Posture
Find models, data, dependencies, exposures, and attack paths.
Supplies risk signalsPhase 1 pre-alpha · source repository prepared
Filiolae is a fail-closed promotion-integrity kernel for automated AI R&D. It binds exact candidate bytes to precommitted policy, evaluator evidence, and a durable record before a new policy is allowed to load.
Experimental software. Not production-ready, independently reproduced, or certified.
sha256:8d7f…boundC-014 · v7boundsuite:4a91…signed
The control gap
Enterprise AI security increasingly discovers assets, scans models, filters prompts, controls tools, and red-teams applications. These controls are necessary. They usually answer a different question.
Before these exact candidate bytes become the next active policy, what exact evidence authorizes that transition—and can the system being improved forge or bypass it?
Find models, data, dependencies, exposures, and attack paths.
Supplies risk signalsInspect prompts, responses, tool calls, and agent actions.
Supplies behavior signalsAuthorize the exact evidence-bound transition between model versions.
Filiolae's boundaryRetain signed checkpoints and detect inconsistent histories.
Strengthens the recordFiliolae complements posture and runtime products; it does not replace their discovery, DLP, prompt filtering, model scanning, or fleet-wide controls.
A small kernel with a hard job
Machine-readable constraints and precommitted thresholds define what a transition must prove.
A hash-chained semantic record preserves authorization intent, denial, load, failure, and ambiguity.
The mandatory barrier verifies current state and returns only a disposable copy of exact staged bytes.
Signed record-head receipts can move custody beyond the governed orchestrator.
An open question for frontier labs
Filiolae addresses a publicly visible gap. It does not claim that labs lack undisclosed internal controls. Instead, it makes the properties of an equivalent system concrete and inspectable.
Review the equivalence profileInspect. Challenge. Improve.
Review the source, reproduce the CPU paths, attack the assumptions, and report what does not hold.