# Published vaults on sgit.ai > The catalogue of encrypted vaults published at https://sgit.ai/demos/vaults/index.html, > generated at build time (v0.6.8) from the same file the table on that page is built > from, so this list and that table cannot drift apart. > > Every vault below is opened by a READ KEY: a 64-character hex string and a vault id, derived > one-way from a vault key that is never published. A read key is the complete credential: > no account, no token, nothing to install. `sgit clone ` from the CLI, or open it at > https://dev.vault.sgraph.ai/#. > > The server stores ciphertext under opaque ids and cannot read any of this. How a browser > reads one file out of a vault is written up at /vault/reading-a-vault-file.md. ## The vaults (36) - **#36 Company X-Ray**: A business plan for reading a company's own documents together, with one invented company X-rayed and every finding tied to its evidence - page: /demos/vaults/company-xray/index.md - id `ukpqjkly` · Briefing · published 2026-09-24 · 710 KB · 60 files - read key: `sgit_public_read_6da900d8edd0abd580452a85f6bbe588474cecf21e5f7cbbbbad57d1bf228454:ukpqjkly` - **#35 Lesson Loop**: A business plan for coaches: the coach's knowledge captured at the end of every lesson, in a record the player holds - page: /demos/vaults/lesson-loop/index.md - id `3s9q7zl7` · Briefing · published 2026-09-24 · 407 KB · 27 files - read key: `sgit_public_read_2d397a3a06c235452300c55375ebe8e470ba70a1a5263dc72679f8a78c42dfc1:3s9q7zl7` - **#34 Risk Acceptance Office**: A business plan with one risk replayed: established on facts, accepted for an interval, escalated, funded and ended on facts - page: /demos/vaults/risk-acceptance/index.md - id `odn10gfp` · Briefing · published 2026-09-24 · 673 KB · 32 files - read key: `sgit_public_read_3e6f04360f083cff58daa851a63d6d0fcc7f6eadb5bdca7c57acef6ef15bc93e:odn10gfp` - **#33 Connector Twin**: A business plan with a working replay: what an agent did through Gmail and Calendar, what it saw, and what can be undone - page: /demos/vaults/connector-twin/index.md - id `7tkvspwp` · Briefing · published 2026-09-24 · 515 KB · 31 files - read key: `sgit_public_read_4fb639e76d976d691c7655060e74f6d7fe13a7b96ea77d9230446977e5cdf860:7tkvspwp` - **#32 Agent as Webmaster**: A complete business plan, with mock-ups and prototypes, written for somebody else to run - page: /demos/vaults/agent-webmaster/index.md - id `ikrqeu5t` · Briefing · published 2026-09-23 · 666 KB · 32 files - read key: `sgit_public_read_d5ba4a106276936456b0a108b3988aa777f5402ba6699fcd67becd620fe55828:ikrqeu5t` - **#31 DSIT AI Risk Toolkit**: Start with an AI decision and trace it back to UK DSIT guidance; an eight-slide walkthrough plays from the vault - page: /demos/vaults/dsit-ai-risk-toolkit/index.md - id `0q4sfr57` · Reference · published 2026-09-20 · 12.1 MB · 155 files - read key: `sgit_public_read_cdc00d2baaf75361d86ae1b7a40169bd98d71aaae1bd581e181a0f0ba0e0e6bb:0q4sfr57` - **#30 Fractional CISO application pack**: The sibling of #29, written for an archetype instead of a company, so there is nothing to redact. Two days a month, a twelve-month map, and a section that says what the role is not - page: /demos/vaults/fractional-ciso-pack/index.md - id `eaba68j5` · Briefing · published 2026-09-18 · 19 MB · 72 files - read key: `sgit_public_read_7c84275ebcbbf312dbbec4713a00c83fb0dd8520b6a52b082d7ff81e3523c40e:eaba68j5` - **#29 