---
title: The estate this joins — seven vaults, running here
description: "The graph estate UnGovr's data would plug into: seven published vaults you can open in this page with nothing but a read key, the sites that publish alongside them, and the one edge that is missing from all of them."
lead: "Every vault below is **running, not screenshotted** — pick one and it decrypts in your browser from a read key printed on this page. They are here because each of them has a hole shaped like UnGovr: **an obligation with no named body, or a body with no named jurisdiction.**"
order: 6
toc: true
wide: true
provenance:
  vault: dkeclt5r @ obj-cas-imm-e23f0cecfccf
  date: 9 September 2026
  note: "Read keys copied from each vault's own published page on sgit.ai. Counts on this page were computed from the vaults themselves, not from their prose."
---

<div class="picker" id="picker" role="group" aria-label="Choose a vault to open">
<div class="vcard" data-vault="2wzct4k7" data-readkey="0f01d367b04f886f6c65038649b76504f4cd2ad06480d88a5e933a671e0db072" data-app="1" data-name="AIUC-1 conformance layer">
<b>AIUC-1 conformance layer</b><span>The standards map. 1,126 crosswalks into thirteen frameworks &mdash; and a conformance layer that keeps <i>does the standard say this</i> apart from <i>does this subject do this</i>.</span>
<div class="vact"><button type="button" class="vopen">Open it here</button><a class="vtab" href="https://dev.vault.sgraph.ai/#sgit_private_read_0f01d367b04f886f6c65038649b76504f4cd2ad06480d88a5e933a671e0db072%3A2wzct4k7" rel="noopener" target="_blank">New tab &#8599;</a></div>
</div>
<div class="vcard" data-vault="hq21tlqu" data-readkey="4435037d6936ef6986d0646ff23ed3affc46eb74bf8a65ca1f729fd5d3a4ae00" data-app="1" data-name="AIUC-1, as a graph you can cite">
<b>AIUC-1, as a graph</b><span>The catalogue the layer above forked byte for byte: 53 controls, 144 requirements, and every field naming the page it was read from with the sha256 of the bytes.</span>
<div class="vact"><button type="button" class="vopen">Open it here</button><a class="vtab" href="https://dev.vault.sgraph.ai/#sgit_private_read_4435037d6936ef6986d0646ff23ed3affc46eb74bf8a65ca1f729fd5d3a4ae00%3Ahq21tlqu" rel="noopener" target="_blank">New tab &#8599;</a></div>
</div>
<div class="vcard" data-vault="73heuprz" data-readkey="c004daae386e8d17fa648884acc527018bd4ea1116ad673fb2f1b068011695c9" data-app="1" data-name="Regulation Graph">
<b>Regulation Graph</b><span>The EU AI Act parsed from <b>official Formex XML</b>, hash-verified to the bytes it came from &mdash; 1,523 nodes, 1,944 edges, eleven views.</span>
<div class="vact"><button type="button" class="vopen">Open it here</button><a class="vtab" href="https://dev.vault.sgraph.ai/#sgit_rk1_c004daae386e8d17fa648884acc527018bd4ea1116ad673fb2f1b068011695c9%3A73heuprz" rel="noopener" target="_blank">New tab &#8599;</a></div>
</div>
<div class="vcard" data-vault="posrhzp3" data-readkey="d990a52efb9af32c8463e2962f3ca5ccf92b3b6e8ea788e55009073c29b4da29" data-app="1" data-name="Licence to Operate">
<b>Licence to Operate</b><span>One agent, a grant of 12 capabilities, a mandate of 4, and the <b>8-capability delta no policy covers</b> &mdash; with every reply priced against a live policy.</span>
<div class="vact"><button type="button" class="vopen">Open it here</button><a class="vtab" href="https://dev.vault.sgraph.ai/#d990a52efb9af32c8463e2962f3ca5ccf92b3b6e8ea788e55009073c29b4da29%3Aposrhzp3" rel="noopener" target="_blank">New tab &#8599;</a></div>
</div>
<div class="vcard" data-vault="4zf6pf2z" data-readkey="a702fba803faac4369eb5d5a320b4dfa017af62bd2425fb298aac4b99e95c0ae" data-app="1" data-name="Risk Mandate">
<b>Risk Mandate</b><span>A working application delivered <i>as</i> a vault: 124 files, 98 commits, eight entry points &mdash; and it calls an LLM without ever holding the API key.</span>
<div class="vact"><button type="button" class="vopen">Open it here</button><a class="vtab" href="https://dev.vault.sgraph.ai/#sgit_rk1_a702fba803faac4369eb5d5a320b4dfa017af62bd2425fb298aac4b99e95c0ae%3A4zf6pf2z" rel="noopener" target="_blank">New tab &#8599;</a></div>
</div>
<div class="vcard" data-vault="4zv4bvmu" data-readkey="439ca57ab9e53b4edfa67e99da1b70948c297d323376c890292dc2f0876aa15c" data-app="1" data-name="Standards Atlas — GDPR">
<b>Standards Atlas &mdash; GDPR</b><span>GDPR as a semantic graph where CJEU rulings, regulator guidance and <b>per-country variation</b> are first-class nodes layered over the articles they bend.</span>
<div class="vact"><button type="button" class="vopen">Open it here</button><a class="vtab" href="https://dev.vault.sgraph.ai/#sgit_rk1_439ca57ab9e53b4edfa67e99da1b70948c297d323376c890292dc2f0876aa15c%3A4zv4bvmu" rel="noopener" target="_blank">New tab &#8599;</a></div>
</div>
<div class="vcard" data-vault="3simlnqe" data-readkey="1c1b95f5903e35850a9bc0541ffa09c6b5d4017cbf18817d2ad6f894127e5638" data-app="1" data-name="Risk Graph Explorer">
<b>Risk Graph Explorer</b><span>A <b>fact</b>-to-risk graph explorer, built to be public: its <code>app.json</code> requests no permissions at all. The word in the middle is the one this site is about.</span>
<div class="vact"><button type="button" class="vopen">Open it here</button><a class="vtab" href="https://dev.vault.sgraph.ai/#sgit_rk1_1c1b95f5903e35850a9bc0541ffa09c6b5d4017cbf18817d2ad6f894127e5638%3A3simlnqe" rel="noopener" target="_blank">New tab &#8599;</a></div>
</div>
</div>

