I’ve gone through this process for my email client Kanmail [1]. The third party audit is not required for email clients that run on end users computers and store credentials locally. By the looks of it Pegasus falls into this category and should not have any issues getting approved (still need the YT video and such but the Google team are surprisingly responsive and helpful in my experience). [1] https://kanmail.io
Do you have evidence - in writing - to the contrary from a Google official?
Abridged wording and my non-lawyer interpretation below in case I'm not clear:
> Every app that [accesses Gmail and also accesses other servers] is required to go through a security assessment from Google empanelled security assessors. [...]
> In order to maintain access to restricted scopes, the app will need to undergo this security assessment on an annual basis, [... costs usually] between $10,000 - $75,000 (or more) [...]
> This fee may be required whether or not your app passes the assessment and will be payable by the developer."