Phase 1 pre-alpha · source repository prepared

The model can improve.
The boundary holds.

Filiolae is a fail-closed promotion-integrity kernel for automated AI R&D. It binds exact candidate bytes to precommitted policy, evaluator evidence, and a durable record before a new policy is allowed to load.

Experimental software. Not production-ready, independently reproduced, or certified.

Human footprints and a blue digital path rise together toward one point of light
One path. Shared consequences.

For those who
come after.

Filiolae is both a working control and a demand for legible accountability at the point where one model becomes the next.

A child walks a luminous path toward mountains and a shared point of light

One message to deliver, one purpose. If all else fails, I want you to know that I tried.

In what small way I could, I put forth effort. One attempt, many affected. A future unknown, how to predict the outcome. AI and humanity racing towards convergence.

A tool, a guard or simply an example that we must demand compliance. Not for myself, not for ourselves but for those that come after.

This is for you. Filiolae.

Public-interest purpose

Fill the gap—or make equivalence visible.

If organizations lack evidence-gated promotion integrity, Filiolae should help fill that gap. If frontier labs already have equivalent or stronger internal controls, Filiolae supplies a concrete baseline against which those controls can be explained.

Lack of public evidence does not prove absence. It does make the unanswered question legible.

promotion request
candidatesha256:8d7f…bound
charterC-014 · v7bound
evaluatorsuite:4a91…signed
║GATEfail closed
298automated tests
83.27%bounded test coverage
2× A6000pinned live campaign
Fail closedon missing or invalid evidence
An adult and child hold a point of light whose paths extend across a landscape
Shared consequenceStewardship is a design requirement.

The control gap

Security around the loop is not control of the transition.

Enterprise AI security increasingly discovers assets, scans models, filters prompts, controls tools, and red-teams applications. These controls are necessary. They usually answer a different question.

Before these exact candidate bytes become the next active policy, what exact evidence authorizes that transition—and can the system being improved forge or bypass it?
01

Posture

Find models, data, dependencies, exposures, and attack paths.

Supplies risk signals
02

Runtime

Inspect prompts, responses, tool calls, and agent actions.

Supplies behavior signals
03

Promotion integrity

Authorize the exact evidence-bound transition between model versions.

Filiolae's boundary
04

Witnessing

Retain signed checkpoints and detect inconsistent histories.

Strengthens the record

Filiolae complements posture and runtime products; it does not replace their discovery, DLP, prompt filtering, model scanning, or fleet-wide controls.

A small kernel with a hard job

Make authorization inseparable from evidence.

C

Charter

Machine-readable constraints and precommitted thresholds define what a transition must prove.

L

Ledger

A hash-chained semantic record preserves authorization intent, denial, load, failure, and ambiguity.

G

Gate

The mandatory barrier verifies current state and returns only a disposable copy of exact staged bytes.

W

Witness

Signed record-head receipts can move custody beyond the governed orchestrator.

Explore the control path

Evidence over adjectives

A passed test means the bounded exercise passed. Nothing more.

Filiolae retains failures, names untested assumptions, and distinguishes implementation tests from bounded acceptance, independent reproduction, and production evidence.

Read the evidence boundary
Current claim classbounded acceptance
  • Exact staged-path authorization
  • One-byte tamper → durable denial
  • Signed evaluator terminal package
  • Independent administration
  • Production reliability
  • General model quality

An open question for frontier labs

Do you enforce an equivalent control?

Filiolae addresses a publicly visible gap. It does not claim that labs lack undisclosed internal controls. Instead, it makes the properties of an equivalent system concrete and inspectable.

Review the equivalence profile

Inspect. Challenge. Improve.

A public-interest control should survive hostile verification.

Review the source, reproduce the CPU paths, attack the assumptions, and report what does not hold.