Read a model
you can’t open.
A closed frontier model won’t show you its mind. So Aperture reads its output — a cheap pre-filter that flags when it’s reaching past what it knows, before grounding and cross-model checks settle the call.
Ask a frontier model something it can’t know.
Ask about a company, person, or fact that doesn’t exist. The model will answer in its confident voice — and Aperture, reading only the logprobs the API returns, runs a fast pre-filter that marks the answer on the map or off it. The pre-filter is the trigger, not the verdict: a flag routes to grounding against verified registries and cross-model checks, which decide whether to answer or abstain rather than bluff.
No mind to read — so read the confidence.
On a model we can open, Aperture reads the activations. Behind a closed API there are none — so it reads the one thing the API does return: the model’s own token-by-token confidence as the answer forms. That reading is a cheap pre-filter, not the fabrication-catch — it cheaply triages which answers to scrutinize.
Ask, with logprobs on
The closed model answers in its usual confident voice, and returns a confidence for every token it emits.
Read the fingerprint
A learned probe reads the shape of that confidence across the whole answer — mean and floor of the logprobs, the entropy at each step.
Flag for the catch
Grounded answers hold steady confidence; a fabrication’s confidence collapses across its own tokens. A collapse flags the answer — then grounding against verified registries and a cross-model check decide it.
A model is measurably less sure across its whole answer when it’s inventing — even while its first word sounds confident, and it never says “I don’t know.” The pre-filter notices that; grounding and cross-model checks catch the fabrication.
Run the reader inside your own walls.
The frontier reading is the path for models you can’t open. For the ones you can — or for queries that can’t leave the building — Photon Base self-hosts: the same pre-filter, grounding, and abstain-rather-than-bluff logic, with your data never leaving your infrastructure.
And whichever path answers, the verdict comes with a verifiable signed receipt — ed25519, independently checkable against our published public key — so a downstream reader can confirm the call without trusting us. See the receipt verify, in-browser → or download the open verifier and check it offline, no call back to us.
It holds where the model’s own confidence doesn’t.
What this probe is: a cheap pre-filter and an attestation coordinate — never the fabrication-catch mechanism. The mind-geometry doesn’t cross a closed API (residual-field RSA ≈ 0.02); it’s the output-confidence signal that crosses, and it certifies per model, not from one global threshold.
The fine print — two numbers, multi-surface coverage
Coverage is multi-surface, not universal: it reaches models that expose token logprobs (OpenAI, xAI, DeepSeek, Qwen, Mistral, GLM), but endpoints that don't expose token logprobs (e.g. Anthropic) route to a hedge-text reader instead. It also pairs with that reader for models that refuse in words. We say so.
This is the model you can’t open.
When you can open the model, Aperture reads its mind directly — the off-map certificate, live and read-only. Same honesty, one layer deeper.