diff --git a/build/html/.buildinfo b/build/html/.buildinfo
index 331e078..d5dfb07 100644
--- a/build/html/.buildinfo
+++ b/build/html/.buildinfo
@@ -1,4 +1,4 @@
# Sphinx build info version 1
# This file records the configuration used when building these files. When it is not found, a full rebuild will be done.
-config: 99feb519dacc1b2aed6961d763dc4e5a
+config: 19300f99a53c0c3aa4174fd39d759eba
tags: 645f666f9bcd5a90fca523b33c5a78b7
diff --git a/build/html/.buildinfo.bak b/build/html/.buildinfo.bak
new file mode 100644
index 0000000..331e078
--- /dev/null
+++ b/build/html/.buildinfo.bak
@@ -0,0 +1,4 @@
+# Sphinx build info version 1
+# This file records the configuration used when building these files. When it is not found, a full rebuild will be done.
+config: 99feb519dacc1b2aed6961d763dc4e5a
+tags: 645f666f9bcd5a90fca523b33c5a78b7
diff --git a/build/html/.doctrees/environment.pickle b/build/html/.doctrees/environment.pickle
index 8929a97..17c74c6 100644
Binary files a/build/html/.doctrees/environment.pickle and b/build/html/.doctrees/environment.pickle differ
diff --git a/build/html/.doctrees/index.doctree b/build/html/.doctrees/index.doctree
index 9cb1430..ef020d3 100644
Binary files a/build/html/.doctrees/index.doctree and b/build/html/.doctrees/index.doctree differ
diff --git a/build/html/_sources/index.rst.txt b/build/html/_sources/index.rst.txt
index 9350471..21123f5 100644
--- a/build/html/_sources/index.rst.txt
+++ b/build/html/_sources/index.rst.txt
@@ -37,4 +37,10 @@ Network Error Bundle: ``ct_sender`` (sender-only status) and ``ct_system``
(ops bounce, no mail body). ``logging.mode=summary``.
Variables: ``crypto.mode``, ``routing.mode=passthrough``, ``SM_LEAF_HUB``,
-``SM_HTTP``. See system-git-sync ``docs/VARIABLES.md``.
+``SM_HTTP``. In the system PDF see the Variables chapter
+(``peergos-for-compliance.pdf``, same folder).
+
+.. raw:: latex
+
+ Companion system PDF: \href{peergos-for-compliance.pdf}{peergos-for-compliance.pdf}.
+ Catalog: \href{nats-service-endpoints.pdf}{nats-service-endpoints.pdf}.
diff --git a/build/html/index.html b/build/html/index.html
index c10c887..e954bbb 100644
--- a/build/html/index.html
+++ b/build/html/index.html
@@ -66,7 +66,8 @@ Tests send targeted good and bad messages on ct_sender (sender-only status) and ct_system
(ops bounce, no mail body). logging.mode=summary.
Variables: crypto.mode, routing.mode=passthrough, SM_LEAF_HUB,
-SM_HTTP. See system-git-sync docs/VARIABLES.md.
SM_HTTP. In the system PDF see the Variables chapter
+(peergos-for-compliance.pdf, same folder).
diff --git a/build/html/nats-service-endpoints.pdf b/build/html/nats-service-endpoints.pdf
new file mode 100644
index 0000000..5fd0175
Binary files /dev/null and b/build/html/nats-service-endpoints.pdf differ
diff --git a/build/html/peergos-for-compliance.pdf b/build/html/peergos-for-compliance.pdf
new file mode 100644
index 0000000..7867976
Binary files /dev/null and b/build/html/peergos-for-compliance.pdf differ
diff --git a/build/html/searchindex.js b/build/html/searchindex.js
index 5a26db6..444385e 100644
--- a/build/html/searchindex.js
+++ b/build/html/searchindex.js
@@ -1 +1 @@
