Hey, this was my first post at PG
Brings back memories seeing it rise from the dead.
Not needed. They have given their answer on audits multiple times on their forum.
Our software is free and open source, while we repute at the moment not acceptable to provide external companies with root access to our servers to perform audits which can not anyway guarantee future avoidance of traffic logging or transmission to third parties. On the contrary, we deem very useful anything related to penetration tests. Such tests are frequently performed by independent researchers and bounty hunters and we also have a bounty program.
As I said back when this post was first made, I think PG is correct in sticking with its criteria but, I also think that forum members tend to default to equating a lack of audits as being nefarious which, without evidence, I think is misguided.