Making yourself audit-ready with Verae DataCubes ================================================ How to **prepare an organization** for HIPAA-aligned, SOC 2, or ISO 27001 work using Verae DataCubes on **Peergos** (encrypted cryptree + hashed IPFS) and HPKE on an **untrusted NATS** broker. **This document is not a HIPAA, SOC 2, or ISO certificate.** Peergos’s public pentests are **not** your Type II or ISO registrar certificate. They are **component security evaluations** you can attach. .. toctree:: :maxdepth: 2 verification architecture baa-dpa checklist howto What we verified about Peergos (EU) ----------------------------------- See the full sourced table in :doc:`verification`. * Encrypted client-side filesystem (cryptree); keys not on the storage server — **yes** (Peergos book + Cure53 design review). * IPFS blocks content-addressed; Peergos verifies hashes — **yes**. * Independent **EU** security audits, reports published — **yes, two:** Cure53 Berlin (2019); Radically Open Security Amsterdam (2024). * “Peergos is HIPAA/SOC 2/ISO certified” — **no.** Those audits are pentest/code/design reviews, not management-system certificates. Peergos **was designed as a trust-minimized encrypted filesystem**, **evaluated in Europe** by two specialist firms, with **public reports**. That supports the **at-rest / backup** story. It does **not** finish *your* audit. .. only:: html Live technical surfaces: * https://pfc.georgelambert.org/health * https://pfc.georgelambert.org/v1/npe/keys * https://docs.pfc.georgelambert.org/controls.html * https://git.georgelambert.org/marchon/peergos-making-yourself-audit-ready-with-verae-datacubes Companion system docs (HTML): https://docs.pfc.georgelambert.org/ .. only:: latex Companion PDFs in the **same directory** as this file (relative PDF links, not Markdown): .. raw:: latex \begin{itemize} \item \href{peergos-for-compliance.pdf}{peergos-for-compliance.pdf} \item \href{nats-service-endpoints.pdf}{nats-service-endpoints.pdf} \item \href{secure-messaging.pdf}{secure-messaging.pdf} \end{itemize}