-Search.setIndex({"alltitles":{"Errors":[[0,"errors"]],"Messages":[[0,"messages"]],"Secure messaging":[[0,null]],"Who calls this module":[[0,"who-calls-this-module"]]},"docnames":["index"],"envversion":{"sphinx":66,"sphinx.domains.c":3,"sphinx.domains.changeset":1,"sphinx.domains.citation":1,"sphinx.domains.cpp":9,"sphinx.domains.index":1,"sphinx.domains.javascript":3,"sphinx.domains.math":2,"sphinx.domains.python":4,"sphinx.domains.rst":2,"sphinx.domains.std":2},"filenames":["index.rst"],"indexentries":{},"objects":{},"objnames":{},"objtypes":{},"terms":{"15s":0,"5s":0,"From":0,"TO":0,"This":0,"To":0,"accept":0,"ack":0,"admin":0,"alg":0,"append":0,"bad":0,"bodi":0,"bounc":0,"bundl":0,"catalog":0,"certif":0,"ciphertext":0,"clear":0,"cmd":0,"config":0,"configur":0,"connector":0,"consol":0,"contain":0,"crypto":0,"ct":0,"ct_sender":0,"ct_system":0,"datacub":0,"dead":0,"dest":0,"doc":0,"ed25519":0,"empti":0,"endpoint":0,"envelop":0,"failur":0,"field":0,"filter":0,"georgelambert":0,"git":0,"go":0,"good":0,"health":0,"hipaa":0,"histori":0,"https":0,"hub":0,"iso":0,"json":0,"leaf":0,"log":0,"lookup_id":0,"loopback":0,"mail":0,"mailbox":0,"marchon":0,"md":0,"miss":0,"mode":0,"must":0,"nat":0,"network":0,"npe":0,"onli":0,"op":0,"option":0,"org":0,"passthrough":0,"pfc":0,"plaintext":0,"process":0,"py":0,"python":0,"reopen":0,"rout":0,"secure_messag":0,"see":0,"send":0,"sender":0,"servic":0,"sidecar":0,"sign":0,"sm":0,"sm_http":0,"sm_leaf_hub":0,"soc":0,"spec":0,"status":0,"success":0,"summari":0,"sync":0,"system":0,"systemd":0,"target":0,"test":0,"timeout":0,"variabl":0,"vera":0},"titles":["Secure messaging"],"titleterms":{"Who":0,"call":0,"error":0,"messag":0,"modul":0,"secur":0}})
\ No newline at end of file
+Search.setIndex({"alltitles":{"Errors":[[0,"errors"]],"Messages":[[0,"messages"]],"Secure messaging":[[0,null]],"Who calls this module":[[0,"who-calls-this-module"]]},"docnames":["index"],"envversion":{"sphinx":66,"sphinx.domains.c":3,"sphinx.domains.changeset":1,"sphinx.domains.citation":1,"sphinx.domains.cpp":9,"sphinx.domains.index":1,"sphinx.domains.javascript":3,"sphinx.domains.math":2,"sphinx.domains.python":4,"sphinx.domains.rst":2,"sphinx.domains.std":2},"filenames":["index.rst"],"indexentries":{},"objects":{},"objnames":{},"objtypes":{},"terms":{"15s":0,"5s":0,"From":0,"In":0,"TO":0,"This":0,"To":0,"accept":0,"ack":0,"admin":0,"alg":0,"append":0,"bad":0,"bodi":0,"bounc":0,"bundl":0,"catalog":0,"certif":0,"chapter":0,"ciphertext":0,"clear":0,"cmd":0,"complianc":0,"config":0,"configur":0,"connector":0,"consol":0,"contain":0,"crypto":0,"ct":0,"ct_sender":0,"ct_system":0,"datacub":0,"dead":0,"dest":0,"doc":[],"ed25519":0,"empti":0,"endpoint":0,"envelop":0,"failur":0,"field":0,"filter":0,"folder":0,"georgelambert":0,"git":0,"go":0,"good":0,"health":0,"hipaa":0,"histori":0,"https":0,"hub":0,"iso":0,"json":0,"leaf":0,"log":0,"lookup_id":0,"loopback":0,"mail":0,"mailbox":0,"marchon":0,"md":[],"miss":0,"mode":0,"must":0,"nat":0,"network":0,"npe":0,"onli":0,"op":0,"option":0,"org":0,"passthrough":0,"pdf":0,"peergo":0,"pfc":0,"plaintext":0,"process":0,"py":0,"python":0,"reopen":0,"rout":0,"secure_messag":0,"see":0,"send":0,"sender":0,"servic":0,"sidecar":0,"sign":0,"sm":0,"sm_http":0,"sm_leaf_hub":0,"soc":0,"spec":0,"status":0,"success":0,"summari":0,"sync":0,"system":0,"systemd":0,"target":0,"test":0,"timeout":0,"variabl":0,"vera":0},"titles":["Secure messaging"],"titleterms":{"Who":0,"call":0,"error":0,"messag":0,"modul":0,"secur":0}})
\ No newline at end of file
diff --git a/build/html/secure-messaging.pdf b/build/html/secure-messaging.pdf
new file mode 100644
index 0000000..dd2008f
Binary files /dev/null and b/build/html/secure-messaging.pdf differ
diff --git a/build/latex/.doctrees/environment.pickle b/build/latex/.doctrees/environment.pickle
index 42ddaec..7e76e1d 100644
Binary files a/build/latex/.doctrees/environment.pickle and b/build/latex/.doctrees/environment.pickle differ