<div class="stage" id="stage"><p class="stage-idle"><b>Nothing has been fetched yet.</b> This page opens no connection until you pick a vault above &mdash; then exactly one, to <code>dev.vault.sgraph.ai</code>. One at a time, by design: seven vaults booting at once is a worse demonstration than one booting well. {{claim:estate-lazy}}</p></div>

<script>
/* One stage, one vault. The vendored component mounts every `.sgv-uiembed` it can
   see at the moment it is evaluated — so the stage is emptied and rebuilt before
   each eval, and only the chosen vault is ever in the DOM to be mounted. The
   component's source is fetched once and re-evaluated from memory after that, so
   picking a second vault costs no extra request for the component itself.

   Stale message listeners from a previous pick survive the eval; they are inert,
   because each checks `s.frame.contentWindow` and a removed frame has none. */
(function () {
  var root = document.documentElement.getAttribute('data-root') || '';
  var src = null, picker = document.getElementById('picker'), stage = document.getElementById('stage');
  if (!picker || !stage) return;

  function run(card) {
    stage.textContent = '';
    var host = document.createElement('div');
    host.className = 'sgv-uiembed';
    host.setAttribute('data-vault', card.getAttribute('data-vault'));
    host.setAttribute('data-readkey', card.getAttribute('data-readkey'));
    host.setAttribute('data-app', card.getAttribute('data-app') || '1');
    var h = document.createElement('p');
    h.className = 'stage-now';
    h.innerHTML = 'Open: <b></b>';
    h.querySelector('b').textContent = card.getAttribute('data-name');
    stage.appendChild(h); stage.appendChild(host);
    var all = picker.querySelectorAll('.vcard');
    for (var i = 0; i < all.length; i++) all[i].classList.toggle('on', all[i] === card);
    (0, eval)(src);
    stage.scrollIntoView({ block: 'start' });
  }

  picker.addEventListener('click', function (e) {
    var btn = e.target.closest ? e.target.closest('.vopen') : null;
    if (!btn) return;
    var card = btn.closest('.vcard');
    if (!card) return;
    if (src) { run(card); return; }
    stage.textContent = 'Loading the embed component…';
    fetch(root + 'assets/vault-ui-embed.js')
      .then(function (r) { if (!r.ok) throw new Error(r.status); return r.text(); })
      .then(function (t) { src = t; run(card); })
      .catch(function (err) {
        stage.textContent = 'The embed component failed to load (' + err.message + '). ' +
          'Every vault above still opens in its own tab from the link on its card.';
      });
  });
}());
</script>

## Why these seven, and not a link list

A link list would have been easier and would have told an executive nothing. **The point of a vault is that the credential is the whole thing** — no account, no token, no seat. Handing over a read key and having the artefact decrypt in front of you is the argument; a screenshot of it is not.

So each of these opens here, from a key printed a few lines below, and **none of it is stored on this site**. A push to any of those vaults changes what you see on this page with no rebuild and no deploy.

