Some checks are pending
ci / markdown (push) Waiting to run
Open with an executive summary that HIPAA, SOC 2, and ISO 27001 are organizational programs. Verae DataCubes supply store, communicate, timestamp, verify, and audit tools for the technical portion only. Chapters cover transit (HPKE, visible routing), rest (IPFS/Peergos hash-verified restore), receipts, EU Peergos evaluations (Cure53 2019, ROS 2024), cross-blockchain timestamping, and write-once Iceberg archive. PDF is branded with the Verae logo top-left and Verae Inc contact in the footer; last chapters are sourced bios for Garfinkel (FINRA CRD 5052743), Haber, and Lambert.
241 lines
No EOL
12 KiB
HTML
241 lines
No EOL
12 KiB
HTML
<!DOCTYPE html>
|
||
|
||
<html lang="en" data-content_root="./">
|
||
<head>
|
||
<meta charset="utf-8" />
|
||
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
|
||
|
||
<title>3. The Verae DataCube Server Solution — Making yourself audit-ready with Verae DataCubes</title>
|
||
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
|
||
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
|
||
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
|
||
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
|
||
<script src="_static/documentation_options.js?v=250a654d"></script>
|
||
<script src="_static/doctools.js?v=fd6eb6e6"></script>
|
||
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
|
||
<link rel="icon" href="_static/VeraeFullLogo.png"/>
|
||
<link rel="index" title="Index" href="genindex.html" />
|
||
<link rel="search" title="Search" href="search.html" />
|
||
<link rel="next" title="4. Secure communications — data in transit" href="data-in-transit.html" />
|
||
<link rel="prev" title="2. What Verae provides — and what it does not" href="what-verae-provides.html" />
|
||
|
||
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
|
||
|
||
|
||
|
||
|
||
|
||
</head><body>
|
||
<div class="document">
|
||
|
||
<div class="sphinxsidebar" role="navigation" aria-label="Main">
|
||
<div class="sphinxsidebarwrapper">
|
||
<p class="logo"><a href="index.html">
|
||
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo of Making yourself audit-ready with Verae DataCubes"/>
|
||
</a></p>
|
||
<p class="logo">
|
||
<a href="index.html">
|
||
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo" />
|
||
|
||
</a>
|
||
</p>
|
||
|
||
|
||
|
||
<p class="blurb">Tools for storage, communications, timestamping, verification, and audit — not a certificate.</p>
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
<search id="searchbox" style="display: none" role="search">
|
||
<div class="searchformwrapper">
|
||
<form class="search" action="search.html" method="get">
|
||
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false" placeholder="Search"/>
|
||
<input type="submit" value="Go" />
|
||
</form>
|
||
</div>
|
||
</search>
|
||
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
|
||
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
|
||
<ul class="current">
|
||
<li class="toctree-l1"><a class="reference internal" href="executive.html">1. Executive summary</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
|
||
<li class="toctree-l1 current"><a class="current reference internal" href="#">3. The Verae DataCube Server Solution</a><ul>
|
||
<li class="toctree-l2"><a class="reference internal" href="#purpose">3.1. Purpose</a></li>
|
||
<li class="toctree-l2"><a class="reference internal" href="#the-datacube-as-a-container">3.2. The DataCube as a container</a></li>
|
||
<li class="toctree-l2"><a class="reference internal" href="#two-information-states-one-operational-picture">3.3. Two information states, one operational picture</a></li>
|
||
<li class="toctree-l2"><a class="reference internal" href="#what-server-means-in-practice">3.4. What “server” means in practice</a></li>
|
||
<li class="toctree-l2"><a class="reference internal" href="#what-the-server-solution-is-not">3.5. What the server solution is not</a></li>
|
||
</ul>
|
||
</li>
|
||
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">6. Global timestamped receipts</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">7. Peergos security evaluations in Europe</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">8. Verae global timestamping — a cross-blockchain receipt</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="checklist.html">12. Audit-ready checklist</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="howto.html">13. How to use this briefing</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">15. Stuart Haber</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
