peergos-making-yourself-aud.../build/html/index.html
George Lambert 8496ef8338
Some checks are pending
ci / markdown (push) Waiting to run
Put the executive summary on page 2, before the table of contents.
The cover stays page 1. Numbered chapters now start at What Verae
provides. The TOC lists Executive summary at page 2.
2026-09-16 01:21:05 -04:00

299 lines
No EOL
22 KiB
HTML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!DOCTYPE html>
<html lang="en" data-content_root="./">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>Making yourself audit-ready with Verae DataCubes &#8212; Making yourself audit-ready with Verae DataCubes</title>
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=2d7b7068" />
<script src="_static/documentation_options.js?v=250a654d"></script>
<script src="_static/doctools.js?v=fd6eb6e6"></script>
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
<link rel="icon" href="_static/VeraeFullLogo.png"/>
<link rel="index" title="Index" href="genindex.html" />
<link rel="search" title="Search" href="search.html" />
<link rel="next" title="1. What Verae provides — and what it does not" href="what-verae-provides.html" />
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
</head><body>
<div class="document">
<div class="sphinxsidebar" role="navigation" aria-label="Main">
<div class="sphinxsidebarwrapper">
<p class="logo"><a href="#">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo of Making yourself audit-ready with Verae DataCubes"/>
</a></p>
<p class="logo">
<a href="#">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo" />
</a>
</p>
<p class="blurb">Tools for storage, communications, timestamping, verification, and audit — not a certificate.</p>
<search id="searchbox" style="display: none" role="search">
<div class="searchformwrapper">
<form class="search" action="search.html" method="get">
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false" placeholder="Search"/>
<input type="submit" value="Go" />
</form>
</div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">1. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">2. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">3. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">4. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">5. Global timestamped receipts</a></li>
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">6. Peergos security evaluations in Europe</a></li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">7. Verae global timestamping — a cross-blockchain receipt</a></li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">8. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">9. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">10. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">11. Audit-ready checklist</a></li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">12. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">13. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">14. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">15. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">16. Verae Inc — contact</a></li>
</ul>
<div class="relations">
<h3>Related Topics</h3>
<ul>
<li><a href="#">Documentation overview</a><ul>
<li>Next: <a href="what-verae-provides.html" title="next chapter"><span class="section-number">1. </span>What Verae provides — and what it does not</a></li>
</ul></li>
</ul>
</div>
</div>
</div>
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="making-yourself-audit-ready-with-verae-datacubes">
<h1>Making yourself audit-ready with Verae DataCubes<a class="headerlink" href="#making-yourself-audit-ready-with-verae-datacubes" title="Link to this heading"></a></h1>
<a class="logo reference internal image-reference" href="_images/VeraeFullLogo.png"><img alt="Verae" class="logo" src="_images/VeraeFullLogo.png" style="width: 280px;" />
</a>
<p>Software alone does not make an organization HIPAA certified, SOC 2
attested, or ISO 27001 certified.</p>
<p>That sentence is the point of this document. It is also the sentence
that is most often skipped when a vendor, an integrator, or an internal
champion shows encryption, hashing, or a pentest PDF and treats the
conversation as finished. It is not finished. Encryption is a control.
A pentest is an evaluation of a component. A certificate, an attestation,
or a covered-entity determination is a statement about <strong>an organization</strong>
— its legal entity, its people, its written policies, its operating
procedures, its internal controls, the evidence those controls produce,
and the independent party that examined that evidence.</p>
<p>The Verae DataCube Solution gives an organization tools to <strong>store</strong>,
<strong>communicate</strong>, <strong>timestamp</strong>, <strong>verify</strong>, and <strong>audit</strong> for compliance.