They were chosen on one test: **does this artefact contain an obligation, a control or a risk that currently floats free of a named body in a named place?** All seven do. That is the hole UnGovr fills, and the rest of this page is about its exact shape.

## What UnGovr adds, in one number

The AIUC-1 conformance vault is the densest standards map in the estate. Its graph was opened with the published read key and counted rather than read about: **11,610 edges**, of which **1,126 are `maps_to` crosswalks** from AIUC-1 controls out to **489 distinct control items across exactly thirteen frameworks**. {{claim:estate-aiuc-crosswalks}}

**Ninety-five of those 1,126 crosswalks point at law** — the EU AI Act (62), the Colorado AI Act (18), California SB 53 (9) and NYC Local Law 144 (6). **Three of those four laws are sub-national United States jurisdictions.** {{claim:estate-aiuc-law-share}}

That is the whole argument on one line. A crosswalk that ends at *the Colorado AI Act* is a statement about a text. It is not yet a statement about **which bodies in Colorado it binds**, and no vault in this estate can answer that today. UnGovr's index is keyed on exactly that axis — `us/co`, `us/ca`, `us/ny/new-york` — which is why the connection is worth building and why it is **one edge**, not a project.

| The estate has | UnGovr has | Missing |
|---|---|---|
| control → law crosswalk | body → jurisdiction, with a slug | law → **the bodies it binds** |
| an obligation with a deadline set by an attestation's expiry | a deadline set by **statute** | which of the two governs |
| `unevidenced` as the default answer | a public-records law string per body | whether the record can be *asserted* to exist |

**The dev pack for this work is [published in full](/packs/security-graph/)** — eight files: the anchor-node thesis, the model with fifteen edges and their inverses, the standards map above with its working, a worked example, the integration surface, and thirteen tests of which five currently pass, all inherited. It lives in `packs/security-graph/` in the government-graph vault and is republished here byte for byte.

## The second finding, which is a gap rather than a number

**Not one general security control set appears in AIUC-1's thirteen.** No NIST CSF, no SP 800-53, no ISO/IEC 27001 or 27002, no SOC 2, no CIS Controls, no PCI DSS, no HIPAA, no FedRAMP. Every one of the thirteen is AI-specific. {{claim:estate-aiuc-ai-only}}

That is not a defect in AIUC-1 — it is an agent standard and the AI corpus is the right scope for it. But it does mean that **the general-security half of any security-standards map is genuinely absent from this estate**, and anyone assuming otherwise would be wrong about precisely the frameworks most enterprises are assessed against. It is the first thing the dev pack proposes to build, and it is named as unbuilt rather than implied.

> **A label that had to be read rather than trusted.** One of the thirteen is `framework:owasp-top-10`, labelled *"OWASP Top 10"* — which reads as the web application list, a general security artefact. Listing its members shows it is not: `LLM01:25 — Prompt Injection` through `LLM10:25 — Unbounded Consumption`, the **OWASP Top 10 for LLM Applications**. {{claim:estate-owasp-label}} The AI-specific finding above survives only because the members were listed instead of the label being believed. **A shorthand that collides with a different, better-known standard is exactly what an anchor node exists to disambiguate.**

## They already use anchor nodes — which is the good news

The crosswalks do not point at frameworks. They point at **`anchor:` nodes** — `anchor:co-ai-act:6-1-1702-developer-duties` — reached by an `anchors_to` edge, of which there are **489**, one per distinct external control item. {{claim:estate-anchor-pattern}}

So the pattern this work depends on is **already established in this estate and does not have to be argued for**. What the dev pack proposes is a different *axis* of anchor, not a new mechanism: theirs anchor **provisions across standards**; ours would anchor **obligations to the body and the place**. The two compose. Neither replaces the other.

This is the discipline `graphs.sgit.ai` states as [the sixth of its nine](https://graphs.sgit.ai/v1/grammar/edge-set.html) — *don't merge vocabularies; keep them intact and bridge them through anchor nodes.* Merging UnGovr's entity vocabulary into a standards vocabulary would destroy both. Bridging them costs one node class and one edge.

## Sites, not vaults

Three of these publish alongside the vaults and are worth an executive's attention in their own right.

