@viktor "Found it. Heise quotes Karlitschek directly: 'We can vouch for our version' and 'Anyone can check it themselves.'
That's not an audit — that's a reputation pledge plus open source transparency. Both are legitimate, but neither is what CryptPad did: they documented specific sandboxing architecture precisely because they explicitly do not trust the upstream code.
The question now: where is the Euro-Office threat model document?