Those tools are real, they are specific, and they are described in the
chapters that follow. They are still only tools. To obtain HIPAA-aligned
status as a covered entity or business associate with a defensible
program, a SOC 2 Type I or Type II report, or an ISO 27001 certificate,
the organization must still:</p>
<ul class="simple">
<li><p>write and live by <strong>policies</strong> (what the organization says it will do);</p></li>
<li><p>operate <strong>procedures</strong> (how staff actually do it, every day);</p></li>
<li><p>design and test <strong>internal controls</strong> (the checks that catch failure);</p></li>
<li><p>retain <strong>evidence</strong> (logs, tickets, screenshots, signed approvals,
restore tests, training records);</p></li>
<li><p>engage an <strong>independent auditor</strong>, CPA firm, or ISO registrar, as the
chosen program requires.</p></li>
</ul>
<p>Verae cannot issue those certificates. Verae cannot sit in the
organizations chair during an OCR investigation, a SOC 2 fieldwork
week, or an ISO Stage 2 audit. What Verae can do — and what this
briefing is written to make precise — is provide the <strong>tools</strong>, the
<strong>background</strong>, and the <strong>software infrastructure</strong> that make it easier
to implement the <strong>technical portion</strong> of those programs.</p>
<div class="toctree-wrapper compound">
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">1. What Verae provides — and what it does not</a><ul>
<li class="toctree-l2"><a class="reference internal" href="what-verae-provides.html#the-boundary">1.1. The boundary</a></li>
<li class="toctree-l2"><a class="reference internal" href="what-verae-provides.html#the-tools">1.2. The tools</a></li>
<li class="toctree-l2"><a class="reference internal" href="what-verae-provides.html#what-the-organization-must-still-do">1.3. What the organization must still do</a></li>
<li class="toctree-l2"><a class="reference internal" href="what-verae-provides.html#why-the-distinction-matters-in-an-exam">1.4. Why the distinction matters in an exam</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">2. The Verae DataCube Server Solution</a><ul>
<li class="toctree-l2"><a class="reference internal" href="datacube-server.html#purpose">2.1. Purpose</a></li>
<li class="toctree-l2"><a class="reference internal" href="datacube-server.html#the-datacube-as-a-container">2.2. The DataCube as a container</a></li>
<li class="toctree-l2"><a class="reference internal" href="datacube-server.html#two-information-states-one-operational-picture">2.3. Two information states, one operational picture</a></li>
<li class="toctree-l2"><a class="reference internal" href="datacube-server.html#what-server-means-in-practice">2.4. What “server” means in practice</a></li>
<li class="toctree-l2"><a class="reference internal" href="datacube-server.html#what-the-server-solution-is-not">2.5. What the server solution is not</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">3. Secure communications — data in transit</a><ul>
<li class="toctree-l2"><a class="reference internal" href="data-in-transit.html#the-problem">3.1. The problem</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-in-transit.html#point-to-point-encryption">3.2. Point-to-point encryption</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-in-transit.html#visible-routing">3.3. Visible routing</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-in-transit.html#error-handling-without-leaking-content">3.4. Error handling without leaking content</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-in-transit.html#the-public-key-directory">3.5. The public-key directory</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-in-transit.html#what-this-does-and-does-not-satisfy">3.6. What this does, and does not, satisfy</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">4. Encryption at rest — IPFS blocks and Peergos</a><ul>
<li class="toctree-l2"><a class="reference internal" href="data-at-rest.html#the-problem">4.1. The problem</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-at-rest.html#content-addressed-blocks">4.2. Content-addressed blocks</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-at-rest.html#peergos-on-top-of-ipfs">4.3. Peergos on top of IPFS</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-at-rest.html#tamper-evident-restore">4.4. Tamper-evident restore</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-at-rest.html#append-only-at-the-cube-layer">4.5. Append-only at the cube layer</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-at-rest.html#what-a-disk-operator-sees">4.6. What a disk operator sees</a></li>
<li class="toctree-l2"><a class="reference internal" href="data-at-rest.html#what-this-does-and-does-not-satisfy">4.7. What this does, and does not, satisfy</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">5. Global timestamped receipts</a><ul>
