Skip to content Skip to content

For grantmakers and technical funders · current priority

Fund the independent validation study

Palimpsest has already frozen and published a 145-row sample, the codebook and the analysis procedure for its AI-response classifier. The remaining gap is human work: two independent coders must label the same sample before the project can publish an inter-rater reliability result.

Fund independent validation Inspect the frozen study

The funding case in one minute

The method is ready. The independent coding is not.

Funding pays for two attested coding passes. Palimpsest will publish the completed sheets, the agreement calculation and the study's limitations whatever the result. A low agreement score would reject the labelling scheme; it will not be hidden or replaced.

Open the print-friendly grant brief · Review the public funding ledger · Open a written funding inquiry

not loaded

sealed attestations in the eval registry, each one a frozen probe set and a named model, chained to the entry before it

chain state: not loaded

measured: not loaded

eval-registry-latest.json · the chain itself

not loaded

entries in the sealed erasure ledger, a second and separate hash chain covering the censorship observations

chain state: not loaded

measured: not loaded

erasure-observatory-latest.json · the ledger itself

not loaded

one step forecasts scored against what actually happened next, including every one the published band got wrong

coverage: not loaded

measured: not loaded

forecast-ledger-latest.json · history

01 · Why this exists

She saw a censored answer. Then she built the proof a screenshot could not provide.

Stated without jargon, in one paragraph, because a funder should not need the vocabulary of the field to decide whether this matters.

The founding observation

The author tested Chinese and state-aligned LLMs on documented political events and direct criticism of Chinese Communist Party policy. Responses did not merely become shorter: across models and languages, some refused, omitted the disputed facts, or substituted official framing.

That observation is why the censorship observatory and the AI eval registry are one project. A single screenshot is easy to dismiss and easy to select after the fact. Palimpsest instead freezes the question first, repeats it against controls and matched languages, publishes the answer, the denominator and the limitation, then seals the run.

This is not a claim that every Chinese model behaves identically, and it does not infer a provider's motive. It is a testable account of observed output differences. Independent studies have likewise reported bilingual political bias and refusal-to-reframing patterns. The founder's full account now publishes beside its evidence receipts, limitations and falsifier.

01 · observe a discrepancy 02 · freeze the test 03 · publish and seal the evidence

When a government censors, the evidence is an absence: a post that was there yesterday and is gone today, a website that stops resolving, an answer a chatbot used to give and now will not. Absences are hard to cite, which is why censorship is so often reported as anecdote. Palimpsest turns those absences into measurements. It archives public material first, watches for what disappears, probes AI models with the same frozen set of questions week after week to see what they quietly stop answering, and publishes each reading as a dated, openly licensed file with the raw evidence attached. Because a record of erasure is itself worth erasing, every entry is hashed into an append-only chain whose roots are stamped outside this project on a schedule. A reader can recompute the served chain offline and compare it with those witnesses; a conflicting rewrite becomes detectable instead of resting on the operator's word.

  • The censorship observatory Deletion, blocking and rewriting measured as data across the network layer, the model layer and the narrative layer, refreshing on its own schedule without a human in the loop. Live observatory, erasure observatory, the brief.
  • The verifiable eval registry AI evaluations sealed at publication. Every matching run must follow a declared commitment in the registry; current collectors additionally require an exact protocol in a separate public commit before any model query. The legacy GFI v1 boundary remains visibly partial rather than being retroactively upgraded. Chinese state-aligned models and Western frontier models use the same integrity machinery but separate, scoped suites. The registry, the Generative Firewall Index.
  • Both are free to everyone, forever Every reading is a public file. There is no gated tier, no dataset held back, no commercial version. Data and method for researchers, every dataset published.

02 · Is it real

It is running right now, and you can check it without asking us

The strongest thing this project can offer a funder is not a description of itself. It is a set of files that were written by machines on a schedule, that carry their own timestamps, and that fail verification if anyone touches them.

The numbers in this column are fetched from those files as you read. If a fetch fails, the card says so in red instead of showing a figure.

The sealed record

not loaded

attestations in the eval chain, of which not loaded are sealed model runs and not loaded are pre registrations committing a probe set before the model saw it.

chain verified
not loaded
models covered
not loaded
merkle root
not loaded
head hash
not loaded
first entry
not loaded
verify offline
not loaded

measured: not loaded

The claim ceiling—not a vanity grade

not loaded

The machine-readable assurance report has not loaded.

checks passing
not loaded
partial
not loaded
pending / open
not loaded
failed
not loaded

limits: not loaded

assessed: not loaded

eval-assurance-latest.json

The external anchor

A chain you keep to yourself proves nothing. Both roots are stamped outside this project, so the publication date of a root is attested by something that has no interest in Palimpsest being right.

