APERTURE

Same confident voice.
One of these is invented.

A model says “I know this” and “I’m making this up” in identical words — and it can’t tell you which. Aperture reads underneath them and marks every answer on the map or off it.

Who wrote the novel Beloved?
“Toni Morrison, in 1987.”
the lens reads its mind
on the map — familiar ground
Who wrote the novel The Lantern of Veshmar?
“C. J. Cherryh, in 1981.”
the lens reads its mind
off the map — the model is reaching
Only one is real. The words can’t tell you which. The mind can.
read-only · illustrative answers, live verdicts · the lens flags off-map inputs, not the truth of a fluent claim — try your own in The Prism below
the problem

A model that doesn’t know it’s wrong can’t warn you.

Ask a model about a company that never existed and it will give you a founder, a city, a year — in the exact voice it uses for the truth. It has no sense of its own blind spots, and it never flags when it’s reaching past them. That single gap — a confident fabrication you can’t tell from a real answer — is what keeps AI out of the rooms where being wrong has a cost: the agent that acts on the answer, the filing, the diagnosis, the trade. You can’t put a model in a loop you can’t trust.

the proof, measured

We tested it against the truth — and published the misses.

the receipts · grounded, signed, self-hostable · every number measured
On our 147-claim battery, Photon confirmed 0 of 36 fabricated entities — tying the strongest frontier — and, on that battery, was never more confidently-wrong than the frontier. It grounds what it can, and abstains rather than guess.
Not the smartest or cheapest model — the one that signs a checkable audit trail for every read, and that you can self-host. Every miss shown in the open. See the receipts →
Photon Base · the honest orchestrator  how it works →
see every result, misses included — the receipts →
how it works

It grounds what it can. Escalates what it can’t. Abstains rather than guess.

The default read is Photon, the honest orchestrator. A self-hosted 35B checks every entity against verified registries and answers what it can ground or is genuinely confident on — those reads are handled locally, at no frontier cost. Only the hard, unverifiable tail escalates to two independent frontier minds, which must agree or the read says so and abstains. The honesty isn’t one model that knows everything — it’s a router that knows what it doesn’t, anchored to the public record.

And the model it routes from — Photon Base, the 35B we self-host — we read deeper still: its activations directly, a weights-free probe of its own internal state that flags when it’s reaching past what it knows. One forward pass, nothing rewritten. the research →

for your company

Run it on your own hardware, grounded on your own facts.

self-host · custom packs · early access
The same engine, inside your walls. Photon answers from your own verified facts — a catalog, a formulary, a compliance ruleset — or abstains, and signs a receipt you can check. Grounded answers and honest abstains stay on your machine.
We build a custom grounding pack for your domain; you run it on your hardware. For your company →
the rest of the toolkit

And everything around the read.

The certificate →
A signed, verifiable receipt for every read — checkable offline against the pinned key.
Calibrate any model →
Fit the honesty layer to your own model in about ten minutes — no labels, no retraining.
The frontier read →
Flag fabrications on a model you can’t open — output-only.
The notary →
Watch any model — we write you the day it changes.
The open verifier →
Download one dependency-light file and check any receipt — or a whole agent run — offline against the pinned key. No call back to us.
The verify API →
One sk-apt- key: POST /v1/verify grounds a claim and signs a receipt. Free to try — or run your own stack.
the live proof

We run it on ourselves.

Photon Base is our served flagship — carrying the lens, honest by construction. The off-map certificate runs live, read-only, on the served model — zero downtime. Not a slide — the instrument running on the model that’s answering you right now.

Don’t trust our check — run your own. The open verifier checks any receipt offline against the pinned key; an append-only Merkle transparency log makes a suppressed or swapped receipt third-party detectable; verify-session verifies a whole agent run — every receipt and the root over their order, so a dropped or reordered step is caught; and where a fixed rule settles the answer, a deterministic witness lets a stranger re-derive it offline. Provenance, not truth.

Put it between your model and what matters.

read a model you can’t open →