Home / Vaults

Published vaults

Every vault whose read key this site has deliberately published — with, for each one, a page describing what it does, the features it uses, what the shape is good for, and the vault itself running live inside the page. The keys below are the complete credential: no account, no token, and no write capability anywhere in them.

Publishing one of your own? The method is written down — the seven steps behind every row below, the tools that do each one, and the mistakes that produced each rule. Written to be followed by another site's agent.
Intake, since it nearly went wrong. A credential submitted for publication here was once a vault key described as a read key — a legacy passphrase:vault_id form with no prefix to give it away. It was caught, only the derived read key was published, and nothing leaked; but the catch depended on somebody looking. Every submission now runs through admin/build/check_credential.py first, which refuses a write credential by prefix (sgit_vk1_, which new vaults emit) or, for anything older, by shape — a read key is 64 hex characters, and anything else before the colon is a passphrase. Prefixes are the better answer; the shape check covers the years of keys created before them.
The two rules, applied to every row. Read keys yes, vault keys never — a read key is a capability we hand out on purpose, and it cannot become write access. And every vault is audited before its key appears here, because content travels with the key forever; findings are published on the vault’s page, not filed away.
VaultIdShapeContentsPublished read key
Field Notes4bshby5napplication (vault app)4 files · 11 KB · 2 commits · app entry index.htmlsgit_rk1_2848993a68c02a33ea5582902c391901191e53680d35b36c0e76185d4107ad81:4bshby5nopen live ↗
Strategy Mapsookq4mn4structured analysis (two apps, one vault)33 files · 830 KB · 3 commits · app entries index.html and sgit-maps.htmlsgit_rk1_451c4c1e28fbb24a7f350bb3f107b2c103d69ed363167029ef9c9000ff76c07b:ookq4mn4open live ↗
Deploy Docsfyofmkvrrecord-keeping (live markdown)17 files · 25 KB · 2 commits · markdown, no appsgit_rk1_8d01421290efc3fa03205eced0534335a06ae209d627555b3dde136b878e3de1:fyofmkvropen live ↗
The Vault Cataloguekc67yhgwrecord-keeping (an index of vaults)9 files · 11 KB · 2 commits · markdown, no appsgit_rk1_fd71e4bde7232498e43a5da869b1501260d9d403031b20af87b5bc801bdf6280:kc67yhgwopen live ↗
Algarve · May 20263d04e6b9ca98gallery (photo story)71 files · 29 MB · 36 commits · app entry index.htmlsgit_rk1_0a0f34839d737eef0f8f66e5236990b1f397af064763e3f71dca2717015f9d15:3d04e6b9ca98open live ↗
Supplement Stackr7zes477record-keeping (patient-held health record)23 files · 2.3 MB · 5 commits · app entry index.htmlsgit_rk1_047186b559528058c66d1792b7345639b1238cb95c166d1d5f5b65c59813c2ee:r7zes477open live ↗
Risk Mandate4zf6pf2zapplication (a software project in a vault)124 files · 1.9 MB · 98 commits · 8 app entriessgit_rk1_a702fba803faac4369eb5d5a320b4dfa017af62bd2425fb298aac4b99e95c0ae:4zf6pf2zopen live ↗
Agentic Browser Isolation0610gsp9structured analysis (a living risk graph)104 files · 2.4 MB · 4 commits · 17 app entriessgit_rk1_92cad4cea8f58c55f59b686c71c935225a1ba7c41ecb6922a8aa570467604f6e:0610gsp9open live ↗
Risk Graph Explorer3simlnqeapplication (public by design)33 files · 428 KB · 7 commits · 1 app entrysgit_rk1_1c1b95f5903e35850a9bc0541ffa09c6b5d4017cbf18817d2ad6f894127e5638:3simlnqeopen live ↗
Vault App Modexth1xt78developer reference (nine POCs and a demo)57 files · 251 KB · 8 commits · app entry _poc-hub/index.htmlsgit_rk1_05f2391f22e4135ea27bca6b697dca18c54ab91b046325bef74f62f5324b8bc8:xth1xt78open live ↗
Private Health Scorezc6abngvapplication (a clinical workflow, sanitised republication)35 files · 1.2 MB · 3 commits · app entry home/index.htmlsgit_rk1_a76f327fb602f1619a67a15a0b756d69e82a1f7fa48438d4b6ecbebae2dc3d40:zc6abngvopen live ↗
VoiceDebriefk6xy9z4dstructured analysis (four apps, one vault)92 files · 1.2 MB · 18 commits · app entry part-4/index.htmlsgit_rk1_31e8196d3e83b37277083c29f105b8310dbac4569e22715b5e0f85d46878eec1:k6xy9z4dopen live ↗
Regulation Graph73heuprzreference data (regulation as an evidence graph)207 files · 14.9 MB · 2 commits · 11 app viewssgit_rk1_c004daae386e8d17fa648884acc527018bd4ea1116ad673fb2f1b068011695c9:73heuprzopen live ↗
SG/Payments Brief Packo3m0sz3qbriefing pack (PROPOSED)18 files · 224 KB · app entry index.htmlsgit_rk1_cd1987b87f719c2ff6da51128200665312afaeeadcbf7a1a20f870f03f9959f8:o3m0sz3qopen live ↗
SG Commercialisationhaeu7p1ecommercial operating model78 files · 536 KB · register deliberately emptysgit_rk1_3c8cba7edd2f14e63d0b0f0da4d513430e3eea06f364baefaf8b22d85e151da6:haeu7p1eopen live ↗
RiskMandate · File securitywu365g94risk-acceptance walk (11 steps)71 files · 2.7 MB · SQLite in the browsersgit_rk1_e8a1e664b9f984b0d8df442f463231077d455d7cbaa3e336610b14f9a1e1dc77:wu365g94open live ↗
Standards Atlas — GDPR4zv4bvmustandard as a semantic graph116 files · 6.3 MB · writes scoped to feedback/sgit_rk1_439ca57ab9e53b4edfa67e99da1b70948c297d323376c890292dc2f0876aa15c:4zv4bvmuopen live ↗
Content-Transformation Proxy3c90c2bff2b1as-built engineering brief140 files · 63 MB · slides, diagrams and source PDFssgit_rk1_18bf8b2aa558fec879edb39c79ee66d6b9594ada2dff71039b3f66f5b14e4839:3c90c2bff2b1open live ↗
Penetration Test Reporto4lrwx02security report (fictional)93 files · 6.4 MB · retest script per findingsgit_rk1_14042259ecbec2d0c7c4e68963695c4ceeeeb652767d25b777024a4f05ccd025:o4lrwx02open live ↗
AI vs. AI — Black Hat EU 2025k1izvg7econference keynote87 files · 20 MB · 26 slides, 6 PDF exports, 8 research paperssgit_rk1_147fa50d3c491aeea3e700d60ef21ea2897884e263700d95765dc8f624dc59ac:k1izvg7eopen live ↗
Scaling Threat Modeling0ict6flmconference session53 files · 4.1 MB · 11 layers, 51 nodes, 179 threatssgit_rk1_23fb205247b2b9c88a943d7ffece9dacf9c00c50cc94840668b4916f247b8ec4:0ict6flmopen live ↗

The machine-first version of this list is the catalogue — an index of vaults that is itself a vault, updated by an sgit push with no site deploy. New entries start there: a read key and one line, the rest derived. The walkthrough of how a vault gets published at all — creation, audit, deliberate key publication, embed — is on the embed demo page.