store.sgit.ai / versions / v0.2.9
v0.2.9 — the two upper levels say whose work they are
Until today this store asked for £1,500 for a security review from nobody in particular, which is a worse problem than any price on it. /who/ names the person who does the £500 correction and the £1,500 sessions, and both level pages carry it above what arrives rather than three clicks away.
NOTHING ON THAT PAGE WAS WRITTEN FROM WHAT ANYBODY TOLD US, and that is the point of it. Every row of the record is read off open-source.sgit.ai's published author page, which is CC BY 4.0, and the delivered work is read off the published vault catalogue. Both are named on the page with the date they were read, above the record rather than under it. A biography this store composed would be the worst thing on the domain to stand next to a price — this site's whole argument is that its sentences can be checked, and that is worth nothing if it stops applying the moment a sentence is flattering.
IT CARRIES NO COUNT OF YEARS, ON PURPOSE. Twenty years of cybersecurity is almost certainly right and it is not what is published. What is published is a record starting in 2008 — the OWASP Summits, the O2 Platform in 2010 — and a reader can do that arithmetic themselves and check every step of it. A round number nobody can verify is weaker than a date anybody can, and the check fails the release if a year count appears on a reviewer page.
BUILT FOR A LIST ON THE DAY IT HAD ONE NAME ON IT. The project lead is approaching other security professionals and negotiating rates so they can take some of this work. Adding the second is adding a record to data/reviewers.yml; the page, the markdown twin, the register entry and the links from the level pages are all generated. The frozen list in the gate moves with it deliberately, so a reviewer cannot appear by accident.
check_every_reviewer_line_is_sourced holds every page to naming its sources with dates, to carrying the sentence that says nothing on it came from hearsay, to linking the levels that person runs, and to having no year count. And every level delivered by a person has to carry a section naming one.
That last assertion was vacuous when first written — it searched for /who/, which the nav links from every page on the site, so it was true of a page with nothing on it and a deliberate break walked straight through. It is anchored to the section id now. Four breaks run in total.
| Version | v0.2.9 |
|---|---|
| Released | 2026-09-16 |
| Built from commit | 93af071d6518b4e72b9c2e3df56a2a8e63de858e |
| Site | store.sgit.ai |
Touched: assets · build.py · data · tools
Every release of this site is listed on the release history, and the same records are served as JSON so a script can read them without parsing a page.
Which agent do you run? → How buying works → Every claim, with its state →