peergos-making-yourself-aud.../build/html/peergos-eu-evaluations.html
George Lambert 8496ef8338
Some checks are pending
ci / markdown (push) Waiting to run
Put the executive summary on page 2, before the table of contents.
The cover stays page 1. Numbered chapters now start at What Verae
provides. The TOC lists Executive summary at page 2.
2026-09-16 01:21:05 -04:00

273 lines
No EOL
14 KiB
HTML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!DOCTYPE html>
<html lang="en" data-content_root="./">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>6. Peergos security evaluations in Europe &#8212; Making yourself audit-ready with Verae DataCubes</title>
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=2d7b7068" />
<script src="_static/documentation_options.js?v=250a654d"></script>
<script src="_static/doctools.js?v=fd6eb6e6"></script>
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
<link rel="icon" href="_static/VeraeFullLogo.png"/>
<link rel="index" title="Index" href="genindex.html" />
<link rel="search" title="Search" href="search.html" />
<link rel="next" title="7. Verae global timestamping — a cross-blockchain receipt" href="global-timestamping.html" />
<link rel="prev" title="5. Global timestamped receipts" href="timestamped-receipts.html" />
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
</head><body>
<div class="document">
<div class="sphinxsidebar" role="navigation" aria-label="Main">
<div class="sphinxsidebarwrapper">
<p class="logo"><a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo of Making yourself audit-ready with Verae DataCubes"/>
</a></p>
<p class="logo">
<a href="index.html">
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo" />
</a>
</p>
<p class="blurb">Tools for storage, communications, timestamping, verification, and audit — not a certificate.</p>
<search id="searchbox" style="display: none" role="search">
<div class="searchformwrapper">
<form class="search" action="search.html" method="get">
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false" placeholder="Search"/>
<input type="submit" value="Go" />
</form>
</div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">1. What Verae provides — and what it does not</a></li>
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">2. The Verae DataCube Server Solution</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">3. Secure communications — data in transit</a></li>
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">4. Encryption at rest — IPFS blocks and Peergos</a></li>
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">5. Global timestamped receipts</a></li>
<li class="toctree-l1 current"><a class="current reference internal" href="#">6. Peergos security evaluations in Europe</a><ul>
<li class="toctree-l2"><a class="reference internal" href="#what-was-evaluated">6.1. What was evaluated</a></li>
<li class="toctree-l2"><a class="reference internal" href="#cure53-berlin-germany">6.2. 2019 — Cure53, Berlin, Germany</a></li>
<li class="toctree-l2"><a class="reference internal" href="#radically-open-security-b-v-amsterdam">6.3. 2024 — Radically Open Security B.V., Amsterdam</a></li>
<li class="toctree-l2"><a class="reference internal" href="#how-to-present-these-reports-to-an-auditor">6.4. How to present these reports to an auditor</a></li>
<li class="toctree-l2"><a class="reference internal" href="#hosted-peergos-versus-self-hosted-datacubes">6.5. Hosted Peergos versus self-hosted DataCubes</a></li>
<li class="toctree-l2"><a class="reference internal" href="#what-designed-under-funding-from-cure53-ros-is-not">6.6. What “designed under funding from Cure53 / ROS” is not</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">7. Verae global timestamping — a cross-blockchain receipt</a></li>
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">8. Write-once Iceberg archive</a></li>
<li class="toctree-l1"><a class="reference internal" href="architecture.html">9. Architecture for an audit interview</a></li>
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">10. BAAs, DPAs, and ciphertext without host keys</a></li>
<li class="toctree-l1"><a class="reference internal" href="checklist.html">11. Audit-ready checklist</a></li>
<li class="toctree-l1"><a class="reference internal" href="howto.html">12. How to use this briefing</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">13. James H. Garfinkel</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-stuart-haber.html">14. Stuart Haber</a></li>
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">15. George Lambert</a></li>
