|
Some checks are pending
ci / markdown (push) Waiting to run
Cure53 Berlin 2019 and ROS Amsterdam 2024 are pentests, not HIPAA/SOC2/ISO certificates. BAA/DPA guidance for ciphertext-at-rest on cryptree+IPFS. |
||
|---|---|---|
| .forgejo/workflows | ||
| .gitignore | ||
| BAA-DPA.md | ||
| CHECKLIST.md | ||
| HOWTO.md | ||
| LICENSE | ||
| MODULE.md | ||
| PEERGOS-VERIFICATION.md | ||
| README.md | ||
Making yourself audit-ready with Verae DataCubes
How to prepare an organization for HIPAA-aligned, SOC 2, or ISO 27001 work using Verae DataCubes on Peergos (encrypted cryptree + hashed IPFS) and HPKE on an untrusted NATS broker.
This repository is not a HIPAA, SOC 2, or ISO certificate.
Peergos’s public pentests are not your Type II or ISO registrar
certificate. They are component security evaluations you can attach.
What we verified about Peergos (EU)
Full sources: PEERGOS-VERIFICATION.md.
| Fact | Verified? |
|---|---|
| Encrypted client-side filesystem (cryptree); keys not on the storage server | Yes — Peergos book + Cure53 design review |
| IPFS blocks content-addressed; Peergos verifies hashes (tamper-evident restore) | Yes — trust-free layers |
| Independent EU security audits, reports published | Yes — two: Cure53 Berlin (2019); Radically Open Security Amsterdam (2024, NLnet; EU Horizon 2020 NGI-POINTER mentioned on the post) |
| “Peergos is HIPAA/SOC 2/ISO certified” | No. Those audits are pentest/code/design reviews, not management-system certificates |
So: Peergos was designed as a trust-minimized encrypted filesystem, evaluated in Europe by two specialist firms, with public reports. That supports the at-rest / backup story. It does not finish your audit.
Architecture (audit interview in one page)
Endpoint (keys stay here / HSM)
│ HPKE content (NPE suite)
│ routing: dest + subject in the clear
▼
Untrusted NATS (cannot read bodies)
│
▼
Verae DataCube chain (append-only hashes)
│ written through Peergos client
▼
Peergos cryptree (encrypted names, sizes, graph)
│ chunks → CID / hash
▼
IPFS (distributed, hash-verified ciphertext)
- At rest: Peergos cryptree + IPFS. Hosts with disk/backup see opaque hashed ciphertext, not PHI, if they lack keys.
- In transit (NATS): HPKE-Base to directory public keys. Broker is honest-but-curious: destinations yes, bodies no.
- Integrity: cube JSONL chain + dual hash + IPFS CID check on restore (re-fetch blocks, re-verify hashes — not a plaintext tape).
BAAs / DPAs
Ciphertext-without-keys narrows who is a Business Associate or
GDPR processor for content. It does not automatically delete
contracts for VMs, usernames, or logs. See BAA-DPA.md.
Pack
| File | Use |
|---|---|
PEERGOS-VERIFICATION.md |
Sourced Peergos/EU audit facts |
BAA-DPA.md |
Counsel briefing |
CHECKLIST.md |
Evidence list |
HOWTO.md |
How to hand this to an auditor |
MODULE.md |
Callers / non-runtime |
Live technical surfaces (ns1): https://pfc.georgelambert.org/health · https://pfc.georgelambert.org/v1/npe/keys · https://docs.pfc.georgelambert.org/controls.html
Related: https://git.georgelambert.org/marchon/system-git-sync