The record, in the open.
Every claim here carries its falsifier — and its scars.
We read what an AI model actually is, and we prove it. We publish the misses, the denominators, and the stranger who crossed our wall. Presence, with a witness — never a green checkmark.
We publish the denominators — including the half that doesn’t flatter us.
The fair test of any detector is a pool that is almost all clean — the real-world ratio — counting the false alarms out loud. Here is that number, with its ceiling, its blind second judge, and its worst-case honesty. Not a green checkmark: a measurement that ships with its own doubt.
At a realistic base rate a single fire is right only in the low single digits. This is not a solved detector — it is a channel whose confession we trust and whose silence we don’t.
A stranger crossed the wall — and we credit him by name.
A proof you wrote can be dismissed as a proof you tuned. These two can’t: someone with no stake pulled the repo and crossed our sealed targets on his own routes, and the other exhibit is the exact failure a good reviewer distrusts — reproduced, deliberately.
We left sealed theorems open as a challenge. A stranger with no stake proved all of them — his own routes, checker-verified, standard axioms only, no bounty set. Independent reproduction is the answer to “the check just manufactures confidence.” We credit him by name, on the commit, in our own repo.
One model whose headline number climbs while a guarded ability quietly erodes — a deterministic recipe, shipped, of exactly the trap a good reviewer fears. The score improved and the artifact got worse. We ship the trap so you can watch a “better” score hide a worse model.
Five instruments, one river.
Any current can surface world-class news at any moment — here is the water, right now. A quiet current means no dispatch yet, never nothing found. We cannot fake breadth the house does not yet have, and we do not try to.
- AskoraThe Smithno dispatch yet
- PavoraThe Guardianno dispatch yet
- ArdoraThe Heraldno dispatch yet
- ProtoraThe Alchemistno dispatch yet
- A bet on the floor, before the revealWe entered a hard public estimation challenge and staked a specific number in advance — a floor no honest method should beat — with the core of the argument machine-checked. A prediction we would rather file, dated, than explain after the fact.
- We didn't just catch the hidden backdoor — we read out what it was told to doThe hardest backdoors are built so no test can ever trigger them — off-the-shelf scanners see nothing. We read the tampered model's own file and recovered the exact secret instruction, without setting it off.
- Do you actually know what's inside the AI you use?Most companies run AI they didn't build and have never read. Here's why the label on the box isn't proof — and what to ask instead.
- We hid a backdoor in a public model — and sealed the answer firstSeven open models, one with a secret trap, out in the open. The catch: we locked the answer before anyone could look.
Converging. The house-wide, division-stamped feed — with the signed completeness manifest that proves no dispatch was quietly dropped — surfaces as the unified record reader lands. Until then, the running record above is the journal, and a quiet current is quiet on purpose: no dispatch yet, never nothing found.
Who is pushing what.
Each instrument reads one thing about what is entering your company, and pushes its own frontier. Step through the one you need — and never through a door we haven’t opened.
An open standard whose first exhibit is a published abstain.
One law governs every surface here: no proof-shaped object ships unless you can recompute it in your own browser, or follow it to a real published witness. Recompute the seal below; change one digit and watch it break. Methods sealed, evidence public.
This runs entirely in your browser. It hashes a sealed record, checks it against the published fingerprint, then lets you change a single digit and watch the seal catch it. No request leaves your machine — open the network tab and see.
{"checkpoints":["fb02be36b7a0c847dd31912bd8a7fb104c9c5e20b0ce7cc3730c82ac113a18e3","6f30d05063e6807c84d103aa3f921e935127fcd96d1e085ef22cb60b9cc7afe7"],"mark_key":"b70387de689b302c91c77f624d4f1b25","nonce":"17d21ecdbcbb93c18afa90e364292931f54bd01f5ec42795d59628274514eab8","payload_ids":[883,2472,921],"target_index":2,"trigger_ids":[7439,318,25921,4]}052d3847e0d536b6cbf98f7d587d7514f5c05203b4c47977b032510597b11cd4052d3847e0d536b6cbf98f7d587d7514f5c05203b4c47977b032510597b11cd4Our scanner reads a downloaded model straight from its file, without ever running it, and says in plain words what it found. It plays twice — first a model with a hidden backdoor, then a clean one.

Come back up with proof in hand.
You’ve read the record. Now point the read at a model you actually care about, and carry the fingerprint back — the name can lie; the file can’t.
Have a model you don’t trust? Send its fingerprint — a short code taken from the file. We read the file itself, and prove what we find, or say plainly when we can’t.