<li class="toctree-l1"><a class="reference internal" href="contact.html">16. Verae Inc — contact</a></li>
</ul>
<div class="relations">
<h3>Related Topics</h3>
<ul>
<li><a href="index.html">Documentation overview</a><ul>
<li>Previous: <a href="timestamped-receipts.html" title="previous chapter"><span class="section-number">5. </span>Global timestamped receipts</a></li>
<li>Next: <a href="global-timestamping.html" title="next chapter"><span class="section-number">7. </span>Verae global timestamping — a cross-blockchain receipt</a></li>
</ul></li>
</ul>
</div>
</div>
</div>
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="peergos-security-evaluations-in-europe">
<h1><span class="section-number">6. </span>Peergos security evaluations in Europe<a class="headerlink" href="#peergos-security-evaluations-in-europe" title="Link to this heading"></a></h1>
<section id="what-was-evaluated">
<h2><span class="section-number">6.1. </span>What was evaluated<a class="headerlink" href="#what-was-evaluated" title="Link to this heading"></a></h2>
<p>The offline storage and replication system used with Verae
DataCubes is <strong>Peergos</strong>: an encrypted, peer-to-peer filesystem
whose blocks live on IPFS. Peergos was designed as a
trust-minimized store — the server is treated as an adversary
for content and for most metadata — and that design was
submitted to independent European security firms <strong>twice</strong>.</p>
<p>Those engagements are <strong>security evaluations of the Peergos
protocol and implementation</strong>. They are pentests, source-code
audits, and (in 2019) a cryptographic and design review. They
are <strong>not</strong>:</p>
<ul class="simple">
<li><p>a HIPAA certification of Peergos, Verae, or any customer;</p></li>
<li><p>a SOC 2 Type I or Type II report;</p></li>
<li><p>an ISO 27001 certificate of an ISMS;</p></li>
<li><p>a government “certified filesystem” designation.</p></li>
</ul>
<p>Both firms are <strong>EU-based</strong>. Both full reports are <strong>public</strong>.
That combination — independent, European, public, repeat —
is unusual and is worth attaching to a vendor-assurance file,
<strong>labeled correctly</strong>.</p>
</section>
<section id="cure53-berlin-germany">
<h2><span class="section-number">6.2. </span>2019 — Cure53, Berlin, Germany<a class="headerlink" href="#cure53-berlin-germany" title="Link to this heading"></a></h2>
<ul class="simple">
<li><p><strong>Firm:</strong> Cure53</p></li>
<li><p><strong>Location:</strong> Berlin, Germany</p></li>
<li><p><strong>When:</strong> MayJune 2019</p></li>
<li><p><strong>Scope:</strong> pentest, source-code audit, and
<strong>crypto / design review</strong></p></li>
<li><p><strong>Outcome:</strong> no fundamental architectural or cryptographic
problems were identified. Issues that were identified were
fixed. Cure53 stated that the platform <strong>passed this
evaluation</strong>.</p></li>
</ul>
<p>A crypto/design review is a stronger statement than a
black-box pentest of a web form. It is an expert reading of
whether the cryptree, the chunk encryption, the identity
model, and the threat model hang together. “Passed” in
Cure53s language is not an ISO mark. It is a specialist
firm saying: we looked at the cryptography and the
architecture, we did not find a fatal flaw, and the issues we
did find were addressed.</p>
<p>Primary sources (public):</p>
<ul class="simple">
<li><p><a class="reference external" href="https://peergos.org/posts/security-audit">https://peergos.org/posts/security-audit</a></p></li>
<li><p><a class="reference external" href="https://cure53.de/pentest-report_peergos.pdf">https://cure53.de/pentest-report_peergos.pdf</a></p></li>
<li><p><a class="reference external" href="https://github.com/Peergos/Peergos/tree/master/audits">https://github.com/Peergos/Peergos/tree/master/audits</a></p></li>
</ul>
</section>
<section id="radically-open-security-b-v-amsterdam">
<h2><span class="section-number">6.3. </span>2024 — Radically Open Security B.V., Amsterdam<a class="headerlink" href="#radically-open-security-b-v-amsterdam" title="Link to this heading"></a></h2>
<ul class="simple">
<li><p><strong>Firm:</strong> Radically Open Security B.V.</p></li>
<li><p><strong>Location:</strong> Amsterdam, Netherlands</p></li>
<li><p><strong>When:</strong> SeptemberNovember 2024</p></li>
<li><p><strong>Scope:</strong> crystal-box pentest plus code audit of the
Peergos <strong>web UI</strong></p></li>
<li><p><strong>Funding context:</strong> the 2024 audit post states support
