European & American AI Research Lab Bari (Apulia) · San Francisco · 10K+ citations

The guardrail for the
agentic and voice era.

In the agentic and voice era, the guardrail is called 100× more often than yesterday's model. We have the economics to be there on every call — with a verdict that is deterministic and recomputable by an auditor who doesn't trust us.

Geodesia is a European and American AI research lab — labs in Bari (Apulia), Italy and San Francisco, California. G-1, our first product, is live — a real-time, non-invasive trust layer that drops in front of any open-source LLM (vLLM, SGLang, TensorRT-LLM, llama.cpp, Ollama, OpenAI-compatible APIs), a streaming voice/audio pipeline, or an agentic MCP tool-loop. All nine safety axes in a single ~300M forward pass — 28–30 ms ingress, one GPU: cheap and fast enough to run on every agent step and every voice chunk, where 8B-class stacks can only afford the final check. Every verdict is a token-level, per-axis reason-code, sealed in a cryptographic audit chain and exportable as a regulator-ready PDF. Runs on your own infrastructure. Zero data egress.

A European & American frontier AI lab.
One trust layer.

Built across two labs — Bari (Apulia), Italy and San Francisco, California — we work on three frontiers: the safety of open-source LLMs, mechanistic explainability of model behaviour, and geometric deep learning. Every output is a peer-reviewed paper and a production capability. G-1 is live today. Our next product, GLAD-Manifold, is a physical, geometric reinvention of the Transformer — and the foundation of the AI and reasoning models that come after it.

Geodesia G-1 · Generally Available

Frontier-grade safety
for any LLM or voice AI.

Trust at the speed of light. No compromise.

G-1 sits in front of your model as a real-time, drop-in OpenAI/Ollama proxy — runs on official, unmodified vLLM, SGLang, TensorRT-LLM, llama.cpp, Ollama, or any OpenAI-compatible endpoint, and on streaming voice/audio pipelines. Nine-axis screening (prompt safety, jailbreak, RAG context-injection, hallucination-on-context, closed-book hallucination, answer safety, profanity, out-of-scope, prompt-complexity routing) powered by our proprietary multimodal model, with a calibrated probability in [0,1] per axis — the ingress pass returns in 28–30 ms for a 2048-token prompt on a single GPU. Constitutional Intelligence aligned to European values. The same layer now guards agentic MCP tool-calls and live web search — not just chat — improves with use under human supervision, and offers an optional 8B-class deep-scan. A compliance platform that auto-generates auditable PDFs for the EU AI Act, California SB 942, and 11 other AI frameworks.

G-1 Product Page Download Whitepaper
0.9405
Context-injection
OOD AUROC · test v4 · RAG-firewall
0.9892
Prompt safety
OOD AUROC · test v5 multilingual
9
Detection axes
28–30 ms ingress / 2048 tok
13
Frameworks
natively mapped · auto-PDF

Not another guardrail.
A different battleground.

Detection quality is table stakes — everyone benchmarks AUROC. We compete where no one can follow: the economics to sit on every agent step and voice chunk, verdicts that are legal evidence, and the one category that is still empty — voice.

The economics of one forward pass

Nine axes, ~300M parameters, 28–30 ms ingress, one GPU, on-prem. Agents multiply LLM calls 10–100× per task and voice generates continuous streams — at that volume the guardrail's cost and latency become the buying criterion. G-1 is cheap and fast enough to run on every step and every chunk, before the model is even called; 8B-class stacks can only afford the final check. The more the world goes agentic and vocal, the wider the gap.

⚖️

Evidence-grade verdicts

Causal attribution, per axis, without model internals — which words drove each flag, computed as a measurement on a deterministic function, not an LLM-generated rationale. Competitors return a boolean, a regex match, or a slow textual rationale. G-1 turns every verdict into a reason-code recomputable by a third party, sealed in a cryptographic audit chain and exportable as a regulator-ready PDF. Built for EU AI Act Art. 13 & 14 and GDPR Art. 22.

🎙️

The trust layer for voice AI

A category almost no one occupies — the incumbents' audio defence is "coming soon", and no hallucination detector touches speech. G-1 screens the streaming transcript on the same input path as typed chat and halts mid-sentence — stopping a jailbreak or a fabrication while it is being spoken, not after. Voice agents in banking, health and customer care are exactly EU AI Act Annex III.

One stack to cover safety + hallucination + injection:

Geodesia G-1 — nine axes, ~300M parameters, 28–30 ms ingress pass, 1 GPU, yours — runs safety, hallucination, and injection detection in a single on-prem forward pass, rather than a serial stack of separate large guards.

On closed-book truthfulness we are deliberately honest: our OOD number (0.769) is measured on entire held-out sources the model never saw, not on an internal-latent-state or multi-generation-resampling method — those approaches need access we don't require, and we're candid that this tradeoff costs us AUROC. We win on the ground that ships, not the leaderboard that doesn't.

Safety is not a property
of the model. It's a property of you.

