Audit-ready checklist ===================== Use this as a working list. Check items only when **evidence exists** (screenshot, log export, signed policy, ticket). This list is not a certificate. A. Scope and data map --------------------- * Named legal entity and systems in scope (console, Drive, NATS, IPFS, ns1) * Data-flow diagram: endpoint → HPKE/NATS → cryptree/IPFS * What is PHI / personal data vs ciphertext vs routing metadata * Peergos verification chapter attached (:doc:`verification`) B. Keys and encryption ---------------------- * Customer holds Peergos/Drive keys; not on storage host * NPE/HPKE endpoint keys in directory; private 0600; no xor content * Signed Ed25519 config; unsigned rejected; admin-history prev+new+diff * HSM or documented lab-to-HSM path C. Access --------- * Console ``PFC_REQUIRE_AUTH=1``, TOTP; Drive login separate * Inspect k-of-n; author is not an officer; log-before-reveal * Joiner / mover / leaver for console users * Google SSO does **not** unwrap cubes D. Integrity and backup ----------------------- * Cube chain append-only JSONL; dual hash * Hash registry: first SHA-256 and receipt win * Peergos/IPFS: hash-verified encrypted blocks (restore = re-fetch CIDs) * Restore test: recover a cube from content-addressed ciphertext without plaintext backup tapes E. Logging ---------- * Inspect audit events * SM summaries: codes + lookup_id only (no bodies) * Admin-history cube for config F. Contracts (counsel) ---------------------- * Written BA / not-a-BA determination for disk, VM, backup, IPFS * DPA Art. 28 where usernames/logs/IPs are processed * NATS operator: metadata vs content in the annex * Peergos component assurance: attach Cure53 2019 + ROS 2024 PDFs (public; not your org’s ISO/SOC report) G. Independent audit of *you* ----------------------------- * SOC 2 Type I/II engagement **or** ISO 27001 registrar **or** HIPAA risk analysis + policies (pick the program you actually need) * Evidence window (Type II / surveillance) if applicable