Some checks are pending
ci / markdown (push) Waiting to run
Cure53 Berlin 2019 and ROS Amsterdam 2024 are pentests, not HIPAA/SOC2/ISO certificates. BAA/DPA guidance for ciphertext-at-rest on cryptree+IPFS.
22 lines
992 B
Markdown
22 lines
992 B
Markdown
# How to use this pack
|
|
|
|
1. Read `PEERGOS-VERIFICATION.md` so you do not over-claim Peergos audits.
|
|
2. Fill `CHECKLIST.md` with **your** instance evidence (ns1, keys, users).
|
|
3. Give `BAA-DPA.md` to counsel with the data-flow from `README.md`.
|
|
4. Point auditors at live technical surfaces (do not give them private keys):
|
|
|
|
- https://pfc.georgelambert.org/health
|
|
- https://pfc.georgelambert.org/v1/npe/keys (public keys only)
|
|
- https://docs.pfc.georgelambert.org/controls.html
|
|
- https://docs.pfc.georgelambert.org/custody.html
|
|
- Peergos Drive (cryptree) on your host
|
|
|
|
5. Attach the two **public** Peergos pentest PDFs from
|
|
https://github.com/Peergos/Peergos/tree/master/audits as **vendor
|
|
security evaluations**, labeled “not our SOC 2 / ISO certificate”.
|
|
|
|
Related code/docs:
|
|
|
|
- https://git.georgelambert.org/marchon/peergos-for-compliance
|
|
- https://git.georgelambert.org/marchon/system-git-sync
|
|
- https://git.georgelambert.org/marchon/secure-messaging
|