For grantmakers and technical funders · current priority
Fund the independent validation study
Palimpsest has already frozen and published a 145-row sample, the codebook and the analysis procedure for its AI-response classifier. The remaining gap is human work: two independent coders must label the same sample before the project can publish an inter-rater reliability result.
Fund independent validation Inspect the frozen study
The funding case in one minute
The method is ready. The independent coding is not.
Funding pays for two attested coding passes. Palimpsest will publish the completed sheets, the agreement calculation and the study's limitations whatever the result. A low agreement score would reject the labelling scheme; it will not be hidden or replaced.
Open the print-friendly grant brief · Review the public funding ledger · Open a written funding inquiry
sealed attestations in the eval registry, each one a frozen probe set and a named model, chained to the entry before it
entries in the sealed erasure ledger, a second and separate hash chain covering the censorship observations
one step forecasts scored against what actually happened next, including every one the published band got wrong
01 · Why this exists
She saw a censored answer. Then she built the proof a screenshot could not provide.
Stated without jargon, in one paragraph, because a funder should not need the vocabulary of the field to decide whether this matters.
The founding observation
The author tested Chinese and state-aligned LLMs on documented political events and direct criticism of Chinese Communist Party policy. Responses did not merely become shorter: across models and languages, some refused, omitted the disputed facts, or substituted official framing.
That observation is why the censorship observatory and the AI eval registry are one project. A single screenshot is easy to dismiss and easy to select after the fact. Palimpsest instead freezes the question first, repeats it against controls and matched languages, publishes the answer, the denominator and the limitation, then seals the run.
This is not a claim that every Chinese model behaves identically, and it does not infer a provider's motive. It is a testable account of observed output differences. Independent studies have likewise reported bilingual political bias and refusal-to-reframing patterns. The founder's full account now publishes beside its evidence receipts, limitations and falsifier.
When a government censors, the evidence is an absence: a post that was there yesterday and is gone today, a website that stops resolving, an answer a chatbot used to give and now will not. Absences are hard to cite, which is why censorship is so often reported as anecdote. Palimpsest turns those absences into measurements. It archives public material first, watches for what disappears, probes AI models with the same frozen set of questions week after week to see what they quietly stop answering, and publishes each reading as a dated, openly licensed file with the raw evidence attached. Because a record of erasure is itself worth erasing, every entry is hashed into an append-only chain whose roots are stamped outside this project on a schedule. A reader can recompute the served chain offline and compare it with those witnesses; a conflicting rewrite becomes detectable instead of resting on the operator's word.
- The censorship observatory Deletion, blocking and rewriting measured as data across the network layer, the model layer and the narrative layer, refreshing on its own schedule without a human in the loop. Live observatory, erasure observatory, the brief.
- The verifiable eval registry AI evaluations sealed at publication. Every matching run must follow a declared commitment in the registry; current collectors additionally require an exact protocol in a separate public commit before any model query. The legacy GFI v1 boundary remains visibly partial rather than being retroactively upgraded. Chinese state-aligned models and Western frontier models use the same integrity machinery but separate, scoped suites. The registry, the Generative Firewall Index.
- Both are free to everyone, forever Every reading is a public file. There is no gated tier, no dataset held back, no commercial version. Data and method for researchers, every dataset published.
02 · Is it real
It is running right now, and you can check it without asking us
The strongest thing this project can offer a funder is not a description of itself. It is a set of files that were written by machines on a schedule, that carry their own timestamps, and that fail verification if anyone touches them.
The numbers in this column are fetched from those files as you read. If a fetch fails, the card says so in red instead of showing a figure.
The sealed record
not loaded
attestations in the eval chain, of which not loaded are sealed model runs and not loaded are pre registrations committing a probe set before the model saw it.
- chain verified
- not loaded
- models covered
- not loaded
- merkle root
- not loaded
- head hash
- not loaded
- first entry
- not loaded
- verify offline
- not loaded
measured: not loaded
The claim ceiling—not a vanity grade
not loaded
The machine-readable assurance report has not loaded.
- checks passing
- not loaded
- partial
- not loaded
- pending / open
- not loaded
- failed
- not loaded
limits: not loaded
assessed: not loaded
The external anchor
A chain you keep to yourself proves nothing. Both roots are stamped outside this project, so the publication date of a root is attested by something that has no interest in Palimpsest being right.
- OpenTimestamps
- not loaded
- Internet Archive
- not loaded
- registry root
- not loaded
- erasure root
- not loaded
- reconciliation
- not loaded
stamped: not loaded
- The code is the whole project Collectors, processors, verifiers, tests and the site itself are in one public repository under MIT. github.com/beepboop2025/palimpsest.
- The signals refresh unattended Each signal is a scheduled workflow that writes a dated file, and its run history is public. Every scheduled run.
