Now recall to have someone externally keep the private keys away from the servers, and one other person (please come back Snake dude!) maintain the VPN settings between the three!
I also hope your backup keys are not only encrypted but have a steganographed backup externally, like I do on "my cat blog". Bitcoin blockchain might come handiest in the future.
And soon to have deadman switches ( >>5958 ). Mines rotate monthly, since I barely have time to connect online at all.
That's not within the threat model of lynxchan & most IBs: If the hardware is already compromised host level, nothing much you can do: which many are (softserv, KVM, Xen, etc.)
But do actually summon me when you've designed a kernel-IB server that can auto validate compromise within hardware! (no irony, for real!)
I mean that extremely positively: