Independent. No commercial relationship with UnGovr — no funding, no agreement, no conversation of any kind — checked 9 September 2026. Disclosures · how every claim here is evidenced

ungovr.providers.sgit.ai / The estate this joins — seven vaults, running here

The estate this joins — seven vaults, running here

Every vault below is running, not screenshotted — pick one and it decrypts in your browser from a read key printed on this page. They are here because each of them has a hole shaped like UnGovr: an obligation with no named body, or a body with no named jurisdiction.

Prose from the government-graph vault dkeclt5r @ obj-cas-imm-e23f0cecfccf, 9 September 2026. Read keys copied from each vault's own published page on sgit.ai. Counts on this page were computed from the vaults themselves, not from their prose. When the vault moves ahead, this page is behind — and says so rather than guessing.

AIUC-1 conformance layerThe standards map. 1,126 crosswalks into thirteen frameworks — and a conformance layer that keeps does the standard say this apart from does this subject do this.
New tab ↗
AIUC-1, as a graphThe catalogue the layer above forked byte for byte: 53 controls, 144 requirements, and every field naming the page it was read from with the sha256 of the bytes.
New tab ↗
Regulation GraphThe EU AI Act parsed from official Formex XML, hash-verified to the bytes it came from — 1,523 nodes, 1,944 edges, eleven views.
New tab ↗
Licence to OperateOne agent, a grant of 12 capabilities, a mandate of 4, and the 8-capability delta no policy covers — with every reply priced against a live policy.
New tab ↗
Risk MandateA working application delivered as a vault: 124 files, 98 commits, eight entry points — and it calls an LLM without ever holding the API key.
New tab ↗
Standards Atlas — GDPRGDPR as a semantic graph where CJEU rulings, regulator guidance and per-country variation are first-class nodes layered over the articles they bend.
New tab ↗
Risk Graph ExplorerA fact-to-risk graph explorer, built to be public: its app.json requests no permissions at all. The word in the middle is the one this site is about.
New tab ↗

Nothing has been fetched yet. This page opens no connection until you pick a vault above — then exactly one, to dev.vault.sgraph.ai. One at a time, by design: seven vaults booting at once is a worse demonstration than one booting well. verified 9 Sep 2026

A link list would have been easier and would have told an executive nothing. The point of a vault is that the credential is the whole thing — no account, no token, no seat. Handing over a read key and having the artefact decrypt in front of you is the argument; a screenshot of it is not.

So each of these opens here, from a key printed a few lines below, and none of it is stored on this site. A push to any of those vaults changes what you see on this page with no rebuild and no deploy.

They were chosen on one test: does this artefact contain an obligation, a control or a risk that currently floats free of a named body in a named place? All seven do. That is the hole UnGovr fills, and the rest of this page is about its exact shape.

What UnGovr adds, in one number

The AIUC-1 conformance vault is the densest standards map in the estate. Its graph was opened with the published read key and counted rather than read about: 11,610 edges, of which 1,126 are maps_to crosswalks from AIUC-1 controls out to 489 distinct control items across exactly thirteen frameworks. measured 9 Sep 2026

Ninety-five of those 1,126 crosswalks point at law — the EU AI Act (62), the Colorado AI Act (18), California SB 53 (9) and NYC Local Law 144 (6). Three of those four laws are sub-national United States jurisdictions. measured 9 Sep 2026

That is the whole argument on one line. A crosswalk that ends at the Colorado AI Act is a statement about a text. It is not yet a statement about which bodies in Colorado it binds, and no vault in this estate can answer that today. UnGovr's index is keyed on exactly that axis — us/co, us/ca, us/ny/new-york — which is why the connection is worth building and why it is one edge, not a project.

The estate hasUnGovr hasMissing
control → law crosswalkbody → jurisdiction, with a sluglaw → the bodies it binds
an obligation with a deadline set by an attestation's expirya deadline set by statutewhich of the two governs
unevidenced as the default answera public-records law string per bodywhether the record can be asserted to exist

The dev pack for this work is published in full — eight files: the anchor-node thesis, the model with fifteen edges and their inverses, the standards map above with its working, a worked example, the integration surface, and thirteen tests of which five currently pass, all inherited. It lives in packs/security-graph/ in the government-graph vault and is republished here byte for byte.

The second finding, which is a gap rather than a number

Not one general security control set appears in AIUC-1's thirteen. No NIST CSF, no SP 800-53, no ISO/IEC 27001 or 27002, no SOC 2, no CIS Controls, no PCI DSS, no HIPAA, no FedRAMP. Every one of the thirteen is AI-specific. measured 9 Sep 2026

That is not a defect in AIUC-1 — it is an agent standard and the AI corpus is the right scope for it. But it does mean that the general-security half of any security-standards map is genuinely absent from this estate, and anyone assuming otherwise would be wrong about precisely the frameworks most enterprises are assessed against. It is the first thing the dev pack proposes to build, and it is named as unbuilt rather than implied.

A label that had to be read rather than trusted. One of the thirteen is framework:owasp-top-10, labelled "OWASP Top 10" — which reads as the web application list, a general security artefact. Listing its members shows it is not: LLM01:25 — Prompt Injection through LLM10:25 — Unbounded Consumption, the OWASP Top 10 for LLM Applications. measured 9 Sep 2026 The AI-specific finding above survives only because the members were listed instead of the label being believed. A shorthand that collides with a different, better-known standard is exactly what an anchor node exists to disambiguate.

