item {}
\sphinxAtStartPar
Independent \sphinxstylestrong{EU} security audits, reports published — \sphinxstylestrong{yes, two:}
Cure53 Berlin (2019); Radically Open Security Amsterdam (2024).
\item {}
\sphinxAtStartPar
“Peergos is HIPAA/SOC 2/ISO certified” — \sphinxstylestrong{no.} Those audits are
pentest/code/design reviews, not management\sphinxhyphen{}system certificates.
\end{itemize}
\sphinxAtStartPar
Peergos \sphinxstylestrong{was designed as a trust\sphinxhyphen{}minimized encrypted filesystem},
\sphinxstylestrong{evaluated in Europe} by two specialist firms, with \sphinxstylestrong{public reports}.
That supports the \sphinxstylestrong{at\sphinxhyphen{}rest / backup} story. It does \sphinxstylestrong{not} finish
\sphinxstyleemphasis{your} audit.
\sphinxAtStartPar
Companion PDFs in the \sphinxstylestrong{same directory} as this file (relative PDF
links, not Markdown):
\begin{itemize}
\item \href{peergos-for-compliance.pdf}{peergos-for-compliance.pdf}
\item \href{nats-service-endpoints.pdf}{nats-service-endpoints.pdf}
\item \href{secure-messaging.pdf}{secure-messaging.pdf}
\end{itemize}
\renewcommand{\indexname}{Index}
\printindex
\end{document}