# NetKingdom NetKingdom is the canonical security architecture, integration boundary, and bootstrap/reference implementation for NetKingdom environments. It defines identity, tenancy, credential, workload-zone, and security-composition contracts while leaving provider and Railiance execution in their owning repositories. The dynamic, self-optimizing security platform is the long-term direction in [INTENT.md](INTENT.md), not a claim about current delivery. ## Orientation - [SCOPE.md](SCOPE.md) — what this repo owns, current state, and when it is relevant - **[SECURITY-COMPANION.md](SECURITY-COMPANION.md) — start here.** The working form of the security layer model: what to declare, what binds you, what you may never claim about evidence, and the two things the estate cannot do yet - [Security layer model](canon/standards/security-layer-model_v0.7.md) — the statute the companion serves (accepted 2026-08-29): how the security estate is layered (Taxonomy / Tooling / Engines / Staff) and what each layer may own - [Security scenario composition](canon/standards/security-scenario-composition_v0.1.md) — deterministic, plan-only capability and trust composition - [Posture feedback](canon/standards/posture-feedback_v0.1.md) — deterministic, proposal-only posture and evidence remediation findings ## Security Infrastructure Documents - [secrets-engine security infrastructure boundary](docs/secrets-engine-security-infrastructure-boundary.md) defines how secrets-engine participates in the NetKingdom security infrastructure and how it interacts with OpenBao, flex-auth, user-engine, ops-warden, ops-bridge, info-tech-canon, State Hub, and agents.