standards.sgit.ai / about / participant

Participant disclosure, and where this approach loses

This site is published by a project that sells the vault layer these instruments are delivered on. It also argues, at length, that nobody should trust a claim they cannot check. Both of those are true at once, so the interests are stated here rather than left to be inferred.

The disclosure

We are a participant, not an observer. The sgit project builds the encrypted vault layer that the instrument vaults run on. A site arguing that vaults are the right substrate for normative material is a site arguing for its publisher's product. That does not make the argument wrong, and it does mean you should hold it to the same standard this site holds everything else to: can you check it?

The check is available. The graph is JSON you can fetch, the positional hashes are recomputable with one shell command, the source documents are published raw, the site is a git repository with a public history, and the gaps are listed more prominently than the achievements.

And a harder version of the same problem

A participant cannot own the register.

This is the project's own conclusion about a related idea, and it applies here. A body that assesses conformity has to be independent of the thing being assessed; a body that publishes the instruments against which assessments are made is in a weaker but real version of the same position. Which is one more reason nothing here outputs a verdict — not out of caution, but because a verdict issued by a participant would be worth nothing even if it were correct.

The sales objection, named in advance

Everybody else sells verdicts. Verdicts are the thing nobody can defend. That is the differentiator, and it is also the standing objection — a buyer of anything called “Standards As A Service” will ask whether they pass, and the answer here is that this does not answer that question. Naming it now is cheaper than discovering it in a meeting, and a reader who wants a percentage should know before they read further that they will not get one. Why →

Where this approach loses

Six honest cases, because a page that only lists strengths is an advertisement.

SituationWhat loses, and to what
You need an answer this afternoonA commercial compliance product will give you a structured answer today. This gives you one modelled instrument, a method, and a list of what is missing. If a deadline is the constraint, this loses.
You need coverage across many instrumentsOne instrument is modelled. Commercial mapping databases cover hundreds. Breadth is not the argument here and pretending otherwise would be the first dishonest sentence on the site.
You need ISO textYou will have to buy it. This site cannot give it to you, and a competitor who appears to is either licensed or is about to have a problem
Your auditor wants a percentageThere is not one, and there will not be. A finding that points at a provision is more defensible and less convenient
You want a maintained commercial productThis is a published method and one instrument, maintained by a small project. The amendment-detection pipeline that would keep it current does not exist — gap G7, and it is the gap that most undermines the value proposition
You are checking whether anyone did this firstThey did. NIS2Onto, PrivComp-KG, the Maryland GDPR + PCI ontology, OSCAL and ClauseMatch are all named, with what each got right. A claim of being first would be false and would be caught

AI co-authorship

The writing on this site was produced with AI assistance, attributed to Dinis Cruz with AI co-authorship, and the source documents carry the same attribution. That matters here more than it would elsewhere for one reason: this site's central argument is that a model asked to assess compliance will produce a plausible answer. The grounding ladder is the mechanism that makes that harder — and it applies to the pages as much as to the tools, which is why operative text is withheld pending re-derivation and why a disputed number is left off a page rather than resolved by guessing.

Licence and corrections

All content CC BY 4.0. Reuse it with attribution. If something here is wrong — a citation, a hash, a characterisation of a prior art project, a claim about what is shipped — the repository is public and a correction is a pull request. A site that asks to be checked has to make checking cheap.