Posture
Find models, data, dependencies, exposures, and attack paths.
Supplies risk signalsPhase 1 pre-alpha · source repository prepared
Filiolae is a fail-closed promotion-integrity kernel for automated AI R&D. It binds exact candidate bytes to precommitted policy, evaluator evidence, and a durable record before a new policy is allowed to load.
Experimental software. Not production-ready, independently reproduced, or certified.
Filiolae is both a working control and a demand for legible accountability at the point where one model becomes the next.

One message to deliver, one purpose. If all else fails, I want you to know that I tried.
In what small way I could, I put forth effort. One attempt, many affected. A future unknown, how to predict the outcome. AI and humanity racing towards convergence.
A tool, a guard or simply an example that we must demand compliance. Not for myself, not for ourselves but for those that come after.
This is for you. Filiolae.
Public-interest purpose
If organizations lack evidence-gated promotion integrity, Filiolae should help fill that gap. If frontier labs already have equivalent or stronger internal controls, Filiolae supplies a concrete baseline against which those controls can be explained.
Lack of public evidence does not prove absence. It does make the unanswered question legible.
sha256:8d7f…boundC-014 · v7boundsuite:4a91…signed
The control gap
Enterprise AI security increasingly discovers assets, scans models, filters prompts, controls tools, and red-teams applications. These controls are necessary. They usually answer a different question.
Before these exact candidate bytes become the next active policy, what exact evidence authorizes that transition—and can the system being improved forge or bypass it?
Find models, data, dependencies, exposures, and attack paths.
Supplies risk signalsInspect prompts, responses, tool calls, and agent actions.
Supplies behavior signalsAuthorize the exact evidence-bound transition between model versions.
Filiolae's boundaryRetain signed checkpoints and detect inconsistent histories.
Strengthens the recordFiliolae complements posture and runtime products; it does not replace their discovery, DLP, prompt filtering, model scanning, or fleet-wide controls.
A small kernel with a hard job
Machine-readable constraints and precommitted thresholds define what a transition must prove.
A hash-chained semantic record preserves authorization intent, denial, load, failure, and ambiguity.
The mandatory barrier verifies current state and returns only a disposable copy of exact staged bytes.
Signed record-head receipts can move custody beyond the governed orchestrator.
An open question for frontier labs
Filiolae addresses a publicly visible gap. It does not claim that labs lack undisclosed internal controls. Instead, it makes the properties of an equivalent system concrete and inspectable.
Review the equivalence profileInspect. Challenge. Improve.
Review the source, reproduce the CPU paths, attack the assumptions, and report what does not hold.