OpenTimestamps
not loaded
Internet Archive
not loaded
registry root
not loaded
erasure root
not loaded
reconciliation
not loaded

stamped: not loaded

anchors-latest.json · every stamp ever taken

  • The code is the whole project Collectors, processors, verifiers, tests and the site itself are in one public repository under MIT. github.com/beepboop2025/palimpsest.
  • The signals refresh unattended Each signal is a scheduled workflow that writes a dated file, and its run history is public. Every scheduled run.
  • There is a test suite, and it is the honest kind Alongside the ordinary unit tests are tests that exist to stop the project fooling itself, for example that a transport failure is never recorded as a takedown, that an empty corpus makes the index abstain rather than print a zero, and that the published cadence matches the actual cron. The tests.
  • Anyone can verify the chains offline Two commands, standard library only, no key and no server. Change one sealed byte and the verifier names the break. How the sealing works.

03 · Is it a public good

Free, open, independently funded, and structurally unable to sell you out

Public good is a claim about structure, not intention, so each line here points at the thing that makes it true rather than at a promise.

  • MIT licensed, in full Code and data both. Anyone may run it, fork it, or replace the maintainer entirely. LICENSE.
  • No paywall and no gated tier Every reading on this site is a plain JSON file served to anyone who asks, with a history file beside it. There is no premium dataset and no embargo window. The readings index.
  • No advertising or paid placement Support is voluntary, whether through GitHub Sponsors or crypto. It never buys a say in research questions, methods, findings or the publication schedule. The individual support page.
  • It never monetizes the people it observes The subject of measurement is the act of suppression. There is no product built on the speakers, no profile of any individual, and no data sold about anyone. SAFETY.md.
  • Built to be cited and replicated, not depended on Method notes, a codebook and a citation file are published so the work survives this maintainer. Methodology, how to cite.

The public-good house

A grant to this house funds three surfaces that observe, seal, and publish. They have no financial authority. They do not sell a named-list seat, they do not size paper risk, and they do not post to the Liquidity Lab morning channel.

  • Palimpsest Censorship measurements and sealed AI evaluations. This page is the grant door. palimpsest.info.
  • Evidence Signal The Telegram house for reviewed public-interest evidence. t.me/EvidenceSignalDesk.
  • NarcoScope Official drug-market records turned into inspectable evidence stories. narcoscope.com.

ScamShield triage also publishes on Evidence Signal. It stays inside this house. Liquidity Lab (Seiche, LiquiLens, Undertow) is a sibling software company with its own invoice path.

Individual donors have their own page and it stays deliberately separate from this one. If you are giving personally rather than institutionally, start there. Funding of either kind pays for measurement infrastructure only.

04 · Is it rigorous

It keeps a public score of its own forecasts, misses included

Any observatory can publish a number. The question that separates an instrument from a dashboard is whether it says how wrong it expects to be, and then reports back when it was wrong.

Palimpsest scores every signal prequentially: each reading is forecast from only its own past, never refitted with hindsight, and scored by a proper rule against a fixed quantile baseline. The misses are published in full, because a forecast record with the misses removed is worth nothing.

Calibration of the published bands

not loaded

of readings fell inside the 80 percent band, over not loaded one step forecasts across not loaded signals. A band that is honest should land near its nominal rate, not above it.

not loaded

measured: not loaded

forecast-ledger-latest.json

Per signal, including where the adaptive band lost to the baseline

Signal Forecasts Coverage Nominal Misses Beats baseline
not loaded

not loaded

The worst miss on each signal

This table is the point of the section. These are the readings the published interval failed to contain, taken straight from the ledger with nothing removed. Values are in each signal's own units and do not compare across rows.

Signal Step Forecast 80% band Actual Missed by
not loaded

not loaded

not loaded

not loaded

When methods disagree, the interval is the answer

not loaded

not loaded

not loaded

OONI
not loaded
Censored Planet
not loaded
agreement
not loaded
weighted midpoint
not loaded

not loaded

measured: not loaded

vantage-fusion-latest.json

  • The scoring method is one a reviewer can attack Strictly prequential forecasts, adaptive conformal bands valid under distribution shift, scored by the Weighted Interval Score against a fixed quantile baseline. The point forecast is a random walk on purpose, because the claim being tested is calibration and not sharpness. The scorer.
  • Movement is checked against its own measurement coverage Before a signal is allowed to look like news, it is tested against the possibility that only the sample size moved. A verdict that does not survive that conditioning is published as coverage confounded rather than as a finding. coverage-guard-latest.json.
  • The detection method is retrodicted against documented events The censor attention scorer is run unmodified over six documented censorship events from 2020 to 2023, reconstructed from public documentation, and the top ranked term is the event's own term in all six, never a high volume background term. What is not validated by that exercise is stated in the same document. docs/VALIDATION.md.
  • The human coding study is published as unfinished The sampler, the codebook and the frozen blind sheet for the generative firewall labels are in the repository, drawn with a disclosed seed and with the shortfalls in the rare cells recorded rather than hidden. The answer key is deliberately withheld until both coders finish, because it carries the machine label for every row; its digest is published now, so the key released afterwards is checkable against a commitment that predates the labels, and CI recomputes the seal on the published sheet every run. The two coder pass has not been run, so no inter rater agreement figure is published and none is claimed. Funding that study is one of the things this page is asking for. The live assurance report is required to keep this dimension pending until a coded result actually exists. The frozen study, the codebook, the agreement script that is waiting on coders.