They already use anchor nodes — which is the good news

The crosswalks do not point at frameworks. They point at anchor: nodesanchor:co-ai-act:6-1-1702-developer-duties — reached by an anchors_to edge, of which there are 489, one per distinct external control item. measured 9 Sep 2026

So the pattern this work depends on is already established in this estate and does not have to be argued for. What the dev pack proposes is a different axis of anchor, not a new mechanism: theirs anchor provisions across standards; ours would anchor obligations to the body and the place. The two compose. Neither replaces the other.

This is the discipline graphs.sgit.ai states as the sixth of its ninedon't merge vocabularies; keep them intact and bridge them through anchor nodes. Merging UnGovr's entity vocabulary into a standards vocabulary would destroy both. Bridging them costs one node class and one edge.

Sites, not vaults

Three of these publish alongside the vaults and are worth an executive's attention in their own right.

eu-ai-act.standards.riskmandate.aithe article index ↗ — the Act with the Digital Omnibus on AI applied by a deterministic, gated parser: 119 articles and 14 annexes, 72 amendment instructions each with a derivation page, and 182 touched provisions, each hash-anchored. It is explicit that no official consolidated version existed when it was generated and that only the Official Journal publications are authentic. vendor docs 9 Sep 2026 How to check a provision ↗ is the page to send a sceptic to. It is the clearest example in the estate of the thing this site is also trying to do: publish something so it can be checked rather than merely read.

graphs.sgit.aithe edge set ↗thinking in graphs and meaning through connectivity: the grammar the model in the dev pack is written to. Every edge a verb with a distinct inverse; no generic association; never render the whole graph. It is the reason the pack has fifteen named edges rather than a diagram.

sgit.ai/demos/vaults ↗ — the twenty-six published vaults, each with its own page, its read key and the audit that was run before the key was published. The seven above are a selection made for this reader; that page is the whole set.

The read keys, and why they are printed here

Every credential on this page is a read key: 64 hexadecimal characters that decrypt the vault and can do nothing else. There is no account behind it, no token to refresh, and no path from it to write access — read keys are derived one-way from a vault key that is not published and never will be. Handing one over is the intended way to share a vault, which is why sgit.ai prints them on each vault's own page. Every key below was copied from there rather than obtained privately. verified 9 Sep 2026

VaultVault idRead key, as its own page publishes it
AIUC-1 conformance layer2wzct4k7sgit_private_read_0f01d367…0db072
AIUC-1, as a graphhq21tlqusgit_private_read_4435037d…a4ae00
Regulation Graph73heuprzsgit_rk1_c004daae…1695c9
Licence to Operateposrhzp3d990a52e…b4da29 (no prefix — the oldest form)
Risk Mandate4zf6pf2zsgit_rk1_a702fba8…95c0ae
Standards Atlas — GDPR4zv4bvmusgit_rk1_439ca57a…6aa15c
Risk Graph Explorer3simlnqesgit_rk1_1c1b95f5…7e5638

The full keys are in the page source, on the cards, as data-readkey — and tools/check_site.py refuses to build if any of them is anything other than a bare 64-hex string, which is the shape a read key has and a vault key does not.

Three prefixes, one key. The cards carry bare hex and the embed component reassembles it as sgit_rk1_…, while three of these vaults publish theirs as sgit_private_read_… and one as no prefix at all. These are the same credential under three generations of naming: sgit's own Vault__Crypto names sgit_private_read_ as the read-key prefix and sgit_rk1_ as the legacy one. verified 9 Sep 2026 The table above shows each key in the form its own page publishes, so it can be compared character for character; the embed uses the legacy form because that is what the vendored component builds.

What this page does not prove

No vault on this page has been watched decrypting. written, not run 9 Sep 2026 The boundary is worth stating exactly, because half of it is checked. The picker was driven in a headless browser against a local copy of this site: seven cards, zero frames and zero connections before a pick, exactly one embed and two frames after one, still exactly one after a second — and the frame's URL carrying ?embed=1&parent=… and no credential. verified 9 Sep 2026 What that test cannot reach is what happens inside the frame. The container that built this page reaches the vault host with curl but not with a browser — Chromium gets ERR_CONNECTION_RESET through the tunnel — so no vault can actually boot here. This is the same limit that put the vault page out on unrun until somebody opened it; that claim moved because a person watched the vault come up, and that is the only thing that moves it. Until the same happens here, these seven are written, not watched.

The counts are ours, not AIUC's. Every number in What UnGovr adds was computed by opening vault 2wzct4k7 with its published read key and counting graph/edges.json — 2,293,236 bytes, sha256 984d297a971bfbed…. They are not quoted from that vault's prose, and where the two disagree the vault is right and this page is wrong.

No edge has been built. The join described here is a proposal in a dev pack with thirteen tests, of which five pass and every one of the five was inherited from work already done rather than earned by the pack. Nothing on this page asserts that UnGovr and these vaults are connected today. They are not.

AIUC-1 is not endorsing anything. The two AIUC-1 vaults are unofficial and derivative, not approved, certified or reviewed by AIUC, and not a substitute for the standard; the canonical sources are aiuc-1.com and the official changelog repository ↗. Nothing here is a compliance, certification, underwriting or legal claim about anybody.