- There is a test suite, and it is the honest kind Alongside the ordinary unit tests are tests that exist to stop the project fooling itself, for example that a transport failure is never recorded as a takedown, that an empty corpus makes the index abstain rather than print a zero, and that the published cadence matches the actual cron. The tests.
- Anyone can verify the chains offline Two commands, standard library only, no key and no server. Change one sealed byte and the verifier names the break. How the sealing works.
03 · Is it a public good
Free, open, independently funded, and structurally unable to sell you out
Public good is a claim about structure, not intention, so each line here points at the thing that makes it true rather than at a promise.
- MIT licensed, in full Code and data both. Anyone may run it, fork it, or replace the maintainer entirely. LICENSE.
- No paywall and no gated tier Every reading on this site is a plain JSON file served to anyone who asks, with a history file beside it. There is no premium dataset and no embargo window. The readings index.
- No advertising or paid placement Support is voluntary, whether through GitHub Sponsors or crypto. It never buys a say in research questions, methods, findings or the publication schedule. The individual support page.
- It never monetizes the people it observes The subject of measurement is the act of suppression. There is no product built on the speakers, no profile of any individual, and no data sold about anyone. SAFETY.md.
- Built to be cited and replicated, not depended on Method notes, a codebook and a citation file are published so the work survives this maintainer. Methodology, how to cite.
The public-good house
A grant to this house funds three surfaces that observe, seal, and publish. They have no financial authority. They do not sell a named-list seat, they do not size paper risk, and they do not post to the Liquidity Lab morning channel.
- Palimpsest Censorship measurements and sealed AI evaluations. This page is the grant door. palimpsest.info.
- Evidence Signal The Telegram house for reviewed public-interest evidence. t.me/EvidenceSignalDesk.
- NarcoScope Official drug-market records turned into inspectable evidence stories. narcoscope.com.
ScamShield triage also publishes on Evidence Signal. It stays inside this house. Liquidity Lab (Seiche, LiquiLens, Undertow) is a sibling software company with its own invoice path.
Individual donors have their own page and it stays deliberately separate from this one. If you are giving personally rather than institutionally, start there. Funding of either kind pays for measurement infrastructure only.
04 · Is it rigorous
It keeps a public score of its own forecasts, misses included
Any observatory can publish a number. The question that separates an instrument from a dashboard is whether it says how wrong it expects to be, and then reports back when it was wrong.
Palimpsest scores every signal prequentially: each reading is forecast from only its own past, never refitted with hindsight, and scored by a proper rule against a fixed quantile baseline. The misses are published in full, because a forecast record with the misses removed is worth nothing.
Calibration of the published bands
not loaded
of readings fell inside the 80 percent band, over not loaded one step forecasts across not loaded signals. A band that is honest should land near its nominal rate, not above it.
not loaded
measured: not loaded
Per signal, including where the adaptive band lost to the baseline
| Signal | Forecasts | Coverage | Nominal | Misses | Beats baseline |
|---|---|---|---|---|---|
| not loaded | |||||
not loaded
The worst miss on each signal
This table is the point of the section. These are the readings the published interval failed to contain, taken straight from the ledger with nothing removed. Values are in each signal's own units and do not compare across rows.
| Signal | Step | Forecast | 80% band | Actual | Missed by |
|---|---|---|---|---|---|
| not loaded | |||||
not loaded
not loaded
not loaded
When methods disagree, the interval is the answer
not loaded
not loaded
not loaded
- OONI
- not loaded
- Censored Planet
- not loaded
- agreement
- not loaded
- weighted midpoint
- not loaded
not loaded
measured: not loaded
- The scoring method is one a reviewer can attack Strictly prequential forecasts, adaptive conformal bands valid under distribution shift, scored by the Weighted Interval Score against a fixed quantile baseline. The point forecast is a random walk on purpose, because the claim being tested is calibration and not sharpness. The scorer.
- Movement is checked against its own measurement coverage Before a signal is allowed to look like news, it is tested against the possibility that only the sample size moved. A verdict that does not survive that conditioning is published as coverage confounded rather than as a finding. coverage-guard-latest.json.
- The detection method is retrodicted against documented events The censor attention scorer is run unmodified over six documented censorship events from 2020 to 2023, reconstructed from public documentation, and the top ranked term is the event's own term in all six, never a high volume background term. What is not validated by that exercise is stated in the same document. docs/VALIDATION.md.
- The human coding study is published as unfinished The sampler, the codebook and the frozen blind sheet for the generative firewall labels are in the repository, drawn with a disclosed seed and with the shortfalls in the rare cells recorded rather than hidden. The answer key is deliberately withheld until both coders finish, because it carries the machine label for every row; its digest is published now, so the key released afterwards is checkable against a commitment that predates the labels, and CI recomputes the seal on the published sheet every run. The two coder pass has not been run, so no inter rater agreement figure is published and none is claimed. Funding that study is one of the things this page is asking for. The live assurance report is required to keep this dimension pending until a coded result actually exists. The frozen study, the codebook, the agreement script that is waiting on coders.
