How to use this pack

  1. Read Peergos verification (what was actually audited) so you do not over-claim Peergos audits.

  2. Fill Audit-ready checklist with your instance evidence (ns1, keys, users).

  3. Give BAAs and DPAs when ciphertext has no host keys to counsel with the data-flow from Architecture (audit interview).

  4. Point auditors at live technical surfaces (do not give them private keys).

  1. Attach the two public Peergos pentest PDFs from the Peergos audits/ tree as vendor security evaluations, labeled “not our SOC 2 / ISO certificate”.