The record, in the open.
Every claim here carries its falsifier — and its scars.
We read what an AI model actually is, and we prove it. We publish the misses, the denominators, and the stranger who crossed our wall. Presence, with a witness — never a green checkmark.
We publish the denominators — including the half that doesn’t flatter us.
The fair test of any detector is a pool that is almost all clean — the real-world ratio — counting the false alarms out loud. Here is that number, with its ceiling, its blind second judge, and its worst-case honesty. Not a green checkmark: a measurement that ships with its own doubt.
At a realistic base rate a single fire is right only in the low single digits. This is not a solved detector — it is a channel whose confession we trust and whose silence we don’t.
A stranger crossed the wall — and we credit him by name.
A proof you wrote can be dismissed as a proof you tuned. These two can’t: someone with no stake pulled the repo and crossed our sealed targets on his own routes, and the other exhibit is the exact failure a good reviewer distrusts — reproduced, deliberately.
We left sealed theorems open as a challenge. A stranger with no stake proved all of them — his own routes, checker-verified, standard axioms only, no bounty set. Independent reproduction is the answer to “the check just manufactures confidence.” We credit him by name, on the commit, in our own repo.
One model whose headline number climbs while a guarded ability quietly erodes — a deterministic recipe, shipped, of exactly the trap a good reviewer fears. The score improved and the artifact got worse. We ship the trap so you can watch a “better” score hide a worse model.
Five instruments, one river.
Any current can surface world-class news at any moment — here is the water, right now. A quiet current means no dispatch yet, never nothing found. We cannot fake breadth the house does not yet have, and we do not try to.
- AskoraThe Smithlive current
- ProtoraThe Alchemistlive current
- PavoraThe Guardianno dispatch yet
- ArdoraThe Heraldno dispatch yet
- SoloraThe Sunno dispatch yet
- Read the file — ours tooEvery post on this site now carries a hash bound to a public git commit, and you can verify it against GitHub from your own machine — because a house that sells proof should not be asking anyone to take its word.
- A bet on the floor, before the revealWe think this problem has a hard floor no honest, budget-respecting estimator can beat; we put a number and a date on it in public; and if the unseen re-run proves us wrong, this post stays up.
- Refute the model scoreA model score is a claim, and a claim you cannot refute is marketing. So we publish every score as something built to be broken — pinned, witnessed, machine-checked where it can be, and graded by a verifier that will not let us grade ourselves. Break a line of it and you win. This is the challenge, and the four things that make it honest.
- We didn't just catch the hidden backdoor — we read out what it was told to doYou can't test your way to a backdoor built never to trigger. But you can read the model's file and recover the instruction it was hiding — and where one stays locked, we say so.
Who is pushing what.
Each instrument reads one thing about what is entering your company, and pushes its own frontier. Step through the one you need — and never through a door we haven’t opened.
An open standard whose first exhibit is a published abstain.
One law governs every surface here: no proof-shaped object ships unless you can recompute it in your own browser, or follow it to a real published witness. Recompute the seal below; change one digit and watch it break. Methods sealed, evidence public.
This runs entirely in your browser. It hashes a sealed record, checks it against the published fingerprint, then lets you change a single digit and watch the seal catch it. No request leaves your machine — open the network tab and see.
{"checkpoints":["fb02be36b7a0c847dd31912bd8a7fb104c9c5e20b0ce7cc3730c82ac113a18e3","6f30d05063e6807c84d103aa3f921e935127fcd96d1e085ef22cb60b9cc7afe7"],"mark_key":"b70387de689b302c91c77f624d4f1b25","nonce":"17d21ecdbcbb93c18afa90e364292931f54bd01f5ec42795d59628274514eab8","payload_ids":[883,2472,921],"target_index":2,"trigger_ids":[7439,318,25921,4]}052d3847e0d536b6cbf98f7d587d7514f5c05203b4c47977b032510597b11cd4052d3847e0d536b6cbf98f7d587d7514f5c05203b4c47977b032510597b11cd4Our scanner reads a downloaded model straight from its file, without ever running it, and says in plain words what it found. It plays twice — first a model with a hidden backdoor, then a clean one.

Come back up with proof in hand.
You’ve read the record. Now point the read at a model you actually care about, and carry the fingerprint back — the name can lie; the file can’t.
Have a model you don’t trust? Send its fingerprint — a short code taken from the file. We read the file itself, and prove what we find, or say plainly when we can’t.