pki.sgit.ai / origins

Origins: February to August 2026

Until now this site presented itself as if it began five days ago. It did not. PKI work in this project runs from February 2026, changed direction four times, built things that were retired, and specified things that were never coded. A site that argues for provenance discipline owes a reader its own — so here it is, with the primary sources.

How this section is grounded. The arc below comes from a Librarian cross-reference review of the corpus repository at v0.33.61 — roughly 110 PKI-relevant documents against roughly 3,900 lines of PKI and crypto code. That review is not published as written: it names a customer and unremediated findings against running code. A redacted public edition is, and it states exactly what was removed and why. The thirteen documents below are published verbatim.

The number that frames everything

PKI thinkingPKI shipping
Volume~110 documents · ~265,000 words~3,900 lines of code
WrittenFebruary 2026 – August 2026, continuously20–22 February 2026, a six-day burst
Changed sinceConstantlyNot materially
In the productDescribed throughoutNone — the paths users touch are symmetric only

A prior review measured this project's proposal-to-build ratio at roughly 5–9× in March 2026. For PKI specifically it is considerably worse. That is not a criticism to bury — it is the reason this site exists: publishing the design before the implementation only means something if you also publish how much design is already stacked up behind it.

Four acts, and three changes of direction

   Feb 2026    PKI as MESSAGING        recipient-addressed encryption
   Mar 2026    PKI as PROVENANCE       commit signing, document identity
   Jun 2026    PKI as AGENT IDENTITY   NHI 2.0, vault-to-vault, brokered kernels
   Jul–Aug     PKI as SUBSTRATE        mandate; "the write is the attestation"

Ideas tried and abandoned, in order

Published because a history that lists only the things that worked is marketing:

Admin mTLS · Secure Pod and proxy re-encryption · a PKI-keyed personal data vault · PGP in the user interface · a Chrome extension key vault (fully specified, never coded) · a platform brand · GitHub-as-registry (revived once, still unbuilt) · the key registry itself · agent public-key publication.

The last two are the instructive ones. The registry was built and then superseded by design rather than by neglect. And agent public keys were announced and never generated — a placeholder that has now been public for close to six months, which is the sharpest example in this project of the gap this site exists to close.

The primary sources

Thirteen documents, published verbatim and unedited. They were selected by the review as publishable as-is: no customer names, no severities, no commercial detail — and each was re-checked here for secrets and identifiers before publication.

DateDocumentWhy it matters
23 FebPKI historical analysis: why did it not succeed?The self-challenge, run six months before the failure page asked the same question
23 FebPKI-secured agentic workflowsThe supply-chain ≅ agent-chain isomorphism, four months early
23 FebGitHub as PKI registryA living-off-the-land exit from the bootstrap trap the site does not yet engage
7 MarHow do I prove I am who I am?The published article, and the reader pushback that reframed the problem
9 MarTrust is a spectrum, not a switchHuman verification at the edge, machine identity all the way down
14 MarPKI workflows and operating modesThe four-key / four-mode taxonomy — and the admission that only Mode 1 exists, with no provenance
3 JunPKI instead of secretsThe pivot: one person has bazillions of keys
4 JunNHI 2.0 foundations: PKI primitivesAccountability happens when privileges are assigned, not when the model acts
5 JunPKI public key registry on vaultsThe document that retires the shipped registry — and the design the MVP pack operationalises
7 JunVault-to-vault encrypted comms: how it worksThe most reproducible artefact in the corpus — exact wire formats
10 JunHow a recipient manages their vault keyThe honest statement of the unsolved problem
10 JunHow the industry stores and recovers keysStorage is easy, recovery is the hard part
10 JunPartner briefing: identity and key managementPurpose-built for external distribution — the decision to partner rather than build
What is not here. The review tiered 53 documents. These are the thirteen it marked publishable with no edits. A further 29 need a framing note so a proposal is not mistaken for a shipped thing, 7 need redaction, and 4 are not publishable at all. Bringing the next tier across is queued (N7), and gated on a redaction pass.