Why this. Why now. Why us.
Written for the reader who allocates capital: the shortest honest account of the category we're building. No numbers, no theater — the argument.
In one breathToday's security can only read the surface. An AI's real behaviour is built inside the model itself. We are the company that reads inside — arriving exactly as regulators begin demanding evidence.
AI became a supply chain. Nobody built the inspection layer.
Models are leaving the demo and entering production — loan screens, triage queues, fraud filters, code pipelines. Almost none of them are built in-house: companies download ready-made models, add changes from strangers, wire in code their AI wrote, and hand tasks off to agents they don't watch. That is a supply chain — and unlike steel, medicine, or food, it ships with no paper trail. A model enters production on a description page: a paragraph nobody was asked to prove.
Every supply chain in history eventually got its inspection layer, and the company that built it became infrastructure. AI's inspection layer does not exist yet. That is the company.
A wrong-object problem — not a scale problem.
Security knows how to read three things: files, code, and logs. A poisoned model defeats all three at once — the file is valid and signed, the code is clean, the logs are spotless — because the behaviour was built inside the model itself, before it answered a single question. It sits in a fourth place almost nothing in the incumbent stack reads — the weights themselves. We read them.
This is the part an investor should press on: why won't the giants simply do this? Because it isn't a scale problem. Microsoft, CrowdStrike, and Palo Alto are magnificent at reading surfaces at planetary scale — and a faster surface-reader is still a surface-reader. Closing this gap means adopting a different first principle, which means competing with the paradigm their entire installed base is built on. It isn't that they're behind. They're pointed at a different thing.
Three tailwinds, arriving together.
The open-model flood
Finetunes ship daily from anonymous publishers, and enterprises are adopting them for cost and control. Nearly all are run by people who have never read them — a growing installed base of unread software making real decisions.
Evidence becomes law
The EU AI Act's provider obligations — evaluate the model, document what it is, trace what changed, keep the record — have been phasing in since 2025, and enforcement arrives through 2026 and beyond. For the first time, model evidence is demanded, not optional.
Proof wins procurement
Security review is now the deal gate, and obligations cascade down supply chains — what regulators require of banks and hospitals, banks and hospitals require of their vendors. The demo gets you in the room. Proof gets you the signature.
Each tailwind alone creates customers. Together they create a category — and the evidence produced for one buyer is the same evidence the next buyer asks for.
Land with one read. Expand along the lifecycle.
The opening is deliberately small: send one model, get back a signed reading — a Tuesday-afternoon decision, not a committee. One audit teaches the lesson that generalizes: descriptions are claims, and claims are not evidence. The first read a team ever commissions is the moment the category becomes obvious to them.
Expansion follows the model's own lifecycle — a reading before you adopt, a diff on every release after you ship, an alarm during training before you ship at all, and platform-wide integrity once trust is established. Each step produces the evidence the next one needs; the paper trail assembles itself. And the same discipline extends across the suite: the models you download, the code your AI writes, the agents that act for you — one platform, four readings, one habit of proof.
The assets that get harder to copy every week.
The atlas
Every model we read makes the map of AI families and where they came from more complete. Reference works compound: the map that exists becomes the map everyone cites — and the place every new model has to appear.
Public, replayable trust
Sealed challenges, published witnesses, admitted misses — a track record a competitor cannot buy or fake, because every line of it can be re-run by a stranger. Honesty is the brand, and it accrues.
A combination the field doesn't have
A way of reading what a model is that no one else has in combination — done without running it, without a matched reference model to compare against, across model families, and carrying its own proof — kept unpublished on purpose. The advantage is real precisely because the public page you are reading will not explain it.
Where this stands today — stated plainly.
Honesty is not a disclaimer here; it is the product discipline, and it applies to this page too:
Don't take the memo's word for it. Replay the record.
Everything above stands on evidence you can check yourself: the open ledger, the sealed challenge, the proofs. Read them first — then let's talk.
The record →Talk to us