Audit-ready checklist ===================== Use this as a working list. Check an item only when **evidence exists** (screenshot, log export, signed policy, ticket, receipt). This list is not a certificate. Software having been installed does not tick these boxes. A. Scope and honesty -------------------- * Named legal entity and systems in scope (console, Drive, message fabric, IPFS, timestamping link, Iceberg archive) * Written sentence in the system description: **software is not our HIPAA / SOC 2 / ISO 27001 certificate** * Data-flow diagram: endpoint → HPKE → DataCube → Peergos/IPFS → receipt → Iceberg * PHI / personal data vs ciphertext vs routing metadata, named * Peergos evaluation chapter attached, labeled **component security evaluation** B. Data in transit ------------------ * Production algorithm is HPKE (or documented successor), not a lab construction * Destinations and subjects documented as **visible by design** * Error paths carry codes and lookup ids, not bodies * Public-key directory lists public keys only; private keys mode 0600 or HSM * Broker operator named; metadata vs content in the annex C. Data at rest --------------- * Customer holds Peergos / Drive keys; not on storage host * Peergos hash verification on write and on read, evidenced * Restore test: recover a cube from content-addressed ciphertext **without** a plaintext tape * Dual-hash cube chain; first-hash-wins registry D. Timestamping --------------- * First-registration rule documented and tested (second submit returns original receipt) * Organizational node **linked** to central Verae, **or** direct sync, named in the diagram * Sample bundle: receipt + private metadata + attachment pointer, redacted for the evidence pack * Verae receives fingerprints, not objects --- stated in the data map E. Write-once archive --------------------- * Iceberg (or equivalent) export job exists and has a dated last-run * Object-lock / dual-control / separate account --- evidence that no **single** party can delete a committed snapshot * Retention schedule written by records/counsel, not by engineering folklore * Legal-hold procedure extends retention; ticket example F. Access and change -------------------- * Console requires authentication (TOTP or equivalent); Drive login is a separate plane * Inspect is k-of-n; author is not an officer; log-before-reveal * Joiner / mover / leaver for console users * Signed configuration; unsigned rejected; admin-history prev + new + diff * HSM or a dated plan to move lab keys to HSM G. Contracts (counsel) ---------------------- * Written BA / not-a-BA determination for disk, VM, backup, IPFS, Iceberg * DPA Article 28 where usernames, logs, or IPs are processed * NATS operator: metadata vs content * Verae timestamping: fingerprint-only processing described * Peergos PDFs attached and labeled "not our Type II / ISO" H. Independent examination of *this* organization ------------------------------------------------- * SOC 2 Type I/II engagement, **or** ISO 27001 registrar, **or** HIPAA risk analysis plus policies --- **the program actually chosen**, not all three as wallpaper * Evidence window (Type II / surveillance) if applicable * Named internal owner who will sit in the meeting and not claim the software is the certificate