What is actually shipped
Every site on this network ships one of these. This is the unsoftened version, and it is deliberately the least flattering page here — because a site whose thesis is point at the provision instead of asserting has to survive the same standard being applied to its own claims.
One instrument is modelled. One. Zero crosswalks exist. There is no GDPR graph, no control catalogue, and no file export on any vault on this estate.
Where each piece stands
| Thing | State | Detail |
|---|---|---|
| The method | published | The grammar, the two-hash scheme, bridges-not-merges, authority anchoring, the citation scheme, the grounding ladder. The only material here that is itself the product |
| EU AI Act | modelled, with weaknesses stated | 1,523 nodes, 1,944 edges in a shipped vault. Readings are secondarily sourced; operative text is withheld pending re-derivation; the vault has two commits and no amendment history |
| The citation resolver | shipped | T4. Client-side, sixty lines, no backend. Resolves an address to a record — which is the smallest useful version of it |
| The agentic-access subset | a curated table, not a computed view | Eight instruments; one of them is modelled here. Nothing recomputes when the other seven change |
| GDPR | method only | Two white papers. No vault, no graph, zero provisions. Verified against eight independent sources |
| ISO/IEC 27001 | blocked on a design question | Cannot hold the text. Whether the model can hold a standard it cannot quote is unanswered |
| ISO 31000 | nothing | Zero occurrences in the source material. One paragraph saying so |
| Crosswalks | zero | The single biggest gap → |
| Zip / SQLite distribution | not built anywhere | On any of the twelve published vaults. Net-new across the estate |
| The keys vault | policy published, vault not confirmed built | The policy and the recursion are published; whether the vault exists is not this site's to assert |
The gaps, numbered
Nine things must be built fresh. Nothing in the material behind this site covers them.
| # | Gap | Why it is a gap rather than a task |
|---|---|---|
| G1 | Any crosswalk at all | The material describes crosswalks beautifully — bridges not merges, FrameworkReference nodes, “do this here, satisfy that there” — and contains zero completed mappings. Named as obviously valuable and never done: AI Act ↔ GDPR, ISO 27001 ↔ SOC 2, GDPR ↔ NIS2 incident reporting. This is the biggest single gap on the site |
| G2 | A control catalogue in machine-readable form | No controls file, no requirement schema instance, no JSON or YAML of anything. The only requirement-to-node binding anywhere is one illustrative line in an example |
| G3 | The GDPR graph | Two white papers describe how to build it. The rulings, the guidance and the per-country variation are the graph, and none of that layer is assembled |
| G4 | Zip and SQLite distribution | Not one of the twelve published vaults offers an export. The delivery mechanism is entirely net-new |
| G5 | A stable citation scheme | Closed by this site. The scheme and the resolver ship — the first of the nine to close |
| G6 | A timeline / dates structure | The need is established — “a graph that carries those dates as properties is materially more useful than one that carries only text” — and four AI Act application dates are named in prose and modelled nowhere |
| G7 | An amendment-detection pipeline | No detection, no re-derivation trigger, no staleness monitor. The business argument rests entirely on a mechanism that does not exist |
| G8 | Certification and attestation mechanics | A site called “standards” will be asked how an attestation actually gets issued. Conformity assessment appears in three files; attestation appears in eighty-eight and almost entirely in the cryptographic sense |
| G9 | PUBLIC.md as a real convention | On 2 of 12 live vaults, and absent from the source corpus entirely. Treating it as established would be overstating it |
Eight tensions, held rather than resolved
- This site is called “standards” and is three-quarters law. Managed by making the distinction the opening argument — but it stays a tension, and a reader who notices it should find it already named rather than concealed.
- The best content and the biggest legal blocker are the same subject. ISO is what people search for and the one thing that cannot be published. The interesting response is a page about the paywall; the boring one is a thin stub.
- Encryption is the product and clear text is what enables verification. A vault-native project whose flagship standards site needs greppable, archivable, citable text has genuinely competing goods here. Published as a fork →
- “The amendment is the business model” — and the flagship vault has two commits. The most valuable property is the one least demonstrated.
- This project criticises secondary sourcing and is itself secondarily sourced. It says so, twice, unprompted. Publishing the self-criticism is right; shipping citations that are still secondary is not.
- Evidence, not verdicts — but people want verdicts. The refusal is the differentiator. It is also the standing sales objection, and naming it now is cheaper than discovering it in a meeting.
- A keys vault concentrates every credential into one artefact. Right trade, real single point of failure, and the recursion has to be answered outside the system.
- One instrument done properly is a stronger position than five done thinly, and reads as less. The conclusion this project reached itself: “one instrument, done properly, with its working shown and its verification openly incomplete.” Resist filling the shelf.
The warning this site is most exposed to
That applies to this site more than to any other on the network, because this is the one with the word standards in its name. Three things follow, and they are enforced rather than intended: no tool here outputs a pass, a score or a percentage; no page says “compliant”, “meets” or “satisfies” without naming the evidence and the measure; and the machine surface carries the same rule for agents. The mechanism → · the disclosure →