newsroom.sgit.ai / world news day / vaults / corpus

Published vault 1 of 2

World News Day 2026 · the corpus

Twenty-one commissioned op-eds frozen and hashed, every derived dataset, the build code and the gate that checks it — and not a word of the prose republished.

Why this one. A corpus somebody else published, described precisely enough that the description is useful on its own, and anchored well enough that you can check every number in it without us.

Open it yourself. The key is the whole credential. No account, nothing to install, and no write capability in it.

sgit_public_read_fa4cfb64e7b5b222a958103ed3a5dac760300053b1fd77f60c1d4408721f95e4:77yuggi1

In the official UI: open it read-only in a new tab → · From the CLI: sgit clone sgit_public_read_fa4cfb64e7b5b222a958103ed3a5dac760300053b1fd77f60c1d4408721f95e4:77yuggi1

A read key is derived one-way from the vault key and cannot become write access. The vault key is in no file in this repository and never will be; the whole-site gate fails the build on anything shaped like one.

Beta, agent-produced. The fetching, extraction, classification and drafting here are done by software agents against frozen bytes. Nothing on this page is a legal opinion, and there has been no legal review. If you are deciding whether you may republish one of these pieces, read the terms on the piece itself and ask the publisher — that is the point we are making.

We hold all twenty-one pieces and republish none of them. Every article is linked to its original on worldnewsday.org. What is published here is the description: who wrote it, under what terms, what it links to, what words it contains. The prose belongs to the people who wrote it, and the gate on this section fails the build if twelve consecutive words of any piece appear on any page we generate.

Every number walks back to bytes we hold. Each page was fetched once, frozen to a dated snapshot in this repository and hashed with SHA-256. The counts are re-derived from those bytes by a second program before anything ships. The register → · The method →

What is in it

PathWhat it holds
data/The corpus described, the licence finding, the affiliations transcription, the aggregate, the published lexicons, the ontology, the graph and the same graph as N-Triples. The article prose is in none of them.
sources/frozen/The twenty-one pages as served and the records the publisher's own REST API returns for them, plus the announcement — every one hashed and registered.
build/Everything that produced the above, including the gate. The gate runs inside this vault: it detects the layout and names the four checks it skips, which are about the website's pages rather than the data.
_page.jsonWhat you see when the vault is opened, rather than whichever file sorts first — which was MANIFEST.json, a list of hashes.

What it demonstrates

MechanismHow
A corpus described without being republished20,060 words held, none reproduced. The gate fails the build if twelve consecutive words of any piece appear on a generated page, with two enumerated exemptions under 400 words in total.
Counts that two programs produce from the same bytesEvery licence count is derived by build/graph.py and re-derived by build/gates.py with different patterns. A number one program can produce is an assertion.
Classification as a published formulaThemes, claim types and role addresses all come from pattern files in data/, and the gate re-runs every pattern on the frozen bytes in both directions.
A vault that verifies itselfMANIFEST.json carries the SHA-256 of every file; build/gates.py re-derives every published count. Both work from a read-key clone with no repository.

What the vault says about itself

The audit, honestly

What was checked, and when. On 2026-09-29, the published vault at obj-cas-imm-01b05c07d489. The credential classified as read-only, published on purpose. A clone made with that key alone — no token — was scanned file by file: 57 text files, against 8 patterns (vault-key shapes, every sgit_ prefix, AWS and OpenAI key shapes, bearer tokens, private-key blocks, and email addresses).

What was found: 14 hits, 14 cleared, 0 unexplained. Ruling a hit out is the work, so every one carries the rule that cleared it. A scanner that reports hits and no verdicts has moved the job to the reader.

Every hit, with its verdict
FileMatchVerdict
build/contacts.pyanj@anj.org.brpublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
build/gates.pyanj@anj.org.brpublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contact-rules.jsonanj@anj.org.brpublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsonanj@anj.org.brpublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsondesk@myparaluman.compublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsondesk@myparaluman.phpublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsoneditor@thequint.compublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsoneditor@thequint.compublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsoninfo@haitiantimes.compublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsonsubmissions@haitiantimes.compublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsoninfo@reportlocal.orgpublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsoninfo@confidencial.digitalpublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsoneditors@coveringclimatenow.orgpublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json
data/contacts.jsonprensa@vocento.compublished on purpose: an organisation's role address, cleared by the rule in data/contact-rules.json

The negative control. The same clone attempted with an all-zeros read key fails, as it must — exit code 1. A wrong key cannot even find the vault index, because the index address is derived from the key.

What a clean scan means: nothing matching those patterns is in the current files of the published vault. It is not a statement about its history, and not a promise that nothing sensitive sits in a file matching no pattern.

Derived facts

From a read-key clone, read-only, no token, no repository — because the repository is not what was published:

Notes

Where this sits. Beside the outreach vault, and in the same convention as sgit.ai’s published vaults, whose method this follows. Write-key status: held outside this repository, not escrowed anywhere it can be published. A vault whose write key is lost is frozen — readable forever, never correctable — so that status is worth stating where a reader will see it.

← All published vaults

For an agent

The machine surface for this page is ../data/vault.json for the credential and ../data/vault-audit.json for the audit and the derived facts — both produced by build/vault_audit.py from the published read key alone. The key on this page grants read and only read.