|
||
</ul>
|
||
|
||
<div class="relations">
|
||
<h3>Related Topics</h3>
|
||
<ul>
|
||
<li><a href="index.html">Documentation overview</a><ul>
|
||
<li>Previous: <a href="what-verae-provides.html" title="previous chapter"><span class="section-number">2. </span>What Verae provides — and what it does not</a></li>
|
||
<li>Next: <a href="data-in-transit.html" title="next chapter"><span class="section-number">4. </span>Secure communications — data in transit</a></li>
|
||
</ul></li>
|
||
</ul>
|
||
</div>
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
</div>
|
||
</div>
|
||
<div class="documentwrapper">
|
||
<div class="bodywrapper">
|
||
|
||
|
||
<div class="body" role="main">
|
||
|
||
<section id="the-verae-datacube-server-solution">
|
||
<h1><span class="section-number">3. </span>The Verae DataCube Server Solution<a class="headerlink" href="#the-verae-datacube-server-solution" title="Link to this heading">¶</a></h1>
|
||
<section id="purpose">
|
||
<h2><span class="section-number">3.1. </span>Purpose<a class="headerlink" href="#purpose" title="Link to this heading">¶</a></h2>
|
||
<p>A Verae DataCube Server Solution is the on-premises or
|
||
customer-hosted assembly that gives an organization a place to put
|
||
sensitive digital objects, a way to move them, a way to prove when
|
||
they first existed, and a way to show an examiner that the bits
|
||
have not been silently rewritten.</p>
|
||
<p>It is a <strong>server solution</strong> in the sense that an organization runs
|
||
(or has run for it) a set of cooperating services: encrypted
|
||
storage, a message fabric, a public-key directory, a timestamping
|
||
link to Verae’s central service, and an archival export path. It is
|
||
not a single binary, and it is not a cloud folder with a padlock
|
||
icon.</p>
|
||
</section>
|
||
<section id="the-datacube-as-a-container">
|
||
<h2><span class="section-number">3.2. </span>The DataCube as a container<a class="headerlink" href="#the-datacube-as-a-container" title="Link to this heading">¶</a></h2>
|
||
<p>A <strong>DataCube</strong> is a customer-controlled container for digital
|
||
objects and for the metadata that makes those objects examinable.
|
||
Typical contents include:</p>
|
||
<ul class="simple">
|
||
<li><p>the object bytes (a message body, a document, an image, a log
|
||
extract, an AI prompt and completion, or any other digital
|
||
media);</p></li>
|
||
<li><p><strong>private metadata</strong> that the organization needs but does not
|
||
necessarily share (internal identifiers, matter numbers, legal-hold
|
||
flags);</p></li>
|
||
<li><p><strong>attached files</strong> that travel with the object;</p></li>
|
||
<li><p>an <strong>internal chain</strong> of hashes so that the cube itself has a
|
||
history — each new write names the previous write.</p></li>
|
||
</ul>
|
||
<p>Verae’s public product description is consistent with this split:
|
||
records stay in <strong>storage the customer controls</strong>; Verae seals a
|
||
<strong>fingerprint</strong>. The server solution is the machinery that makes
|
||
that split operational rather than rhetorical.</p>
|
||
</section>
|
||
<section id="two-information-states-one-operational-picture">
|
||
<h2><span class="section-number">3.3. </span>Two information states, one operational picture<a class="headerlink" href="#two-information-states-one-operational-picture" title="Link to this heading">¶</a></h2>
|
||
<p>Classical security training divides information into <strong>data in
|
||
transit</strong> and <strong>data at rest</strong>. The DataCube Server Solution is
|
||
built around that division.</p>
|
||
<p><strong>In transit</strong>, the problem is an untrusted network. Messages must
|
||
be readable at the destination and nowhere else along the path, yet
|
||
the path must still be able to deliver them. Chapter 4 treats that
|
||
problem in full: point-to-point encryption, visible routing,
|
||
honest-but-curious brokers.</p>
|
||
<p><strong>At rest</strong>, the problem is an untrusted disk, an untrusted backup
|
||
operator, and an untrusted replica. Bytes must be stored so that a
|
||
host who does not hold keys sees opaque blocks, and so that a
|
||
restore can prove it brought back the same blocks that were
|
||
written. Chapter 5 treats that problem in full: IPFS
|
||
content-addressed ciphertext, Peergos hash verification,
|
||
tamper-evident restore.</p>
|
||
<p>A third problem sits beside those two: <strong>time</strong>. Storage and transit
|
||
prove confidentiality and integrity of <em>what</em> was stored or sent.