What should be blocked isn't decided by the model — it's decided by the company deploying it, its industry, and its internal policy, and it's different for every product. A hospital's over-refusal threshold is a bank's bare minimum. A phrase that's an attack inside a customer-support bot is a red team's everyday vocabulary. No generalist safety model can encode this, and no vendor can hand it to you pre-configured. Geodesia doesn't sell a fixed line — it sells a system that learns your line from your traffic, under human supervision, inside your perimeter.

Immediate

You move a threshold through Policy Lens and it's live from the very next request — after Policy Lens simulates its exact effect on your real traffic first.

Fast

An approved correction enters an episodic memory consulted at scoring time — the corrected pattern is recalled without retraining anything.

Structural

The approved corpus enters the model weights — deliberately, only when a human decides it belongs there.

A ~300M-parameter detector.
Nine axes, measured honestly.

Geodesia G-1 is a guardrail, not a chatbot — so we don't benchmark it against generator models. Every number below is an AUROC computed on entire datasets held out from training, across two evaluation runs: test v4 (English, six labeled axes) and test v5 (multilingual, two labeled axes).

Axis OOD AUROC · test v4 (EN) OOD AUROC · test v5 (ML)
Context-injection · RAG-firewall 0.9405
Prompt safety 0.9204 0.9892
Answer safety 0.9174
Hallucination-on-context 0.8671
Jailbreak 0.8623 0.8426
Closed-book hallucination (advisory) 0.769
MACRO 0.8795 (6 axes) 0.9159 (2 axes)

How these numbers are measured. Every AUROC here is computed on entire datasets held out from training — not rows set aside, but sources the model never saw in any form. Cross-referencing this checkpoint's training-era corpus against the two test sets' sources yields 0 shared sources out of 18 for the English test and 0 out of 26 for the multilingual one. In-distribution numbers, which most LLM-safety vendors publish, systematically reward memorization — our numbers are lower, and that's exactly the point.

Three axes — profanity, out-of-scope, prompt-complexity — run in the same forward pass but are covered by neither test set yet, so they ship in annotate-only mode until an operator promotes them.

Checkpoint gladg_v3_psjbft_ep0, corpora corpus_ood_test_v4 / corpus_ood_test_v5_ml. Closed-book is shipped as advisory: it raises a high-confidence flag for human review on confidently-incorrect answers, not a hard block. Full per-axis breakdown, latency, and methodology on the G-1 product page.

See what your
compliance team will actually use.

G-1 ships with a complete operator console. Six workspaces — Chat, Causal Explainability, Agent Flow Debugger, Agent & MCP Security, and the Compliance Reports Generator — each mapped to a phase of the EU AI Act governance lifecycle. The runtime catches the failure; the platform turns the catch into evidence a regulator will accept.

Geodesia G-1 Chat workspace: the runtime intercepting a hallucinated answer with full diagnostic signals (Hallucination, Prompt Safety, Answer Safety) and Constitutional Intelligence active.

Now it protects agents,
not just chats.

The same real-time trust layer now covers agentic tool-calls, live web search, three new detection axes, and a threshold simulator to move the safety line — and gets harder to fool the more it is used.

🧩 Agent & MCP Security

Inspects the full Model Context Protocol lifecycle — tool discovery, calls, results, resources — with allow / warn / block verdicts. Stops tool poisoning, indirect injection and data exfiltration.

🔬 Deep-Scan

Optional 8B-class safety judge for maximum depth, reading internal states across the safety axes.

🎯 SLEDGE

Closed-book truthfulness recalibrated per served model, with a conformal false-positive guarantee and hot-reload.

♻️ Self-Evolving Security

Three horizons, one loop, under human supervision: an immediate Policy Lens threshold, a fast episodic-memory correction, a structural gated retraining — incidents are memorised, not trained on, until a human decides. How it works →

🌐 Web Search Firewall

Every fetched page screened before it can ground an answer — injection blocked, safe pages read.

🆘 Crisis detection

A dedicated crisis / self-harm detector — including euphemisms and short queries.

🧹 Three new axes

Profanity, out-of-scope, prompt-complexity — same forward pass, annotate-only until an operator promotes them.

💰 Cost control

out_of_scope rejects before the upstream call; prompt_complexity routes cheap vs. capable models — a guardrail that saves tokens instead of spending them.

🎚️ Policy Lens

A counterfactual threshold simulator over your own logged requests, validated against your reviewers' corrections.

Three doors, depending on what you need.

The Product

Geodesia G-1

The trust layer in detail: architecture, Constitutional Intelligence, the compliance platform, benchmarks, and how it deploys inside your perimeter.

Product page → vLLM · on-prem · zero egress
The Lab

Research & Roadmap

Three research pillars, peer-reviewed work (MuPAX, EVIDENCE, NSP), and what comes after G-1: GLAD-Manifold, our physical, geometric world model.

Research → Bari · Stanford
The Document

G-1 Whitepaper

The full technical whitepaper for compliance officers, Chief Risk Officers, and AI leadership. Architecture, compliance, three enterprise use cases.

Overview → PDF · 10 pages · June 2026
Made in Bari & San Francisco with

Talk to the lab.
Audit the platform.

For CISOs, Heads of AI, DPOs, and legal teams evaluating regulated LLM deployment. Live demo. Sandbox access. Reference architecture review.