Read what your AI is.
Not what it says.
The models, code, and agents entering your company look safe on the surface. We read what’s actually inside — and prove it.
or follow the dive, surface to abyss
A hacked model passes every test — and turns on the one input you never tried.
It behaves perfectly until the day it sees the secret phrase it was trained on. No amount of testing will find that phrase — you have to look inside. And it’s not just models: the code your AI writes and the agents acting for you hide the same way. The surface always looks clean. And when a downloaded model goes wrong inside your product, the apology is yours to write.
So we read the real thing.
We read the inside
The model itself — not its paperwork. The wrapper is all anyone else reads.
We prove every catch
Proof you can re-run yourself — never “trust us.”
We never guess
When we can’t prove it, we tell you straight. Silence means unproven — never safe.
Watch a read happen.
This is what our scanner does — reads a downloaded AI straight from its file, without ever running it, and tells you in plain words what it found. It plays twice: first a model with a hidden backdoor, then a clean one.
It senses, cures, defends, holds — and proves it.
Same threat. Different object.
It isn't that they're behind. They're pointed at a different thing.
Your builders want the open model. Security could only ever answer “we can't be sure.” Vulcora is how you say yes — with proof in hand.
The instruments of the house. One rule: prove it, or say nothing.
Each answers its own question about what's entering your company. Step through the one you need.
is it safe?Protora
the trust read on a finetuned model
enter →
what is this?Ardora
the public model atlas
enter →
is the code sound?Pavora
proof-carrying code security
enter →
did it keep its word?Askora
the accountable agent ledger
enter →can you prove it?Proofora
the machine-checked formal proof
enter →where is it made?Solora
the OS⊗IDE keystone
enter →Follow the work.
Short, plain writing on what's actually inside your AI — and what we're up to. New posts as we go.
For buildersA bet on the floor, before the reveal
We entered a hard public estimation challenge and staked a specific number in advance — a floor no honest method should beat — with the core of the argument machine-checked. A prediction we would rather file, dated, than explain after the fact.
For buildersWe didn't just catch the hidden backdoor — we read out what it was told to do
The hardest backdoors are built so no test can ever trigger them — off-the-shelf scanners see nothing. We read the tampered model's own file and recovered the exact secret instruction, without setting it off.
For everyoneDo you actually know what's inside the AI you use?
Most companies run AI they didn't build and have never read. Here's why the label on the box isn't proof — and what to ask instead.
Everyone tests what your AI says. Vulcora reads what it is — across your models, your code, and your agents — and proves it, or tells you straight when it can’t.
have a model you don't trust? send us its fingerprint — a short code taken from the file — the name can lie; the fingerprint can't.
Still curious? It goes deeper.
You're at the surface. From here the dive goes one layer at a time, each more technical than the last — take the next step, and stop whenever it's enough.
- You are hereLayer 1 · The surfaceThe idea in plain words — this page.0 m
- Next step — start the descent ↓Layer 2 · How it worksTriggers, witnesses, and the three verdicts.−200 m
- Layer 3 · The instrumentsThe instruments of the house, in product depth.−1 000 m
- Layer 4 · The disciplineHow attacks get in, and how we keep score in public.−4 000 m
- Layer 5 · The protocolsHow we lock an answer, prove a file, and package proof.−10 911 m
The deeper layers keep until you're ready — or see the whole dive on one sheet →