How to use this pack
====================

1. Read :doc:`verification` so you do not over-claim Peergos audits.
2. Fill :doc:`checklist` with **your** instance evidence (ns1, keys, users).
3. Give :doc:`baa-dpa` to counsel with the data-flow from :doc:`architecture`.
4. Point auditors at live technical surfaces (do not give them private keys).

.. only:: html

   * https://pfc.georgelambert.org/health
   * https://pfc.georgelambert.org/v1/npe/keys (public keys only)
   * https://docs.pfc.georgelambert.org/controls.html
   * https://docs.pfc.georgelambert.org/custody.html
   * Peergos Drive (cryptree) on your host
   * https://git.georgelambert.org/marchon/peergos-for-compliance
   * https://git.georgelambert.org/marchon/system-git-sync
   * https://git.georgelambert.org/marchon/secure-messaging

5. Attach the two **public** Peergos pentest PDFs from the Peergos
   ``audits/`` tree as **vendor security evaluations**, labeled “not our
   SOC 2 / ISO certificate”.

.. only:: latex

   Companion system PDF (same folder):

   .. raw:: latex

      \href{peergos-for-compliance.pdf}{peergos-for-compliance.pdf}
