Participant disclosure
This site is published by the people building the thing it describes. Read its claims with that in mind.
secrets.sgit.ai is part of the sgit.ai family of sites, published by Dinis Cruz and the sgit team, and built in the open by a Claude Code session working from a published brief. The secrets manager it describes is the key-vault layer under sgit and Risk Mandate, both of which the same people build. The site therefore has an interest in the design being right, and in it being adopted.
What that means for the reader
- Every claim carries a status from
data/features.json: shipped with a version, proposed, or absent. The shipped page and docs/reality.md are generated from it and cannot disagree with each other or with the pages. - The brief this site was built from is published in full, with what it got wrong beside it, so the site can be checked against something other than its own claims.
- The security argument is a design until the acceptance test is run and its write-up published, whatever the result; the security page says so in its own status line.
- Everything in the repository is public, including the configuration of every environment and the review graphs of the code, at the repository.
Who did what
The design documents were written by Dinis Cruz with AI co-authorship in October 2026. The site, its pipeline and its content pages are written by a Claude Code session under the rules in the build agent's role file; the person's decisions are recorded in the project lead's. Content is CC BY 4.0; code is Apache-2.0.