How to use this pack¶
Read Peergos verification (what was actually audited) so you do not over-claim Peergos audits.
Fill Audit-ready checklist with your instance evidence (ns1, keys, users).
Give BAAs and DPAs when ciphertext has no host keys to counsel with the data-flow from Architecture (audit interview).
Point auditors at live technical surfaces (do not give them private keys).
https://pfc.georgelambert.org/v1/npe/keys (public keys only)
Peergos Drive (cryptree) on your host
https://git.georgelambert.org/marchon/peergos-for-compliance
Attach the two public Peergos pentest PDFs from the Peergos
audits/tree as vendor security evaluations, labeled “not our SOC 2 / ISO certificate”.