|
||
They do not, by themselves, prove <em>when</em> it first existed, or that
|
||
a later rewrite is not being offered as the original. Timestamped
|
||
receipts (Chapter 6) and the cross-blockchain timestamping
|
||
architecture (Chapter 8) address that.</p>
|
||
</section>
|
||
<section id="what-server-means-in-practice">
|
||
<h2><span class="section-number">3.4. </span>What “server” means in practice<a class="headerlink" href="#what-server-means-in-practice" title="Link to this heading">¶</a></h2>
|
||
<p>In a typical deployment the organization runs, or links:</p>
|
||
<ul class="simple">
|
||
<li><p>a <strong>Peergos</strong> instance (or equivalent cryptree client) that
|
||
writes encrypted, content-addressed blocks;</p></li>
|
||
<li><p>an <strong>IPFS</strong> layer that stores and replicates those blocks by
|
||
hash;</p></li>
|
||
<li><p>a <strong>message fabric</strong> (NATS in the reference deployment) that
|
||
carries HPKE-sealed bodies with destinations in the clear;</p></li>
|
||
<li><p>a <strong>public-key directory</strong> so every endpoint can find every
|
||
other endpoint’s encryption key without a private-key leak;</p></li>
|
||
<li><p>an <strong>organizational timestamping node</strong> that either syncs with
|
||
Verae’s central timestamping server or is linked to it;</p></li>
|
||
<li><p>an <strong>admin-history</strong> cube that records configuration changes as
|
||
previous state, new state, and diff;</p></li>
|
||
<li><p>an <strong>Iceberg write-once export</strong> that takes cubes out of any
|
||
single party’s delete path (Chapter 9).</p></li>
|
||
</ul>
|
||
<p>Each of those pieces can be drawn on a whiteboard in an audit
|
||
interview. Each of them also has a failure mode that the
|
||
organization’s procedures must name: lost keys, a mis-issued
|
||
directory entry, a broker that drops messages, a replica that
|
||
serves a wrong block (detected by hash), a timestamping link that
|
||
is down, an archive job that did not run.</p>
|
||
</section>
|
||
<section id="what-the-server-solution-is-not">
|
||
<h2><span class="section-number">3.5. </span>What the server solution is not<a class="headerlink" href="#what-the-server-solution-is-not" title="Link to this heading">¶</a></h2>
|
||
<p>It is not a substitute for workforce training. It is not a
|
||
substitute for a Business Associate Agreement analysis. It is not a
|
||
substitute for access reviews. It is not, by itself, “the HIPAA
|
||
control set” or “the SOC 2 system.” It is the <strong>technical
|
||
substrate</strong> on which those controls can be implemented with less
|
||
faith in honest administrators and more reliance on hashes,
|
||
receipts, and keys the customer holds.</p>
|
||
<p>The following four chapters unpack the substrate: transit, rest,
|
||
receipts, and the European evaluations of the Peergos storage
|
||
layer.</p>
|
||
</section>
|
||
</section>
|
||
|
||
|
||
</div>
|
||
|
||
</div>
|
||
</div>
|
||
<div class="clearer"></div>
|
||
</div>
|
||
<div class="verae-page-footer">
|
||
<strong>Verae Inc</strong>
|
||
· <a href="https://www.verae.com">https://www.verae.com</a>
|
||
· Book a call at <a href="https://www.verae.com">verae.com</a>
|
||
· <a href="https://app.verae.com">app.verae.com</a>
|
||
</div>
|
||
|
||
<div class="footer">
|
||
©2026, Verae Inc.
|
||
|
||
</div>
|
||
|
||
|
||
|
||
|
||
|
||
</body>
|
||
</html> |