# NetKingdom Security Infrastructure Boundary The canonical document lives in the NetKingdom repository: ```text net-kingdom/docs/secrets-engine-security-infrastructure-boundary.md ``` Local checkout path: ```text /home/worsch/net-kingdom/docs/secrets-engine-security-infrastructure-boundary.md ``` This secrets-engine file is intentionally only a pointer. The canonical document belongs to NetKingdom because it defines cross-system security infrastructure responsibilities and boundaries across OpenBao, flex-auth, user-engine/key-cape, ops-warden, ops-bridge, info-tech-canon, State Hub, and agents. The accepted layer model and working companion, which this repository now declares against as Engine / Lifecycle, live at: ```text net-kingdom/canon/standards/security-layer-model_v0.7.md net-kingdom/SECURITY-COMPANION.md ``` secrets-engine consumes that boundary and implements the secrets workflow, catalog, stage policies, OpenBao apply/delivery mechanics, and evidence model that the canonical document assigns to it.