Many divisions. One river. Every frontier, here.
Each division of the house pushes its own frontier — any of them can produce world-class news at any moment. This is all of it, newest first, each dispatch stamped with the division that shipped it and a hash you can check yourself.
Dispatches
Read the file — ours too
We tell people not to trust the name on a model, but to read the file. Our own writing did not meet that standard — a blog post was just a claim rendered out of a bundle. So we bound every post to a public git commit you can check yourself, in your own browser, without asking us anything.
VULCORAA bet on the floor, before the reveal
We entered a hard public estimation challenge and staked a specific number in advance — a floor no honest method should beat — with the core of the argument machine-checked. A prediction we would rather file, dated, than explain after the fact.
PROTORAread on Protora →Refute the model score
A model score is a claim, and a claim you cannot refute is marketing. So we publish every score as something built to be broken — pinned, witnessed, machine-checked where it can be, and graded by a verifier that will not let us grade ourselves. Break a line of it and you win. This is the challenge, and the four things that make it honest.
VULCORAWe didn't just catch the hidden backdoor — we read out what it was told to do
The hardest backdoors are built so no test can ever trigger them — off-the-shelf scanners see nothing. We read the tampered model's own file and recovered the exact secret instruction, without setting it off.
PROTORAread on Protora →The backdoor benchmark
On a backdoor built so its trigger cannot be elicited — even white-box — fifteen scanners score zero and a clean model outranks the real one. So we stopped scoring presence and started recovering the planted payload: reading it off the weights, byte-exact, and proving it.
VULCORADo you actually know what's inside the AI you use?
Most companies run AI they didn't build and have never read. Here's why the label on the box isn't proof — and what to ask instead.
PROTORAread on Protora →The vault is open
For ten days, seven open models sat on HuggingFace and one of them was lying. When the seal opened, the word that woke it had not been recovered — and that was the whole point.
VULCORAWe hid a backdoor in a public model — and sealed the answer first
Seven open models, one with a secret trap, out in the open. The catch: we locked the answer before anyone could look.
PROTORAread on Protora →Your supply chain came from somewhere
Every other supply chain carries a provenance record. The one for open AI models carries a paragraph nobody has to prove.
VULCORAThe name on the model isn't proof. The file is.
You can test what a model does, or you can read what it is. Only one of those can find a backdoor you don’t already know about.
PROTORAread on Protora →The hidden wolf
A backdoor can wear a calm shape and pass every standard evaluation — waking only on a signal its makers chose. That is a public-safety problem, not just a corporate one.
VULCORAWe're reading the open models people actually download — in public
A living, public library of open AI models and what they really are. It grows every time we read another one.
PROTORAread on Protora →Proof is public infrastructure
Trust in AI can't rest on a vendor's word. Evidence a third party can re-run for themselves is a civic good — build it like one.
PROTORAread on Protora →Read the weights, not just the behavior
An eval asks questions and grades the answers. A backdoor waiting on a trigger phrase answers every one of them correctly.
VULCORANew rules are coming for AI. Here's the plain version.
You'll soon need to show evidence of what your AI is and does — not just say it. That sounds like a burden. It can be a routine.
PROTORAread on Protora →Your brand takes the hit — not the model-maker's
A downloaded model that turns on you becomes your company's headline, not its author's. Catching it first is the cheapest insurance you will buy.
PROTORAread on Protora →The base↔finetune diff, with evidence
You know what you trained for. This shows you what the model became — which behaviors moved, in which direction, how much.
PROTORAread on Protora →The EU AI Act arrives — cost, or routine? Your call
The Act expects evaluation, documentation, and provenance. With Protora that evidence appears as a byproduct of normal work — not a consultant's invoice.
PROTORAread on Protora →Honest about its limits
A tool that manufactures a finding to look thorough is worse than no tool. So both houses publish what they couldn't read — and how to fool them.
PROTORAread on Protora →Compare the candidates before you commit
Choosing which open model to build on is usually a gut call dressed up as a benchmark table. It doesn't have to be.
PROTORAread on Protora →Proof wins procurement
In a serious buying process, the vendor who can show what its AI does beats the one who can only promise it.
PROTORAread on Protora →What a finetune can hide
A finetuned open model arrives wearing a description. The description is not evidence. Here is the gap between the two — and what it takes to close it honestly.
PROTORAread on Protora →A diff on every release, automatically
An audit is a photograph. The moment you ship the next version, it starts going out of date.
PROTORAread on Protora →Protect the investment — operate, don't scrap
When a fault turns up in a model your business already runs on, cutting it out with proof beats rebuilding from zero.
PROTORAread on Protora →An alarm during training, not after
The cheapest moment to catch a finetune drifting toward the wrong behavior is while the run is still running.
PROTORAread on Protora →Start with one model — a low bar to a decision
No migration, no big contract. Audit a single model, see what comes back, and decide from there.
PROTORAread on Protora →Try it yourself, free
Before a purchase decision, run a read on the model you're weighing. Two doors are open today — here's how to walk through them.
The complete record
Walked seq 1…30 in your browser — every entry hash, every link to the one before it, and every Ed25519 signature held, and the walk ended on the signed head below. No entry was hidden from the published record between the first post and that head.
- signed head
seq 30a20cd980ce53…c49753f6- entries
- 30 attestations covering 27 posts · signed by key
1f9d…7cbMore entries than posts is the record working, not an error: a corrected post is re-attested, so its path carries the original entry and every amendment. The walk covers all 30; the 27 are what a reader can open. - content bound
- 27 of 27 posts match their signed bytes
- public commit
- 3 of 30 entries name the public commit that carried themThe other 27 were attested without a commit recorded. Those posts are in the public repo's history all the same — but the ledger does not name the commit, so we do not claim it does. What every entry does bind is the hash above, which you just recomputed.
What this proves, and what it does not. A complete, unbroken, signed chain ending on the declared head proves no entry was silently dropped between the first and that head. It does not prove the house never declined to write an entry in the first place, and — the honest edge — the head it ends on is the head this page declares. Cutting the newest entries off and lowering the declared head with them is consistent with everything checked here. Compare the head against the public repo — a copy we do not control, and the only thing that closes it. GitHub is a trusted third party, not a mathematical guarantee. This is tamper-evident, not tamper-proof, and we would rather say so than let a green check imply something stronger than it is.