peergos-making-yourself-aud.../README.md
George Lambert afa270a141
Some checks are pending
ci / markdown (push) Waiting to run
Initial pack: Peergos EU audit verification and DataCube audit-ready checklist
Cure53 Berlin 2019 and ROS Amsterdam 2024 are pentests, not HIPAA/SOC2/ISO
certificates. BAA/DPA guidance for ciphertext-at-rest on cryptree+IPFS.
2026-09-15 23:57:04 -04:00

73 lines
2.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Making yourself audit-ready with Verae DataCubes
How to **prepare an organization** for HIPAA-aligned, SOC 2, or ISO 27001
work using Verae DataCubes on **Peergos** (encrypted cryptree + hashed
IPFS) and HPKE on an **untrusted NATS** broker.
**This repository is not a HIPAA, SOC 2, or ISO certificate.**
Peergoss public pentests are **not** your Type II or ISO registrar
certificate. They are **component security evaluations** you can attach.
## What we verified about Peergos (EU)
Full sources: [`PEERGOS-VERIFICATION.md`](PEERGOS-VERIFICATION.md).
| Fact | Verified? |
|---|---|
| Encrypted client-side filesystem (cryptree); keys not on the storage server | Yes — Peergos book + Cure53 design review |
| IPFS blocks content-addressed; Peergos verifies hashes (tamper-evident restore) | Yes — [trust-free layers](https://book.peergos.org/security/trust.html) |
| Independent **EU** security audits, reports published | **Yes — two:** Cure53 **Berlin** (2019); Radically Open Security **Amsterdam** (2024, NLnet; EU Horizon 2020 NGI-POINTER mentioned on the post) |
| “Peergos is HIPAA/SOC 2/ISO certified” | **No.** Those audits are pentest/code/design reviews, not management-system certificates |
So: Peergos **was designed as a trust-minimized encrypted filesystem**,
**evaluated in Europe** by two specialist firms, with **public reports**.
That supports the **at-rest / backup** story. It does **not** finish
*your* audit.
## Architecture (audit interview in one page)
```
Endpoint (keys stay here / HSM)
│ HPKE content (NPE suite)
│ routing: dest + subject in the clear
Untrusted NATS (cannot read bodies)
Verae DataCube chain (append-only hashes)
│ written through Peergos client
Peergos cryptree (encrypted names, sizes, graph)
│ chunks → CID / hash
IPFS (distributed, hash-verified ciphertext)
```
- **At rest:** Peergos cryptree + IPFS. Hosts with disk/backup see
**opaque hashed ciphertext**, not PHI, if they lack keys.
- **In transit (NATS):** HPKE-Base to directory public keys. Broker is
honest-but-curious: destinations yes, bodies no.
- **Integrity:** cube JSONL chain + dual hash + IPFS CID check on
restore (re-fetch blocks, re-verify hashes — not a plaintext tape).
## BAAs / DPAs
Ciphertext-without-keys **narrows** who is a Business Associate or
GDPR processor for **content**. It does **not** automatically delete
contracts for VMs, usernames, or logs. See [`BAA-DPA.md`](BAA-DPA.md).
## Pack
| File | Use |
|---|---|
| `PEERGOS-VERIFICATION.md` | Sourced Peergos/EU audit facts |
| `BAA-DPA.md` | Counsel briefing |
| `CHECKLIST.md` | Evidence list |
| `HOWTO.md` | How to hand this to an auditor |
| `MODULE.md` | Callers / non-runtime |
Live technical surfaces (ns1): https://pfc.georgelambert.org/health ·
https://pfc.georgelambert.org/v1/npe/keys ·
https://docs.pfc.georgelambert.org/controls.html
Related: https://git.georgelambert.org/marchon/system-git-sync