from <strong>NLnet</strong> (Netherlands) and refers to European Union
Horizon 2020 <strong>NGI-POINTER</strong>, grant <strong>871528</strong>.</p></li>
<li><p><strong>Outcome:</strong> <strong>0</strong> findings rated extreme, high, or
elevated; <strong>2</strong> moderate; <strong>6</strong> low. Peergos states that
all were fixed. There was <strong>no data exposure</strong> and <strong>no
integrity compromise</strong>. The issues were described as
mostly UI crashes.</p></li>
</ul>
<p>A crystal-box (clear-box) engagement means the testers had
source. A web-UI scope is narrower than the 2019
crypto/design review: it is evidence about the interface
that humans actually click, which is where many “encrypted
backend” products fail in practice. Zero high-severity
findings, no data exposure, no integrity compromise, and a
public report are the facts. They are good facts. They are
still not a customers Type II.</p>
<p>Primary sources (public):</p>
<ul class="simple">
<li><p><a class="reference external" href="https://peergos.org/posts/security-audit-2024">https://peergos.org/posts/security-audit-2024</a></p></li>
<li><p><a class="reference external" href="https://github.com/Peergos/Peergos/tree/master/audits">https://github.com/Peergos/Peergos/tree/master/audits</a></p></li>
</ul>
</section>
<section id="how-to-present-these-reports-to-an-auditor">
<h2><span class="section-number">6.4. </span>How to present these reports to an auditor<a class="headerlink" href="#how-to-present-these-reports-to-an-auditor" title="Link to this heading"></a></h2>
<p>Correct:</p>
<blockquote>
<div><p>“Our at-rest layer is Peergos. Peergos was independently
evaluated in Berlin in 2019 (crypto and design) and in
Amsterdam in 2024 (web UI, crystal box). Both reports are
public. We attach them as <strong>component security
evaluations</strong>. They are not our SOC 2, not our ISO 27001,
and not a HIPAA certification. Our own controls, our own
period of examination, and our own auditor are separate.”</p>
</div></blockquote>
<p>Incorrect:</p>
<blockquote>
<div><p>“We are HIPAA certified because Peergos was audited in
Europe.”</p>
<p>“Peergos is ISO 27001.”</p>
<p>“The EU certified this filesystem.”</p>
</div></blockquote>
<p>EU funding is not a certification. NGI-POINTER grant 871528
is a research-and-innovation funding fact. It is worth
listing under “provenance.” It is not a registrars mark.</p>
</section>
<section id="hosted-peergos-versus-self-hosted-datacubes">
<h2><span class="section-number">6.5. </span>Hosted Peergos versus self-hosted DataCubes<a class="headerlink" href="#hosted-peergos-versus-self-hosted-datacubes" title="Link to this heading"></a></h2>
<p>Peergoss hosted privacy notice has stated that peergos.net
uses servers in <strong>Germany</strong>. A <strong>self-hosted</strong> organizational
DataCube is a <strong>different processing location</strong>. The
customers Record of Processing, BAA pack, and ISO scope
must name <em>that</em> location — the customers ns1, region, or
chosen host — not peergos.nets Germany, unless the
customer actually uses peergos.net.</p>
<p>The evaluations still apply to the <strong>protocol and
implementation</strong>. Location of processing is an
organizational fact on top.</p>
</section>
<section id="what-designed-under-funding-from-cure53-ros-is-not">
<h2><span class="section-number">6.6. </span>What “designed under funding from Cure53 / ROS” is not<a class="headerlink" href="#what-designed-under-funding-from-cure53-ros-is-not" title="Link to this heading"></a></h2>
<p>The 2019 Cure53 work and the 2024 ROS work are <strong>evaluations</strong>
of a system that was designed by the Peergos authors. They
are not a claim that Cure53 or Radically Open Security
designed Peergos. The accurate statement is: the storage and
replication system was <strong>independently audited twice in
Europe</strong>, by Cure53 in Berlin (2019) and by Radically Open
Security in Amsterdam (2024), with public reports, and the
2019 work included a cryptographic and design review of the
architecture that Verae DataCubes rely on for data at rest.</p>
</section>
</section>
</div>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="verae-page-footer">
<strong>Verae Inc</strong>
&middot; <a href="https://www.verae.com">https://www.verae.com</a>
&middot; Book a call at <a href="https://www.verae.com">verae.com</a>
&middot; <a href="https://app.verae.com">app.verae.com</a>
</div>
<div class="footer">
&#169;2026, Verae Inc.
</div>
</body>
</html>