<li class="toctree-l2"><a class="reference internal" href="timestamped-receipts.html#why-hashes-are-not-enough-by-themselves">5.1. Why hashes are not enough by themselves</a></li>
<li class="toctree-l2"><a class="reference internal" href="timestamped-receipts.html#what-a-verae-receipt-is">5.2. What a Verae receipt is</a></li>
<li class="toctree-l2"><a class="reference internal" href="timestamped-receipts.html#what-is-registered-and-what-is-not">5.3. What is registered, and what is not</a></li>
<li class="toctree-l2"><a class="reference internal" href="timestamped-receipts.html#first-registration-wins">5.4. First registration wins</a></li>
<li class="toctree-l2"><a class="reference internal" href="timestamped-receipts.html#sequence">5.5. Sequence</a></li>
<li class="toctree-l2"><a class="reference internal" href="timestamped-receipts.html#bundles">5.6. Bundles</a></li>
<li class="toctree-l2"><a class="reference internal" href="timestamped-receipts.html#what-a-receipt-does-not-prove">5.7. What a receipt does not prove</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">6. Peergos security evaluations in Europe</a><ul>
<li class="toctree-l2"><a class="reference internal" href="peergos-eu-evaluations.html#what-was-evaluated">6.1. What was evaluated</a></li>
<li class="toctree-l2"><a class="reference internal" href="peergos-eu-evaluations.html#cure53-berlin-germany">6.2. 2019 — Cure53, Berlin, Germany</a></li>
<li class="toctree-l2"><a class="reference internal" href="peergos-eu-evaluations.html#radically-open-security-b-v-amsterdam">6.3. 2024 — Radically Open Security B.V., Amsterdam</a></li>
<li class="toctree-l2"><a class="reference internal" href="peergos-eu-evaluations.html#how-to-present-these-reports-to-an-auditor">6.4. How to present these reports to an auditor</a></li>
<li class="toctree-l2"><a class="reference internal" href="peergos-eu-evaluations.html#hosted-peergos-versus-self-hosted-datacubes">6.5. Hosted Peergos versus self-hosted DataCubes</a></li>
<li class="toctree-l2"><a class="reference internal" href="peergos-eu-evaluations.html#what-designed-under-funding-from-cure53-ros-is-not">6.6. What “designed under funding from Cure53 / ROS” is not</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">7. Verae global timestamping — a cross-blockchain receipt</a><ul>
<li class="toctree-l2"><a class="reference internal" href="global-timestamping.html#lineage">7.1. Lineage</a></li>
<li class="toctree-l2"><a class="reference internal" href="global-timestamping.html#what-cross-blockchain-means-here">7.2. What “cross-blockchain” means here</a></li>
<li class="toctree-l2"><a class="reference internal" href="global-timestamping.html#two-deployment-patterns">7.3. Two deployment patterns</a></li>
<li class="toctree-l2"><a class="reference internal" href="global-timestamping.html#the-digital-bundle">7.4. The digital bundle</a></li>
<li class="toctree-l2"><a class="reference internal" href="global-timestamping.html#proof-of-existence-versus-proof-of-custody">7.5. Proof of existence versus proof of custody</a></li>
<li class="toctree-l2"><a class="reference internal" href="global-timestamping.html#what-this-does-and-does-not-satisfy">7.6. What this does, and does not, satisfy</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">8. Write-once Iceberg archive</a><ul>
<li class="toctree-l2"><a class="reference internal" href="iceberg-archive.html#the-deletion-problem">8.1. The deletion problem</a></li>
<li class="toctree-l2"><a class="reference internal" href="iceberg-archive.html#what-write-once-iceberg-means-in-this-solution">8.2. What “write-once Iceberg” means in this solution</a></li>
<li class="toctree-l2"><a class="reference internal" href="iceberg-archive.html#how-cubes-move-into-the-archive">8.3. How cubes move into the archive</a></li>
<li class="toctree-l2"><a class="reference internal" href="iceberg-archive.html#relation-to-classical-worm">8.4. Relation to classical WORM</a></li>
<li class="toctree-l2"><a class="reference internal" href="iceberg-archive.html#what-this-does-and-does-not-satisfy">8.5. What this does, and does not, satisfy</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">9. Architecture for an audit interview</a><ul>
<li class="toctree-l2"><a class="reference internal" href="architecture.html#the-picture">9.1. The picture</a></li>
<li class="toctree-l2"><a class="reference internal" href="architecture.html#walkthrough-in-the-order-an-examiner-usually-asks">9.2. Walkthrough, in the order an examiner usually asks</a></li>
<li class="toctree-l2"><a class="reference internal" href="architecture.html#identity-planes">9.3. Identity planes</a></li>
<li class="toctree-l2"><a class="reference internal" href="architecture.html#nats-remains-untrusted">9.4. NATS remains untrusted</a></li>
<li class="toctree-l2"><a class="reference internal" href="architecture.html#what-to-hand-the-examiner">9.5. What to hand the examiner</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">10. BAAs, DPAs, and ciphertext without host keys</a><ul>