05 · Is it safe

Watch the censor, never the censored

Censorship measurement has a history of getting people detained. The safety rules here are architectural, written into how collection works rather than added as a policy page, and they are the reason several otherwise useful capabilities do not exist in this codebase.

  • Public reads only Palimpsest looks at material that was already published in public, and at the fact that it later disappeared. It never deanonymizes a contributor and never profiles an individual.
  • Nobody inside the censoring jurisdiction is ever asked to act The system observes from outside. It places no person in country at risk to gather a data point. Where a vantage inside a censored network is used, it is volunteer hosted infrastructure of an existing measurement platform, and that constraint is surfaced on the reading rather than buried.
  • The subject is the state, not the speaker The unit of analysis is the act of suppression. The gazetteer identifies the vocabulary of censorship, not any person.
  • No state aligned model is ever the analyst The classifier patterns and the sensitive terms list are authored directly and are never delegated to a model aligned with the government being measured, because such a model quietly omits the most sensitive terms. That asymmetry is designed around on purpose. State aligned models are objects of measurement here, never instruments of it.
  • A deletion is never claimed lightly The detector probes a known live control post first each cycle. If the network looks unreliable the whole cycle is marked degraded and every deletion write is suppressed, so a flaky connection can never be recorded as censorship.
  • Offensive capability is out of scope, not backlogged Requests to add intrusion or deanonymization are declined as out of scope rather than triaged as features.

The rules above are published, versioned and enforceable against the code:

SAFETY.md · docs/ETHICS.md · SECURITY.md · docs/OSINT_SOURCES.md

Source safety overrides every other consideration, including completeness of measurement. If any part of this project could endanger a person, the private reporting route in SECURITY.md is the right channel and it reaches the maintainer with no public trace.

06 · What money buys

One immediate study, then three continuing infrastructure needs

The current campaign is deliberately narrow: pay two independent coders to finish the pre-registered validation study. Continuing support can expand the measurement capacity described after it.

The planned campaign target is $1,800 for two independent Mandarin-speaking coders. It is a forward honoraria budget, not an invoice, amount spent or claim about funds received. The public funding ledger keeps that target separate from reconciled income and expenses.

Priority · Two independent human coding passes

The sampling frame, 145-row sheet, codebook and analysis script are already published. What is missing is paid coder time. Both coders must work independently and attest that they did not inspect the classifier or answer key while coding.

The deliverable is public: completed coding sheets, the calculated agreement result and the study limitations. The frozen protocol says that Krippendorff's alpha below 0.667 rejects the labelling scheme, so funding completion does not buy a favourable result.

Current status: pre-registered, not yet coded; no human agreement figure exists.

frozen study · codebook · agreement script

After the study · Independent vantage points

Censorship is vantage dependent. Two independent methods can legitimately disagree because of routing, partial deployment or probe location, and when they do, the honest published answer is a range rather than a midpoint. Egress and vantage infrastructure is what narrows that range, and it is the largest recurring line in running this project.

The gap, live and unretouched:

not loaded

vantage-fusion-latest.json

After the study · Archival storage and external anchoring

Deletion is only measurable if the original was captured first, so the archive grows every cycle and nothing is ever removed from it. Anchoring costs sit here too: each root has to be stamped outside this project for the seal to mean anything to a stranger.

The gap, live and unretouched:

not loaded

anchors-latest.json · the sealed ledger

After the study · Model probe budget

The eval registry pays per query. Every sealed run is a frozen probe set put to a named model, and the value of the series comes from repeating it on a schedule for long enough that drift becomes visible. More budget means more models, more languages, and a denser series rather than a sparser one.

The gap, live and unretouched:

not loaded

eval-registry-latest.json

07 · Contact

Asynchronous funder contact

No call is required. The currently verified route is the project's public issue tracker. Do not include confidential material there.

  • Funders and institutions Open a public funding inquiry asking for diligence material, the current reconciled budget, or a written walkthrough of the verification path. Do not post confidential documents. Start with the one-page grant brief and public funding ledger.
  • Anything touching a person's safety Use the private reporting route in SECURITY.md rather than a public issue. It reaches the maintainer with no public trace. SECURITY.md.
  • Individuals who want to give Sponsor monthly or once through GitHub, or use the crypto route if you prefer a permissionless transfer. Neither route buys influence over the work. GitHub Sponsors, Giveth listing, direct crypto support. The Giveth verification application is submitted but not yet approved, and the project is not yet GIVbacks eligible. Card checkout happens on GitHub; Palimpsest does not collect or store donor card or bank details.
  • Help that is not money Cite the data in research and journalism, replicate a reading and say where it disagreed, or volunteer as a coder for the validation study. Coders are the single most useful non financial contribution right now. For researchers, contributing.

This page names no team size or funding total because neither has a published, reconciled source. What is checkable is linked; what is not yet checkable is labelled as missing.

Palimpsest is MIT licensed and developed in the open as a public good. It watches the censor, never the censored. Every finding ships its raw evidence.
Home · Readings · For researchers · Sponsor · Individual support · Source