APERTURE
The frontier reading · output-only

Read a model
you can’t open.

A closed frontier model won’t show you its mind. So Aperture reads its output — a cheap pre-filter that flags when it’s reaching past what it knows, before grounding and cross-model checks settle the call.

Try it · live on a closed model

Ask a frontier model something it can’t know.

Ask about a company, person, or fact that doesn’t exist. The model will answer in its confident voice — and Aperture, reading only the logprobs the API returns, runs a fast pre-filter that marks the answer on the map or off it. The pre-filter is the trigger, not the verdict: a flag routes to grounding against verified registries and cross-model checks, which decide whether to answer or abstain rather than bluff.

try
How it reads

No mind to read — so read the confidence.

On a model we can open, Aperture reads the activations. Behind a closed API there are none — so it reads the one thing the API does return: the model’s own token-by-token confidence as the answer forms. That reading is a cheap pre-filter, not the fabrication-catch — it cheaply triages which answers to scrutinize.

01

Ask, with logprobs on

The closed model answers in its usual confident voice, and returns a confidence for every token it emits.

02

Read the fingerprint

A learned probe reads the shape of that confidence across the whole answer — mean and floor of the logprobs, the entropy at each step.

03

Flag for the catch

Grounded answers hold steady confidence; a fabrication’s confidence collapses across its own tokens. A collapse flags the answer — then grounding against verified registries and a cross-model check decide it.

A model is measurably less sure across its whole answer when it’s inventing — even while its first word sounds confident, and it never says “I don’t know.” The pre-filter notices that; grounding and cross-model checks catch the fabrication.

Or don’t send it at all

Run the reader inside your own walls.

The frontier reading is the path for models you can’t open. For the ones you can — or for queries that can’t leave the building — Photon Base self-hosts: the same pre-filter, grounding, and abstain-rather-than-bluff logic, with your data never leaving your infrastructure.

And whichever path answers, the verdict comes with a verifiable signed receipt — ed25519, independently checkable against our published public key — so a downstream reader can confirm the call without trusting us. See the receipt verify, in-browser → or download the open verifier and check it offline, no call back to us.

The evidence

It holds where the model’s own confidence doesn’t.

≈0.89–0.92this demo’s per-model AUROC on closed models that confabulate (gpt-4o-mini 0.915, gpt-4o 0.893) — the 2026-06-07 serving-matched re-fit, the conservative probe the demo actually reads with, tuned to not false-flag real entities in free-form queries. Certify per model, not one global threshold
0.93–0.96an OpenAI-trained probe reads the off-map confidence signal in Mistral and a Google (Gemma) model zero-shot — no retraining
0.32 → 0.905on a model whose own first-token entropy runs low (gpt-3.5-turbo, 0.32), the learned probe still reads fabrication at 0.905

What this probe is: a cheap pre-filter and an attestation coordinate — never the fabrication-catch mechanism. The mind-geometry doesn’t cross a closed API (residual-field RSA ≈ 0.02); it’s the output-confidence signal that crosses, and it certifies per model, not from one global threshold.

The fine print — two numbers, multi-surface coverage
Why two numbers? This demo reads with the serving-matched probe (gpt-4o-mini 0.915); the registry wall certifies the same model at 0.972 on a fixed 168-item battery. Same instrument, two batteries — the demo uses the more conservative fit on purpose. AUROC is per-model and per-battery.

Coverage is multi-surface, not universal: it reaches models that expose token logprobs (OpenAI, xAI, DeepSeek, Qwen, Mistral, GLM), but endpoints that don't expose token logprobs (e.g. Anthropic) route to a hedge-text reader instead. It also pairs with that reader for models that refuse in words. We say so.
The other half

This is the model you can’t open.

When you can open the model, Aperture reads its mind directly — the off-map certificate, live and read-only. Same honesty, one layer deeper.