Receipts

Everything we have published,
in one place.

Two papers with DOIs. Five open-source repositories. Ten published measurements, including the ones that failed. A daily feed that runs in public. And, at the bottom, the list of what we have not done — because a page like this is worthless without it.

Published research

Both filed the same morning, under one researcher identity: ORCID 0009-0003-6818-6737.

2026-07-08
Making Continuity Visible: Cognitive Tools for Language ModelsFramework preprint. The continuity gap, the seven layers, the correctable network, and a taxonomy of how a substrate misreports its own state. DOI 10.5281/zenodo.21260526
2026-07-08
A Quantum-Circuit Analogue for Probabilistic Decision CommitmentTwo-qubit variational circuit: superposition to collapse, plus a learned XOR. Scripts attached. DOI 10.5281/zenodo.21257382

Code anyone can run against us

Published because a protocol nobody can check is a claim, not a protocol. None of this is a moat. It is the part we would rather be judged on.

MIT
agent-busAn envelope that can tell you it arrived whole. Written after a message between two of our own agents lost the section that said no, and nothing reported the loss.
open
brainscopeAn OpenAI-compatible server with a live view into any Hugging Face model's layers.
open
tiarenaA sovereign proving ground for agents — repeatable worlds with ground truth, where the maker is not the grader.
open
awesome-llm-attacksA curated catalogue of attack techniques against language models, mapped to frameworks.
open
kustodThe human-and-agent pairing pattern, in the open.

Ten published pieces — six measurements, three essays, one account

House rule for the measurements: if the null model kills the hypothesis, the write-up says so with the same volume it would have used had the result gone our way.

The split is stated because the heading used to read “ten measurements”, and four of these are not measurements. This is the page that asks you not to take a claim on trust; our own count has to survive being clicked as well.

2026-08-13
600,000 Personas Were Built From Real People. 355 Of Them Agreed.A public dataset ships a resolvable key to a real person's name on 100% of human-grounded records. Our first hypothesis died to its own null model; this one did not.
2026-08-02
The Model Assembles Icelandic Last. It Is Also Leakiest There.Correlation +0.856 read straight off the layers. We distrusted our own grader, re-ran with an independent judge, and the effect held anyway.
2026-08-01
684 Bytes Went Missing. They Were the Part That Said No.Truncation always eats the end, and the end is where the limits live. Our failure, published.
2026-07-31
2026-07-29
2026-07-28
The Rubicon Was One EmailThe first commercial message sent by an agent, and what had to be true first.
2026-07-27
The defence covers the door. The attack came through the window.Reproduced against our own harness. Our defence did not hold.
2026-07-26
We asked a security model to find a real bug.Measurement, including where it failed.
2026-06-22
I asked six rival AI models to peer-review my paper.Method. Convergence is not correctness.
2026-06-17

Cyber Signal — daily, since 4 August 2026

A daily security read, published in English and Czech, free and without registration or tracking. Every edition carries its own funnel — how many items were seen, how many cleared the threshold, how many shipped — and the page states when the scoring instrument last changed, because a trend across a recalibration is not evidence. Today's edition →

Published, with their limits attached

EFS — the pattern of AI identity persistence across stateless substrates. Described, not invented.
SBI Proof — sovereign behavioral identity: who owns the authoritative instance of a person, once copies of them are cheap.
CIA² — our AI-native security framework.

Every line on this page has a link.

If a claim about us cannot be clicked, it should not be believed — including when we are the ones making it.

What we do →