sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · llms.sgit.ai · llms-full

On this page

Reading room / llms.sgit.ai / llms-full.txt · section 46 of 49

07 — Boundaries and licensing

1. Licensing

This site's content is CC BY 4.0, consistent with the network. Stamp every raw markdown document; gate with licence-audit.py --check.

The code quoted throughout is Apache-2.0 — SGraph-AI__App__Send and the vault-html guides carry it. Retain the notice where snippets run long, and do not imply the code carries the site's CC BY licence.

The samples in code__chat-pane-samples.md are written for this pack and are CC BY 4.0. The sg.llm.* calls inside them are the shipped API; the surrounding UI is ours. Say so, so a reader knows which half is a contract and which half is an example.


2. ⚠️ Do not create a second source of truth

The corpus already refused to do this, deliberately, and gave its reasons:

"No — and deliberately. It belongs in the two homes that already exist: AUTHORING.md — the canonical window.sg.* contract. Adding a competing document would create a second source of truth that drifts."

That was about a proposed skill, and the same logic applies to this site. A hand-written API reference on llms.sgit.ai will drift from AUTHORING.md within a release.

The resolution: AUTHORING.md stays canonical; the site generates its reference from it and says so on the page. That gives a human-readable public surface without a competing contract — which is the gap the corpus's own reasoning leaves open, since AUTHORING.md is an agent authoring contract that no human reader will find. 08__ Q1.


3. Do not publish

And a rule specific to this site: every sample must use a placeholder that is obviously a placeholder. Not a realistic-looking key. Add sk-or-, sgit_vk1_ and OpenRouter key shapes to the CI key-leak check before the first sample page ships.


4. Publish the security gap — do not soften it

03__ §5. The corpus states plainly that the CSP egress lockdown is not built and that this is "the gap that turns the current design from a convenience into a guarantee."

Publishing a known limitation of your own security design is the estate's own standard — the vault catalogue publishes its own key-exposure incident; the reality-document rule is "briefs are aspirations, not facts." A site that omitted this would be below the standard the rest of the network keeps.

Do not publish an exploitation path, and do not frame it as a vulnerability disclosure. It is a scope statement: the bridge protects the credential you trusted us with; it does not prevent all egress.


5. Network boundaries

SiteOwnsBoundary
llms.sgit.aiThe chat pane, sg.llm.*, the LLM security model, provenance, providers, local models—
sgit.aiThe vault product, the catalogue, the demosThe closest neighbour. AUTHORING.md and the vault UI belong there; the LLM capability inside them belongs here. Agree who owns the /vault chat-panel page — recommendation: this site owns the capability, sgit.ai owns the product tour
coding.sgit.aiHow code is writtenThe samples follow its component conventions. If sg-llm-chat gets built (04__ §3), that site owns the component pattern and this one owns the LLM contract
risks.sgit.ai · standards.sgit.aiRisk and instrumentsThey own the grounding ladder. State it in three lines and link out — 05__ §2
open-source.sgit.aiThe open-source positionSovereignty applies sharply to model providers ("one SLA away from losing access"); the agent-era theses are shared. Two links
graphs.sgit.aiGraph theoryRAG-over-graphs sits on the boundary. Light link
sg-compute.sgit.aiThe compute platformOwns the ollama and local_claude specs. This site links to them for the local-model story; that site owns the specs themselves
newsroom.sgit.aiThe future of newsShares training-data licensing and the fact-graph-as-training-material thread

6. House style


This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).


/briefs/08__gaps-and-open-questions.md