Proof, at every layer.
“Trustworthy” is easy to write and hard to show. This page lists what we can demonstrate — the mechanism behind each claim, and the product it lives in.
Why. An upstream can swap the model, lower the tier, or serve from a pool of consumer accounts. The request returns 200. Nothing at the protocol level tells you.
How.
- Blind capability testsScience, mathematics, code, instruction following, tool use, abstract reasoning; fixed seeds, identical questions to every channel; public evaluation sets; wrong answers count as wrong, never as “too small a sample”.
- Upstream provenanceOfficial direct, cloud-hosted, relay, or consumer subscription pool — identified by independent probes, not by what the upstream declares.
- Independent axes of evidenceRelay, downgrade and origin are judged separately; weak evidence cannot launder a strong finding. Not tested ≠ tested clean. Where no conclusion can be reached, the report says so.
- Difficulty that never saturatesWhen a frontier model scores full marks, the set is too easy; it is hardened until the strongest model still has headroom.
- Scored and acted onA weighted score across capability, performance, reliability and verification; untested dimensions are removed rather than assumed. Channels that fail scheduled inspection are taken out of service automatically.
Every knowledge unit carries its origin — page and block coordinates for documents, timestamps for audio and video. When an agent answers, the source can be opened at exactly that place.
- Text: zero storage.Pass-through in memory, released on completion. Metadata only — timestamp, model, token counts, latency. Auditable by a third party of your choosing; written into the service agreement.
- Generated media.Stored once, in our own store, for delivery. Retention defaults to a fixed period you can change; the expiry is written at storage time and enforced — an expired asset is reported as expired, never as “not found”.
Quote → deduct → then call upstream. One generation, one ledger line. Prices are snapshotted into the line, so a later price change never alters history. A failed generation is refunded in full. The price shown is the price charged.
Every task records who started it, under which organisation and authorisation, which capabilities it called, what it consumed, and how it ended. Governance objects — people and organisation, enterprise capabilities, knowledge and agents, resources and security — each have configuration, authorisation, observation and audit views.
Service levels
Tiered SLA, committed in contract.