Reading a vault from a *.sgit.ai site page, build brief
For devs coding the estate’s sites: the vault API answers plain CORS GETs with no auth header, so a site page reads ciphertext directly and decrypts in the visitor’s browser. The house reader to copy rather than rewrite, the trust rule that inverts on this surface, the ref-caching trap, and the prompt to hand the site’s agent.
Home↗ / Briefs↗ / Reading a vault from a site page
Surface: a page on a *.sgit.ai site, outside every vault host. The other two surfaces → ↗