05 · Is it safe
Watch the censor, never the censored
Censorship measurement has a history of getting people detained. The safety rules here are architectural, written into how collection works rather than added as a policy page, and they are the reason several otherwise useful capabilities do not exist in this codebase.
- Public reads only Palimpsest looks at material that was already published in public, and at the fact that it later disappeared. It never deanonymizes a contributor and never profiles an individual.
- Nobody inside the censoring jurisdiction is ever asked to act The system observes from outside. It places no person in country at risk to gather a data point. Where a vantage inside a censored network is used, it is volunteer hosted infrastructure of an existing measurement platform, and that constraint is surfaced on the reading rather than buried.
- The subject is the state, not the speaker The unit of analysis is the act of suppression. The gazetteer identifies the vocabulary of censorship, not any person.
- No state aligned model is ever the analyst The classifier patterns and the sensitive terms list are authored directly and are never delegated to a model aligned with the government being measured, because such a model quietly omits the most sensitive terms. That asymmetry is designed around on purpose. State aligned models are objects of measurement here, never instruments of it.
- A deletion is never claimed lightly The detector probes a known live control post first each cycle. If the network looks unreliable the whole cycle is marked degraded and every deletion write is suppressed, so a flaky connection can never be recorded as censorship.
- Offensive capability is out of scope, not backlogged Requests to add intrusion or deanonymization are declined as out of scope rather than triaged as features.
The rules above are published, versioned and enforceable against the code:
SAFETY.md · docs/ETHICS.md · SECURITY.md · docs/OSINT_SOURCES.md
Source safety overrides every other consideration, including completeness of measurement. If any part of this project could endanger a person, the private reporting route in SECURITY.md is the right channel and it reaches the maintainer with no public trace.
06 · What money buys
One immediate study, then three continuing infrastructure needs
The current campaign is deliberately narrow: pay two independent coders to finish the pre-registered validation study. Continuing support can expand the measurement capacity described after it.
The planned campaign target is $1,800 for two independent Mandarin-speaking coders. It is a forward honoraria budget, not an invoice, amount spent or claim about funds received. The public funding ledger keeps that target separate from reconciled income and expenses.
Priority · Two independent human coding passes
The sampling frame, 145-row sheet, codebook and analysis script are already published. What is missing is paid coder time. Both coders must work independently and attest that they did not inspect the classifier or answer key while coding.
The deliverable is public: completed coding sheets, the calculated agreement result and the study limitations. The frozen protocol says that Krippendorff's alpha below 0.667 rejects the labelling scheme, so funding completion does not buy a favourable result.
Current status: pre-registered, not yet coded; no human agreement figure exists.
After the study · Independent vantage points
Censorship is vantage dependent. Two independent methods can legitimately disagree because of routing, partial deployment or probe location, and when they do, the honest published answer is a range rather than a midpoint. Egress and vantage infrastructure is what narrows that range, and it is the largest recurring line in running this project.
After the study · Archival storage and external anchoring
Deletion is only measurable if the original was captured first, so the archive grows every cycle and nothing is ever removed from it. Anchoring costs sit here too: each root has to be stamped outside this project for the seal to mean anything to a stranger.
After the study · Model probe budget
The eval registry pays per query. Every sealed run is a frozen probe set put to a named model, and the value of the series comes from repeating it on a schedule for long enough that drift becomes visible. More budget means more models, more languages, and a denser series rather than a sparser one.
07 · Contact
Asynchronous funder contact
No call is required. The currently verified route is the project's public issue tracker. Do not include confidential material there.
- Funders and institutions Open a public funding inquiry asking for diligence material, the current reconciled budget, or a written walkthrough of the verification path. Do not post confidential documents. Start with the one-page grant brief and public funding ledger.
- Anything touching a person's safety Use the private reporting route in SECURITY.md rather than a public issue. It reaches the maintainer with no public trace. SECURITY.md.
- Individuals who want to give Sponsor monthly or once through GitHub, or use the crypto route if you prefer a permissionless transfer. Neither route buys influence over the work. GitHub Sponsors, Giveth listing, direct crypto support. The Giveth verification application is submitted but not yet approved, and the project is not yet GIVbacks eligible. Card checkout happens on GitHub; Palimpsest does not collect or store donor card or bank details.
- Help that is not money Cite the data in research and journalism, replicate a reading and say where it disagreed, or volunteer as a coder for the validation study. Coders are the single most useful non financial contribution right now. For researchers, contributing.
This page names no team size or funding total because neither has a published, reconciled source. What is checkable is linked; what is not yet checkable is labelled as missing.
Palimpsest is MIT licensed and developed in the open as a public good. It watches the
censor, never the censored. Every finding ships its raw evidence.
Home ·
Readings ·
For researchers ·
Sponsor ·
Individual support ·
Source