How to use this briefing ======================== 1. Read the **executive summary** aloud in the first five minutes of any vendor, board, or auditor meeting that touches this system. If anyone says "so we are certified," stop and reread Chapter 1. 2. Read **What Verae provides** so the five verbs (store, communicate, timestamp, verify, audit) are not confused with an ISMS, a Type II, or a HIPAA program. 3. Read the **transit**, **rest**, **receipts**, **Peergos evaluations**, **timestamping**, and **Iceberg** chapters in that order. They are the technical portion, in the order an examiner usually probes: "can the wire read it, can the disk read it, can you prove when, who looked at the crypto, can you produce it later." 4. Fill the **checklist** with **this instance's** evidence. Empty checkboxes are not a moral failing; they are the work remaining. 5. Give **BAAs and DPAs** to counsel with the architecture diagram. Do not let engineering declare a vendor "not a BA." 6. Attach the two **public** Peergos reports as **vendor security evaluations**, with a cover slip that says they are not the organization's SOC 2, ISO 27001, or HIPAA certification. 7. Point auditors at **live technical surfaces** (health, public-key listing, Drive). Do not give them private keys. Do not give them a story that the pentest PDF is the Type II. 8. Keep the **biographies** at the back of the PDF for provenance --- who built the timestamping science, who is building the product, who architected the internet integration and the DataCube server side --- without substituting biography for controls. .. only:: html Reference instance (not a certificate): * https://pfc.georgelambert.org/health * https://pfc.georgelambert.org/v1/npe/keys (public keys only) * https://docs.pfc.georgelambert.org/controls.html * https://docs.pfc.georgelambert.org/custody.html * https://git.georgelambert.org/marchon/peergos-making-yourself-audit-ready-with-verae-datacubes * https://www.verae.com .. only:: latex Companion system PDFs in the same folder: .. raw:: latex \begin{itemize} \item \href{peergos-for-compliance.pdf}{peergos-for-compliance.pdf} \item \href{nats-service-endpoints.pdf}{nats-service-endpoints.pdf} \item \href{secure-messaging.pdf}{secure-messaging.pdf} \end{itemize}