# How to use this pack 1. Read `PEERGOS-VERIFICATION.md` so you do not over-claim Peergos audits. 2. Fill `CHECKLIST.md` with **your** instance evidence (ns1, keys, users). 3. Give `BAA-DPA.md` to counsel with the data-flow from `README.md`. 4. Point auditors at live technical surfaces (do not give them private keys): - https://pfc.georgelambert.org/health - https://pfc.georgelambert.org/v1/npe/keys (public keys only) - https://docs.pfc.georgelambert.org/controls.html - https://docs.pfc.georgelambert.org/custody.html - Peergos Drive (cryptree) on your host 5. Attach the two **public** Peergos pentest PDFs from https://github.com/Peergos/Peergos/tree/master/audits as **vendor security evaluations**, labeled “not our SOC 2 / ISO certificate”. Related code/docs: - https://git.georgelambert.org/marchon/peergos-for-compliance - https://git.georgelambert.org/marchon/system-git-sync - https://git.georgelambert.org/marchon/secure-messaging