**`eu-ai-act.standards.riskmandate.ai` — [the article index ↗](https://eu-ai-act.standards.riskmandate.ai/articles.md)** — the Act with the Digital Omnibus on AI applied by a deterministic, gated parser: **119 articles and 14 annexes**, 72 amendment instructions each with a derivation page, and **182 touched provisions, each hash-anchored**. It is explicit that no official consolidated version existed when it was generated and that only the Official Journal publications are authentic. {{claim:estate-euaiact-site}} [How to check a provision ↗](https://eu-ai-act.standards.riskmandate.ai/verify.md) is the page to send a sceptic to. It is the clearest example in the estate of the thing this site is also trying to do: **publish something so it can be checked rather than merely read.**

**`graphs.sgit.ai` — [the edge set ↗](https://graphs.sgit.ai/v1/grammar/edge-set.html)** — *thinking in graphs* and *meaning through connectivity*: the grammar the model in the dev pack is written to. Every edge a verb with a distinct inverse; no generic association; never render the whole graph. It is the reason the pack has fifteen named edges rather than a diagram.

**[sgit.ai/demos/vaults ↗](https://sgit.ai/demos/vaults/index.html)** — the twenty-six published vaults, each with its own page, its read key and the audit that was run before the key was published. The seven above are a selection made for this reader; that page is the whole set.

## The read keys, and why they are printed here

Every credential on this page is a **read key**: 64 hexadecimal characters that decrypt the vault and can do nothing else. There is no account behind it, no token to refresh, and **no path from it to write access** — read keys are derived one-way from a vault key that is not published and never will be. Handing one over is the intended way to share a vault, which is why sgit.ai prints them on each vault's own page. Every key below was copied from there rather than obtained privately. {{claim:estate-keys-published}}

| Vault | Vault id | Read key, as its own page publishes it |
|---|---|---|
| AIUC-1 conformance layer | `2wzct4k7` | `sgit_private_read_0f01d367…0db072` |
| AIUC-1, as a graph | `hq21tlqu` | `sgit_private_read_4435037d…a4ae00` |
| Regulation Graph | `73heuprz` | `sgit_rk1_c004daae…1695c9` |
| Licence to Operate | `posrhzp3` | `d990a52e…b4da29` *(no prefix — the oldest form)* |
| Risk Mandate | `4zf6pf2z` | `sgit_rk1_a702fba8…95c0ae` |
| Standards Atlas — GDPR | `4zv4bvmu` | `sgit_rk1_439ca57a…6aa15c` |
| Risk Graph Explorer | `3simlnqe` | `sgit_rk1_1c1b95f5…7e5638` |

The full keys are in the page source, on the cards, as `data-readkey` — and `tools/check_site.py` refuses to build if any of them is anything other than a bare 64-hex string, which is the shape a read key has and a vault key does not.

> **Three prefixes, one key.** The cards carry bare hex and the embed component reassembles it as `sgit_rk1_…`, while three of these vaults publish theirs as `sgit_private_read_…` and one as no prefix at all. These are the same credential under three generations of naming: sgit's own `Vault__Crypto` names `sgit_private_read_` as the read-key prefix and `sgit_rk1_` as the **legacy** one. {{claim:estate-legacy-prefix}} The table above shows each key in the form its own page publishes, so it can be compared character for character; the embed uses the legacy form because that is what the vendored component builds.

## What this page does not prove

**No vault on this page has been watched decrypting.** {{claim:estate-embeds-unrun}} The boundary is worth stating exactly, because half of it *is* checked. The picker was driven in a headless browser against a local copy of this site: seven cards, **zero frames and zero connections before a pick**, exactly one embed and two frames after one, still exactly one after a second — and the frame's URL carrying `?embed=1&parent=…` and **no credential**. {{claim:estate-lazy}} What that test cannot reach is what happens *inside* the frame. The container that built this page reaches the vault host with `curl` but not with a browser — Chromium gets `ERR_CONNECTION_RESET` through the tunnel — so no vault can actually boot here. This is the same limit that put [the vault page](/vault/) out on `unrun` until somebody opened it; that claim moved because a person watched the vault come up, and **that is the only thing that moves it**. Until the same happens here, these seven are written, not watched.

**The counts are ours, not AIUC's.** Every number in *What UnGovr adds* was computed by opening vault `2wzct4k7` with its published read key and counting `graph/edges.json` — 2,293,236 bytes, sha256 `984d297a971bfbed…`. They are not quoted from that vault's prose, and where the two disagree the vault is right and this page is wrong.

**No edge has been built.** The join described here is a proposal in a dev pack with thirteen tests, of which five pass and every one of the five was inherited from work already done rather than earned by the pack. Nothing on this page asserts that UnGovr and these vaults are connected today. They are not.

**AIUC-1 is not endorsing anything.** The two AIUC-1 vaults are unofficial and derivative, not approved, certified or reviewed by AIUC, and not a substitute for the standard; the canonical sources are `aiuc-1.com` and [the official changelog repository ↗](https://github.com/aiunderwriting/AIUC-1-Changelog). Nothing here is a compliance, certification, underwriting or legal claim about anybody.

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
