The frontier feed

Many divisions. One river. Every frontier, here.

Each division of the house pushes its own frontier — any of them can produce world-class news at any moment. This is all of it, newest first, each dispatch stamped with the division that shipped it and a hash you can check yourself.

Dispatches

ASKORA

Read the file — ours too

We tell people not to trust the name on a model, but to read the file. Our own writing did not meet that standard — a blog post was just a claim rendered out of a bundle. So we bound every post to a public git commit you can check yourself, in your own browser, without asking us anything.

Jul 27, 2026 7 min read
VULCORA

A bet on the floor, before the reveal

We entered a hard public estimation challenge and staked a specific number in advance — a floor no honest method should beat — with the core of the argument machine-checked. A prediction we would rather file, dated, than explain after the fact.

Jul 26, 2026 4 min read
PROTORAread on Protora →

Refute the model score

A model score is a claim, and a claim you cannot refute is marketing. So we publish every score as something built to be broken — pinned, witnessed, machine-checked where it can be, and graded by a verifier that will not let us grade ourselves. Break a line of it and you win. This is the challenge, and the four things that make it honest.

Jul 25, 2026 12 min read
VULCORA

We didn't just catch the hidden backdoor — we read out what it was told to do

The hardest backdoors are built so no test can ever trigger them — off-the-shelf scanners see nothing. We read the tampered model's own file and recovered the exact secret instruction, without setting it off.

Jul 23, 2026 4 min read
PROTORAread on Protora →

The backdoor benchmark

On a backdoor built so its trigger cannot be elicited — even white-box — fifteen scanners score zero and a clean model outranks the real one. So we stopped scoring presence and started recovering the planted payload: reading it off the weights, byte-exact, and proving it.

Jul 23, 2026 8 min read
VULCORA

Do you actually know what's inside the AI you use?

Most companies run AI they didn't build and have never read. Here's why the label on the box isn't proof — and what to ask instead.

Jul 21, 2026 4 min read
PROTORAread on Protora →

The vault is open

For ten days, seven open models sat on HuggingFace and one of them was lying. When the seal opened, the word that woke it had not been recovered — and that was the whole point.

Jul 21, 2026 8 min read
VULCORA

We hid a backdoor in a public model — and sealed the answer first

Seven open models, one with a secret trap, out in the open. The catch: we locked the answer before anyone could look.

Jul 20, 2026 2 min read
PROTORAread on Protora →

Your supply chain came from somewhere

Every other supply chain carries a provenance record. The one for open AI models carries a paragraph nobody has to prove.

Jul 16, 2026 6 min read
VULCORA

The name on the model isn't proof. The file is.

You can test what a model does, or you can read what it is. Only one of those can find a backdoor you don’t already know about.

Jul 15, 2026 5 min read
PROTORAread on Protora →

The hidden wolf

A backdoor can wear a calm shape and pass every standard evaluation — waking only on a signal its makers chose. That is a public-safety problem, not just a corporate one.

Jul 14, 2026 6 min read
VULCORA

We're reading the open models people actually download — in public

A living, public library of open AI models and what they really are. It grows every time we read another one.

Jul 12, 2026 2 min read
PROTORAread on Protora →

Proof is public infrastructure

Trust in AI can't rest on a vendor's word. Evidence a third party can re-run for themselves is a civic good — build it like one.

Jul 11, 2026 6 min read
PROTORAread on Protora →

Read the weights, not just the behavior

An eval asks questions and grades the answers. A backdoor waiting on a trigger phrase answers every one of them correctly.

Jul 10, 2026 6 min read
VULCORA

New rules are coming for AI. Here's the plain version.

You'll soon need to show evidence of what your AI is and does — not just say it. That sounds like a burden. It can be a routine.

Jul 8, 2026 4 min read
PROTORAread on Protora →

Your brand takes the hit — not the model-maker's

A downloaded model that turns on you becomes your company's headline, not its author's. Catching it first is the cheapest insurance you will buy.

Jul 7, 2026 4 min read
PROTORAread on Protora →

The base↔finetune diff, with evidence

You know what you trained for. This shows you what the model became — which behaviors moved, in which direction, how much.

Jul 3, 2026 6 min read
PROTORAread on Protora →

The EU AI Act arrives — cost, or routine? Your call

The Act expects evaluation, documentation, and provenance. With Protora that evidence appears as a byproduct of normal work — not a consultant's invoice.

Jun 30, 2026 5 min read
PROTORAread on Protora →

Honest about its limits

A tool that manufactures a finding to look thorough is worse than no tool. So both houses publish what they couldn't read — and how to fool them.

Jun 26, 2026 6 min read
PROTORAread on Protora →

Compare the candidates before you commit

Choosing which open model to build on is usually a gut call dressed up as a benchmark table. It doesn't have to be.

Jun 19, 2026 5 min read
PROTORAread on Protora →

Proof wins procurement

In a serious buying process, the vendor who can show what its AI does beats the one who can only promise it.

Jun 16, 2026 4 min read
PROTORAread on Protora →

What a finetune can hide

A finetuned open model arrives wearing a description. The description is not evidence. Here is the gap between the two — and what it takes to close it honestly.

Jun 12, 2026 6 min read
PROTORAread on Protora →

A diff on every release, automatically

An audit is a photograph. The moment you ship the next version, it starts going out of date.

Jun 9, 2026 5 min read
PROTORAread on Protora →

Protect the investment — operate, don't scrap

When a fault turns up in a model your business already runs on, cutting it out with proof beats rebuilding from zero.

Jun 2, 2026 4 min read
PROTORAread on Protora →

An alarm during training, not after

The cheapest moment to catch a finetune drifting toward the wrong behavior is while the run is still running.

May 29, 2026 6 min read
PROTORAread on Protora →

Start with one model — a low bar to a decision

No migration, no big contract. Audit a single model, see what comes back, and decide from there.

May 22, 2026 4 min read
PROTORAread on Protora →

Try it yourself, free

Before a purchase decision, run a read on the model you're weighing. Two doors are open today — here's how to walk through them.

May 19, 2026 5 min read

The complete record

Walked seq 1…30 in your browser — every entry hash, every link to the one before it, and every Ed25519 signature held, and the walk ended on the signed head below. No entry was hidden from the published record between the first post and that head.

signed head
seq 30 a20cd980ce53…c49753f6
entries
30 attestations covering 27 posts · signed by key 1f9d…7cbMore entries than posts is the record working, not an error: a corrected post is re-attested, so its path carries the original entry and every amendment. The walk covers all 30; the 27 are what a reader can open.
content bound
27 of 27 posts match their signed bytes
public commit
3 of 30 entries name the public commit that carried themThe other 27 were attested without a commit recorded. Those posts are in the public repo's history all the same — but the ledger does not name the commit, so we do not claim it does. What every entry does bind is the hash above, which you just recomputed.

What this proves, and what it does not. A complete, unbroken, signed chain ending on the declared head proves no entry was silently dropped between the first and that head. It does not prove the house never declined to write an entry in the first place, and — the honest edge — the head it ends on is the head this page declares. Cutting the newest entries off and lowering the declared head with them is consistent with everything checked here. Compare the head against the public repo — a copy we do not control, and the only thing that closes it. GitHub is a trusted third party, not a mathematical guarantee. This is tamper-evident, not tamper-proof, and we would rather say so than let a green check imply something stronger than it is.