<li class="toctree-l2"><a class="reference internal" href="baa-dpa.html#the-technical-fact">10.1. The technical fact</a></li>
<li class="toctree-l2"><a class="reference internal" href="baa-dpa.html#hipaa-business-associate">10.2. HIPAA — Business Associate</a></li>
<li class="toctree-l2"><a class="reference internal" href="baa-dpa.html#gdpr-processor-versus-technical-measure">10.3. GDPR — processor versus technical measure</a></li>
<li class="toctree-l2"><a class="reference internal" href="baa-dpa.html#nats-operators">10.4. NATS operators</a></li>
<li class="toctree-l2"><a class="reference internal" href="baa-dpa.html#verae-as-timestamping-service">10.5. Verae as timestamping service</a></li>
<li class="toctree-l2"><a class="reference internal" href="baa-dpa.html#component-assurance-versus-the-organization-s-report">10.6. Component assurance versus the organizations report</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">11. Audit-ready checklist</a><ul>
<li class="toctree-l2"><a class="reference internal" href="checklist.html#a-scope-and-honesty">11.1. A. Scope and honesty</a></li>
<li class="toctree-l2"><a class="reference internal" href="checklist.html#b-data-in-transit">11.2. B. Data in transit</a></li>
<li class="toctree-l2"><a class="reference internal" href="checklist.html#c-data-at-rest">11.3. C. Data at rest</a></li>
<li class="toctree-l2"><a class="reference internal" href="checklist.html#d-timestamping">11.4. D. Timestamping</a></li>
<li class="toctree-l2"><a class="reference internal" href="checklist.html#e-write-once-archive">11.5. E. Write-once archive</a></li>
<li class="toctree-l2"><a class="reference internal" href="checklist.html#f-access-and-change">11.6. F. Access and change</a></li>
<li class="toctree-l2"><a class="reference internal" href="checklist.html#g-contracts-counsel">11.7. G. Contracts (counsel)</a></li>
<li class="toctree-l2"><a class="reference internal" href="checklist.html#h-independent-examination-of-this-organization">11.8. H. Independent examination of <em>this</em> organization</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">12. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">13. James H. Garfinkel</a><ul>
<li class="toctree-l2"><a class="reference internal" href="bio-james-garfinkel.html#name-and-sources">13.1. Name and sources</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-james-garfinkel.html#role-at-verae">13.2. Role at Verae</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-james-garfinkel.html#finra-brokercheck-crd-5052743">13.3. FINRA BrokerCheck (CRD 5052743)</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-james-garfinkel.html#education-public-professional-listings">13.4. Education (public professional listings)</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-james-garfinkel.html#why-this-biography-is-in-the-briefing">13.5. Why this biography is in the briefing</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">14. Stuart Haber</a><ul>
<li class="toctree-l2"><a class="reference internal" href="bio-stuart-haber.html#role-at-verae">14.1. Role at Verae</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-stuart-haber.html#the-scientific-work">14.2. The scientific work</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-stuart-haber.html#surety-1994-first-commercial-blockchain">14.3. Surety, 1994: first commercial blockchain</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-stuart-haber.html#other-cryptographic-publications">14.4. Other cryptographic publications</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-stuart-haber.html#why-this-biography-is-in-the-briefing">14.5. Why this biography is in the briefing</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">15. George Lambert</a><ul>
<li class="toctree-l2"><a class="reference internal" href="bio-george-lambert.html#role">15.1. Role</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-george-lambert.html#internet-technical-architect-from-1994">15.2. Internet technical architect, from 1994</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-george-lambert.html#new-hampshire-public-office">15.3. New Hampshire public office</a></li>
<li class="toctree-l2"><a class="reference internal" href="bio-george-lambert.html#why-this-biography-is-in-the-briefing">15.4. Why this biography is in the briefing</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">16. Verae Inc — contact</a><ul>
<li class="toctree-l2"><a class="reference internal" href="contact.html#closing-reminder">16.1. Closing reminder</a></li>
</ul>
</li>
</ul>
</div>
</section>
</div>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="verae-page-footer">
<strong>Verae Inc</strong>
&middot; <a href="https://www.verae.com">https://www.verae.com</a>
&middot; Book a call at <a href="https://www.verae.com">verae.com</a>
&middot; <a href="https://app.verae.com">app.verae.com</a>
</div>
<div class="footer">
&#169;2026, Verae Inc.
</div>
</body>
</html>