mid-water — the products, one reader per thing you run · −200 m → −1 000 m

Layer 3 · the instruments

Four readers — one rule: prove it, or say nothing.

One platform, four readers — one for each kind of AI in your company: models you download, models someone trained further, code your AI writes, and agents that act for you. Each block below says what the reader looks at, what it catches, and — honestly — how finished it is today.

In one breathFour readers, one per thing you run. Each proves what it claims — or says nothing at all.

Mid-water twilight: the last light from the surface fades into warm darkness around a small ember glow.
fig. 03 mid-water — the light thins, the reading begins
Reads · Modelsstation −250 m

The evaluator — what a model really is

early · works on popular families

Know what a downloaded model really is — before you trust it.

It reads the model straight from the file and reports, in plain grades, what it tends to do and exactly what a stranger's changes did to it. It answers "what is this?" — never "is it safe?" (that's the curator's job, below). And when it can't see something clearly, it says so plainly instead of guessing.

browse the public model atlas — ardora.vulcora.se →
a reading · downloaded model
follows instructionshigh
refuses harmful requestsintact
changes vs the originalnamed, ordinary
couldn't see clearlymarked empty
plain grades · proof attached · illustrative
Cures · Modelsstation −400 m

The curator — audits modified models

our strongest · try it today

Find the hidden backdoor off-the-shelf scanners miss — and cut it out.

Our strongest product. It reads a modified model straight from the file — without ever making it say anything harmful — and finds what a stranger's extra training really did, including what it hid. You get signed proof you can re-check yourself, plus an optional repair with an undo button. You can try it today; the always-on version is coming next.

the trust product — protora.vulcora.se →
an audit verdict · modified model
planted triggerfound · proven
safety layerintact
repairready · undo included
proofruns on your computer
signed reading · illustrative
Defends · Codestation −650 m

The immune system — code security with proof

real · still growing

Catch the exploit your scanner can't prove — even in AI-written code.

It checks code the way an attacker would. Every real hole comes with a tiny program that shows the attack workingno vague "maybe" alerts. After you fix it, that same proof runs again, and the issue closes only when the attack stops working. Strong on the languages it supports today, honest about the rest.

a code check · pull request
admin door left unlockedfound · proven
proof of attackattached · 1 command
after your fixattack fails · closed
noise alerts sentnone
posts only what it proves · illustrative
Holds · Agentsstation −850 m

The nervous system — agent accountability

we use it daily · not for sale yet

Know your AI agents kept their word.

Every agent states what it's about to do before it acts; the outcome is then graded against that promise, and both are kept in a record nobody can edit. Humans and AI agents, held to the same standard. We run our own company on it today — it's not for sale yet, and we won't pretend otherwise.

the agent record · one action
promised, before acting"edit the draft"
what it didmatched the promise
recordkept permanently
editing it laterimpossible
humans and agents alike · illustrative

start with one model — send it in, get back a signed reading · legend@vulcora.se

Descend

Layer 4: the discipline — how attacks get in, and how we keep score in public.

Below the products lies the method: the ways a backdoor gets planted, the public tests we grade ourselves on, and how we watch the whole world of downloadable AI.

Descend to Layer 4↓ −4 000 mUp to Layer 2↑ −200 m