diff --git a/build/latex/.doctrees/index.doctree b/build/latex/.doctrees/index.doctree
index 9cb1430..ef020d3 100644
Binary files a/build/latex/.doctrees/index.doctree and b/build/latex/.doctrees/index.doctree differ
diff --git a/build/latex/nats-service-endpoints.pdf b/build/latex/nats-service-endpoints.pdf
new file mode 100644
index 0000000..5fd0175
Binary files /dev/null and b/build/latex/nats-service-endpoints.pdf differ
diff --git a/build/latex/peergos-for-compliance.pdf b/build/latex/peergos-for-compliance.pdf
new file mode 100644
index 0000000..7867976
Binary files /dev/null and b/build/latex/peergos-for-compliance.pdf differ
diff --git a/build/latex/secure-messaging.log b/build/latex/secure-messaging.log
index e24e0ae..b8f0ac8 100644
--- a/build/latex/secure-messaging.log
+++ b/build/latex/secure-messaging.log
@@ -1,4 +1,4 @@
-This is pdfTeX, Version 3.141592653-2.6-1.40.29 (TeX Live 2026) (preloaded format=pdflatex 2026.8.11) 15 SEP 2026 23:08
+This is pdfTeX, Version 3.141592653-2.6-1.40.29 (TeX Live 2026) (preloaded format=pdflatex 2026.8.11) 15 SEP 2026 23:27
entering extended mode
restricted \write18 enabled.
%&-line parsing enabled.
@@ -735,8 +735,7 @@ File: t1qtm.fd 2009/09/25 v1.2 font definition file for T1/qtm
ef
File: l3backend-pdftex.def 2026-07-20 L3 backend support: PDF output (pdfTeX)
\l__color_backend_stack_int=\count347
-)
-No file secure-messaging.aux.
+) (./secure-messaging.aux)
\openout1 = `secure-messaging.aux'.
LaTeX Font Info: Checking defaults for OML/cmm/m/it on input line 73.
@@ -757,6 +756,7 @@ LaTeX Font Info: Checking defaults for PD1/pdf/m/n on input line 73.
LaTeX Font Info: ... okay on input line 73.
LaTeX Font Info: Checking defaults for PU/pdf/m/n on input line 73.
LaTeX Font Info: ... okay on input line 73.
+
(/usr/local/texlive/2026basic/texmf-dist/tex/context/base/mkii/supp-pdf.mkii
[Loading MPS to PDF converter (version 2006.09.02).]
\scratchcounter=\count348
@@ -818,6 +818,7 @@ e
* (1in=72.27pt=25.4mm, 1cm=28.453pt)
Package hyperref Info: Link coloring ON on input line 73.
+(./secure-messaging.out) (./secure-messaging.out)
\@outlinefile=\write5
\openout5 = `secure-messaging.out'.
@@ -825,6 +826,7 @@ Package babel Info: Main language set to 'english'.
Package hyperref Info: Option `pageanchor' set `false' on input line 81.
LaTeX Font Info: Trying to load font information for T1+qhv on input line 81
.
+
(/Users/marchon/Library/texmf/tex/latex/tex-gyre/t1qhv.fd
File: t1qhv.fd 2009/09/25 v1.2 font definition file for T1/qhv
) [1
@@ -834,18 +836,19 @@ tex.map}{/Users/marchon/Library/texmf/fonts/enc/dvips/tex-gyre/q-ec.enc}] [2
]
-No file secure-messaging.toc.
+(./secure-messaging.toc)
\tf@toc=\write6
\openout6 = `secure-messaging.toc'.
-[1
+ [1
] [2
]
LaTeX Font Info: Trying to load font information for TS1+qtm on input line 9
5.
- (/Users/marchon/Library/texmf/tex/latex/tex-gyre/ts1qtm.fd
+
+(/Users/marchon/Library/texmf/tex/latex/tex-gyre/ts1qtm.fd
File: ts1qtm.fd 2009/09/25 v1.2 font definition file for TS1/qtm
)
LaTeX Font Info: Trying to load font information for T1+txtt on input line 9
@@ -892,24 +895,14 @@ Package sphinx Warning: The package ellipse is required for elliptical corners.
LaTeX2e <2026-06-01>
L3 programming layer <2026-07-20>
***********
-
-
-LaTeX Warning: Label(s) may have changed. Rerun to get cross-references right.
-
-
-Package rerunfilecheck Warning: File `secure-messaging.out' has changed.
-(rerunfilecheck) Rerun to get outlines right
-(rerunfilecheck) or use package `bookmark'.
-
-Package rerunfilecheck Info: Checksums for `secure-messaging.out':
-(rerunfilecheck) Before: