peergos-making-yourself-aud.../HOWTO.md
George Lambert afa270a141
Some checks are pending
ci / markdown (push) Waiting to run
Initial pack: Peergos EU audit verification and DataCube audit-ready checklist
Cure53 Berlin 2019 and ROS Amsterdam 2024 are pentests, not HIPAA/SOC2/ISO
certificates. BAA/DPA guidance for ciphertext-at-rest on cryptree+IPFS.
2026-09-15 23:57:04 -04:00

22 lines
992 B
Markdown

# How to use this pack
1. Read `PEERGOS-VERIFICATION.md` so you do not over-claim Peergos audits.
2. Fill `CHECKLIST.md` with **your** instance evidence (ns1, keys, users).
3. Give `BAA-DPA.md` to counsel with the data-flow from `README.md`.
4. Point auditors at live technical surfaces (do not give them private keys):
- https://pfc.georgelambert.org/health
- https://pfc.georgelambert.org/v1/npe/keys (public keys only)
- https://docs.pfc.georgelambert.org/controls.html
- https://docs.pfc.georgelambert.org/custody.html
- Peergos Drive (cryptree) on your host
5. Attach the two **public** Peergos pentest PDFs from
https://github.com/Peergos/Peergos/tree/master/audits as **vendor
security evaluations**, labeled “not our SOC 2 / ISO certificate”.
Related code/docs:
- https://git.georgelambert.org/marchon/peergos-for-compliance
- https://git.georgelambert.org/marchon/system-git-sync
- https://git.georgelambert.org/marchon/secure-messaging