# Design documents

> The brief that this site is built from, what it got wrong, and the four documents that carry the reasoning. Copied in verbatim; the markdown is the source of truth and the HTML is rendered from it on every release.

*Source: <https://secrets.sgit.ai/docs/design/> · site v0.1.2 (2026-10-05) · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.*

---

The brief that this site is built from, what it got wrong, and the four documents that carry the reasoning. Copied in verbatim; the markdown is the source of truth and the HTML is rendered from it on every release.

- [Brief corrections](/docs/design/brief-corrections.md): What the brief got wrong or left open, found while building, dated, beside it. [(markdown)](/docs/design/brief-corrections.md)
- [Risk Mandate — AWS Cognito Client-Side Architecture](/docs/design/riskmandate-aws-cognito-architecture.md): The AWS variant; why no secret can live inside an identity provider; the attack table. [(markdown)](/docs/design/riskmandate-aws-cognito-architecture.md)
- [Risk Mandate — GCP Key Vault Architecture & Password Manager MVP](/docs/design/riskmandate-gcp-key-vault-password-manager-mvp.md): The primary design: all-GCP stack, keyring, PRF unlock, sharing scheme, storage layout, threat summary, password-manager MVP scope. [(markdown)](/docs/design/riskmandate-gcp-key-vault-password-manager-mvp.md)
- [Risk Mandate — User Onboarding & Account Experience](/docs/design/riskmandate-user-onboarding-account-experience.md): The Workspace-based onboarding design, the Google terms research, and the five-tier model that led here. [(markdown)](/docs/design/riskmandate-user-onboarding-account-experience.md)
- [Risk Mandate — Google Workspace as Identity, Storage and Deployment Substrate](/docs/design/riskmandate-workspace-architecture-briefing.md): The earlier Workspace architecture briefing. [(markdown)](/docs/design/riskmandate-workspace-architecture-briefing.md)
- [secrets.sgit.ai — MVP build brief](/docs/design/secrets-sgit-ai__mvp-build-brief.md): The instruction set: architecture, environments, the site, the keyring specification, the pipeline, the build order. [(markdown)](/docs/design/secrets-sgit-ai__mvp-build-brief.md)

---

*[Site index for agents](/llms.txt) · [What is real](/docs/reality.md) · [HTML version](https://secrets.sgit.ai/docs/design/)*
