Initial pack: Peergos EU audit verification and DataCube audit-ready checklist
Some checks are pending
ci / markdown (push) Waiting to run
Some checks are pending
ci / markdown (push) Waiting to run
Cure53 Berlin 2019 and ROS Amsterdam 2024 are pentests, not HIPAA/SOC2/ISO certificates. BAA/DPA guidance for ciphertext-at-rest on cryptree+IPFS.
This commit is contained in:
commit
afa270a141
9 changed files with 392 additions and 0 deletions
22
HOWTO.md
Normal file
22
HOWTO.md
Normal file
|
|
@ -0,0 +1,22 @@
|
|||
# How to use this pack
|
||||
|
||||
1. Read `PEERGOS-VERIFICATION.md` so you do not over-claim Peergos audits.
|
||||
2. Fill `CHECKLIST.md` with **your** instance evidence (ns1, keys, users).
|
||||
3. Give `BAA-DPA.md` to counsel with the data-flow from `README.md`.
|
||||
4. Point auditors at live technical surfaces (do not give them private keys):
|
||||
|
||||
- https://pfc.georgelambert.org/health
|
||||
- https://pfc.georgelambert.org/v1/npe/keys (public keys only)
|
||||
- https://docs.pfc.georgelambert.org/controls.html
|
||||
- https://docs.pfc.georgelambert.org/custody.html
|
||||
- Peergos Drive (cryptree) on your host
|
||||
|
||||
5. Attach the two **public** Peergos pentest PDFs from
|
||||
https://github.com/Peergos/Peergos/tree/master/audits as **vendor
|
||||
security evaluations**, labeled “not our SOC 2 / ISO certificate”.
|
||||
|
||||
Related code/docs:
|
||||
|
||||
- https://git.georgelambert.org/marchon/peergos-for-compliance
|
||||
- https://git.georgelambert.org/marchon/system-git-sync
|
||||
- https://git.georgelambert.org/marchon/secure-messaging
|
||||
Loading…
Add table
Add a link
Reference in a new issue