Interim CISO application pack**: A job application as a vault, three routes for three readers, four documents in four formats each, and the client named nowhere - page: /demos/vaults/interim-ciso-pack/index.md - id `8brojsem` · Briefing · published 2026-09-17 · 17 MB · 56 files - read key: `sgit_public_read_699401f6cb3bdb1d6e19bfa690d8e0006a5379070ff320b5a8ae2fc21968f5c9:8brojsem` - **#28 Synthetic users · riskmandate.ai**: The same method as #27 pointed at a second product, and it measured rather than narrated, catching a shipped bug every existing test had passed over - page: /demos/vaults/synthetic-users-riskmandate/index.md - id `o3q6zhtr` · Analysis · published 2026-09-16 · 3.5 MB · 53 files - read key: `sgit_public_read_a41174009cf6f3019147040ef0c759b6c84c86ffa37eb54af06011c161a12332:o3q6zhtr` - **#27 Synthetic users**: Five invented buyers walked through store.sgit.ai one screenshot at a time, 43 steps, 15 unanswered questions, 18 findings, three costing a sale - page: /demos/vaults/synthetic-users/index.md - id `g2hei4u6` · Analysis · published 2026-09-15 · 6.4 MB · 67 files - read key: `sgit_public_read_b70c317b7aa4b6084e05669795dc89e6bf1e46b4e948b9f6c475948ae502823c:g2hei4u6` - **#26 The sgit.ai board**: The site's own task board as a vault, cards as files, five columns as an app, the source of truth the site renders from - page: /demos/vaults/board/index.md - id `pdulwi6i` · Record · published 2026-09-07 · 40 KB · 21 files - read key: `sgit_public_read_f41d03b0de550479b3c4359709130386df48f34b2cd75e5ed83de28e9776b479:pdulwi6i` - **#25 Agent permission games**: Two games about grants and mandates, the first vault here that phones home - page: /demos/vaults/agent-permission-games/index.md - id `4evnlwrj` · Application · published 2026-09-06 · 2.6 MB · 68 files - read key: `sgit_public_read_f94c8b1d42352d95703ac3d39032735d9b4e388d16ab5b87c948928d8e111118:4evnlwrj` - **#24 AIUC-1 conformance layer**: The AIUC-1 standard as a graph, plus a conformance layer that computes insurability - page: /demos/vaults/aiuc-1-conformance/index.md - id `2wzct4k7` · Reference · published 2026-09-05 · 43 MB · 649 files - read key: `sgit_public_read_0f01d367b04f886f6c65038649b76504f4cd2ad06480d88a5e933a671e0db072:2wzct4k7` - **#23 Licence to Operate**: An insurance policy for an agent, simulated: grant, mandate, and the delta nothing covers - page: /demos/vaults/licence-to-operate/index.md - id `posrhzp3` · Analysis · published 2026-09-04 · 13 MB · 121 files - read key: `sgit_public_read_d990a52efb9af32c8463e2962f3ca5ccf92b3b6e8ea788e55009073c29b4da29:posrhzp3` - **#22 VoiceDebrief pitch (FI)**: A three-minute investor pitch as a presenter app, with script, timings and sources - page: /demos/vaults/voicedebrief-pitch/index.md - id `95i2xqrd` · Presentation · published 2026-09-02 · 17 MB · 48 files - read key: `sgit_public_read_23cbc4c65c24cb23ef3efb78e34593391c6709f0106ea81799aa14fe97f4d211:95i2xqrd` - **#21 Scaling Threat Modeling**: ThreatModCon 2025: eleven linked threat models across 51 nodes and 179 threats - page: /demos/vaults/threatmodcon-2025/index.md - id `0ict6flm` · Presentation · published 2026-08-27 · 4.1 MB · 53 files - read key: `sgit_public_read_23fb205247b2b9c88a943d7ffece9dacf9c00c50cc94840668b4916f247b8ec4:0ict6flm` - **#20 AI vs. AI, Black Hat EU 2025**: The Black Hat EU 2025 keynote, with its PDF exports and eight research papers - page: /demos/vaults/blackhat-eu-2025/index.md - id `k1izvg7e` · Presentation · published 2026-08-27 · 20 MB · 87 files - read key: `sgit_public_read_147fa50d3c491aeea3e700d60ef21ea2897884e263700d95765dc8f624dc59ac:k1izvg7e` - **#19 Standards Atlas, GDPR**: GDPR as a semantic graph, with writes scoped to a feedback folder - page: /demos/vaults/standards-atlas-gdpr/index.md - id `4zv4bvmu` · Reference · published 2026-08-25 · 6.3 MB · 116 files - read key: `sgit_public_read_439ca57ab9e53b4edfa67e99da1b70948c297d323376c890292dc2f0876aa15c:4zv4bvmu` - **#18 RiskMandate · File security**: An eleven-step risk-acceptance walk, running SQLite in the browser - page: /demos/vaults/riskmandate-file-security/index.md - id `wu365g94` · Analysis · published 2026-08-25 · 2.7 MB · 71 files - read key: `sgit_public_read_e8a1e664b9f984b0d8df442f463231077d455d7cbaa3e336610b14f9a1e1dc77:wu365g94` - **#17 Penetration Test Report**: A penetration test report (fictional) with a re-test script per finding - page: /demos/vaults/pentest-report/index.md - id `o4lrwx02` · Report · published 2026-08-25 · 6.4 MB · 93 files - read key: `sgit_public_read_14042259ecbec2d0c7c4e68963695c4ceeeeb652767d25b777024a4f05ccd025:o4lrwx02` - **#16 SG/Payments Brief Pack**: A payments briefing pack, marked PROPOSED rather than dressed as decided - page: /demos/vaults/payments-brief-pack/index.md - id `o3m0sz3q` · Briefing · published 2026-08-25 · 224 KB · 18 files - read key: `sgit_public_read_cd1987b87f719c2ff6da51128200665312afaeeadcbf7a1a20f870f03f9959f8:o3m0sz3q` - **#15 Content-Transformation Proxy**: An as-built engineering brief, shipped with its slides, diagrams and source PDFs - page: /demos/vaults/content-transformation-proxy/index.md - id `3c90c2bff2b1` · Briefing · published 2026-08-25 · 63 MB · 140 files - read key: `sgit_public_read_18bf8b2aa558fec879edb39c79ee66d6b9594ada2dff71039b3f66f5b14e4839:3c90c2bff2b1` - **#14 SG Commercialisation**: A commercial operating model, with its customer register deliberately left empty - page: /demos/vaults/commercialisation/index.md - id `haeu7p1e` · Briefing · published 2026-08-25 · 536 KB · 78 files - read key: `sgit_public_read_3c8cba7edd2f14e63d0b0f0da4d513430e3eea06f364baefaf8b22d85e151da6:haeu7p1e` - **#13 Vault App Mode**: Nine proofs of concept for vault app mode, with a hub that runs them - page: /demos/vaults/vault-app-pocs/index.md - id `xth1xt78` · Reference · published 2026-08-23 · 251 KB · 57 files - read key: `sgit_public_read_05f2391f22e4135ea27bca6b697dca18c54ab91b046325bef74f62f5324b8bc8:xth1xt78` - **#12 Private Health Score**: A clinical questionnaire scored by a versioned framework, with a clinician review screen - page: /demos/vaults/health-score/index.md - id `zc6abngv` · Application · published 2026-08-23 · 1.2 MB · 35 files - read key: `sgit_public_read_a76f327fb602f1619a67a15a0b756d69e82a1f7fa48438d4b6ecbebae2dc3d40:zc6abngv` - **#11 VoiceDebrief**: Four apps in one vault, from raw recording to structured debrief - page: /demos/vaults/voice-debrief/index.md - id `k6xy9z4d` · Analysis · published 2026-08-22 · 1.2 MB · 92 files - read key: `sgit_public_read_31e8196d3e83b37277083c29f105b8310dbac4569e22715b5e0f85d46878eec1:k6xy9z4d` - **#10 Regulation Graph**: The EU AI Act parsed from Formex into an evidence graph, article by article - page: /demos/vaults/regulation-graph/index.md - id `73heuprz` · Reference · published 2026-08-20 · 14.9 MB · 207 files - read key: `sgit_public_read_c004daae386e8d17fa648884acc527018bd4ea1116ad673fb2f1b068011695c9:73heuprz` - **#9 Risk Mandate**: A working software project delivered as a vault, and it calls an LLM holding no API key - page: /demos/vaults/risk-mandate/index.md - id `4zf6pf2z` · Application · published 2026-08-17 · 1.9 MB · 124 files - read key: `sgit_public_read_a702fba803faac4369eb5d5a320b4dfa017af62bd2425fb298aac4b99e95c0ae:4zf6pf2z` - **#8 Risk Graph Explorer**: A fact-to-risk graph explorer, built to be public: its app.json requests nothing - page: /demos/vaults/risk-graph-explorer/index.md - id `3simlnqe` · Application · published 2026-08-17 · 428 KB · 33 files - read key: `sgit_public_read_1c1b95f5903e35850a9bc0541ffa09c6b5d4017cbf18817d2ad6f894127e5638:3simlnqe` - **#7 Agentic Browser Isolation**: Should an agent browse with your logged-in sessions? A living risk graph, per stakeholder - page: /demos/vaults/agentic-browser-isolation/index.md - id `0610gsp9` · Analysis · published 2026-08-17 · 2.4 MB · 104 files - read key: `sgit_public_read_92cad4cea8f58c55f59b686c71c935225a1ba7c41ecb6922a8aa570467604f6e:0610gsp9` - **#6 Supplement Stack**: A patient-held health record: a real regimen, label photos, totals against UK RNIs - page: /demos/vaults/supplement-stack/index.md - id `r7zes477` · Record · published 2026-08-16 · 2.3 MB · 23 files - read key: `sgit_public_read_047186b559528058c66d1792b7345639b1238cb95c166d1d5f5b65c59813c2ee:r7zes477` - **#5 Strategy Maps**: The SG/Send strategy in seven Wardley maps, plus the sgit positioning analysis - page: /demos/vaults/strategy-maps/index.md - id `ookq4mn4` · Analysis · published 2026-08-16 · 830 KB · 33 files - read key: `sgit_public_read_451c4c1e28fbb24a7f350bb3f107b2c103d69ed363167029ef9c9000ff76c07b:ookq4mn4` - **#4 Field Notes**: Six studies with generative SVG art, the smallest complete vault app - page: /demos/vaults/field-notes/index.md - id `4bshby5n` · Application · published 2026-08-16 · 11 KB · 4 files - read key: `sgit_public_read_2848993a68c02a33ea5582902c391901191e53680d35b36c0e76185d4107ad81:4bshby5n` - **#3 Deploy Docs**: Living deployment documentation, updated by an sgit push with no site deploy - page: /demos/vaults/deploy-docs/index.md - id `fyofmkvr` · Record · published 2026-08-16 · 25 KB · 17 files - read key: `sgit_public_read_8d01421290efc3fa03205eced0534335a06ae209d627555b3dde136b878e3de1:fyofmkvr` - **#2 The Vault Catalogue**: An index of published vaults that is itself a vault, and lists itself - page: /demos/vaults/catalogue/index.md - id `kc67yhgw` · Record · published 2026-08-16 · 11 KB · 9 files - read key: `sgit_public_read_fd71e4bde7232498e43a5da869b1501260d9d403031b20af87b5bc801bdf6280:kc67yhgw` - **#1 Algarve · May 2026**: A travel diary: twenty photographs in three sizes and an eight-chapter narrative - page: /demos/vaults/algarve-may-2026/index.md - id `3d04e6b9ca98` · Gallery · published 2026-08-16 · 29 MB · 71 files - read key: `sgit_public_read_0a0f34839d737eef0f8f66e5236990b1f397af064763e3f71dca2717015f9d15:3d04e6b9ca98` ## How these were published - [Publishing a vault: the method](/demos/vaults/publishing.md), the seven steps behind every row above. - [The vault catalogue](/catalogue/index.md), the same index, rendered live from a vault that indexes vaults. - [Reading one file out of a vault](/vault/reading-a-vault-file.md), the primitive under every live embed here.