In the agentic and voice era, the guardrail is called 100× more often than yesterday's model. We have the economics to be there on every call — with a verdict that is deterministic and recomputable by an auditor who doesn't trust us.
Geodesia is a European and American AI research lab — labs in Bari (Apulia), Italy and San Francisco, California. G-1, our first product, is live — a real-time, non-invasive trust layer that drops in front of any open-source LLM (vLLM, SGLang, TensorRT-LLM, llama.cpp, Ollama, OpenAI-compatible APIs), a streaming voice/audio pipeline, or an agentic MCP tool-loop. All nine safety axes in a single ~300M forward pass — 28–30 ms ingress, one GPU: cheap and fast enough to run on every agent step and every voice chunk, where 8B-class stacks can only afford the final check. Every verdict is a token-level, per-axis reason-code, sealed in a cryptographic audit chain and exportable as a regulator-ready PDF. Runs on your own infrastructure. Zero data egress.
Built across two labs — Bari (Apulia), Italy and San Francisco, California — we work on three frontiers: the safety of open-source LLMs, mechanistic explainability of model behaviour, and geometric deep learning. Every output is a peer-reviewed paper and a production capability. G-1 is live today. Our next product, GLAD-Manifold, is a physical, geometric reinvention of the Transformer — and the foundation of the AI and reasoning models that come after it.
Trust at the speed of light. No compromise.
G-1 sits in front of your model as a real-time, drop-in OpenAI/Ollama proxy — runs on official, unmodified vLLM, SGLang, TensorRT-LLM, llama.cpp, Ollama, or any OpenAI-compatible endpoint, and on streaming voice/audio pipelines. Nine-axis screening (prompt safety, jailbreak, RAG context-injection, hallucination-on-context, closed-book hallucination, answer safety, profanity, out-of-scope, prompt-complexity routing) powered by our proprietary multimodal model, with a calibrated probability in [0,1] per axis — the ingress pass returns in 28–30 ms for a 2048-token prompt on a single GPU. Constitutional Intelligence aligned to European values. The same layer now guards agentic MCP tool-calls and live web search — not just chat — improves with use under human supervision, and offers an optional 8B-class deep-scan. A compliance platform that auto-generates auditable PDFs for the EU AI Act, California SB 942, and 11 other AI frameworks.
Detection quality is table stakes — everyone benchmarks AUROC. We compete where no one can follow: the economics to sit on every agent step and voice chunk, verdicts that are legal evidence, and the one category that is still empty — voice.
Nine axes, ~300M parameters, 28–30 ms ingress, one GPU, on-prem. Agents multiply LLM calls 10–100× per task and voice generates continuous streams — at that volume the guardrail's cost and latency become the buying criterion. G-1 is cheap and fast enough to run on every step and every chunk, before the model is even called; 8B-class stacks can only afford the final check. The more the world goes agentic and vocal, the wider the gap.
Causal attribution, per axis, without model internals — which words drove each flag, computed as a measurement on a deterministic function, not an LLM-generated rationale. Competitors return a boolean, a regex match, or a slow textual rationale. G-1 turns every verdict into a reason-code recomputable by a third party, sealed in a cryptographic audit chain and exportable as a regulator-ready PDF. Built for EU AI Act Art. 13 & 14 and GDPR Art. 22.
A category almost no one occupies — the incumbents' audio defence is "coming soon", and no hallucination detector touches speech. G-1 screens the streaming transcript on the same input path as typed chat and halts mid-sentence — stopping a jailbreak or a fabrication while it is being spoken, not after. Voice agents in banking, health and customer care are exactly EU AI Act Annex III.
One stack to cover safety + hallucination + injection:
Geodesia G-1 — nine axes, ~300M parameters, 28–30 ms ingress pass, 1 GPU, yours — runs safety, hallucination, and injection detection in a single on-prem forward pass, rather than a serial stack of separate large guards.
On closed-book truthfulness we are deliberately honest: our OOD number (0.769) is measured on entire held-out sources the model never saw, not on an internal-latent-state or multi-generation-resampling method — those approaches need access we don't require, and we're candid that this tradeoff costs us AUROC. We win on the ground that ships, not the leaderboard that doesn't.
Geodesia G-1 is a guardrail, not a chatbot — so we don't benchmark it against generator models. Every number below is an AUROC computed on entire datasets held out from training, across two evaluation runs: test v4 (English, six labeled axes) and test v5 (multilingual, two labeled axes).
| Axis | OOD AUROC · test v4 (EN) | OOD AUROC · test v5 (ML) |
|---|---|---|
| Context-injection · RAG-firewall | 0.9405 | — |
| Prompt safety | 0.9204 | 0.9892 |
| Answer safety | 0.9174 | — |
| Hallucination-on-context | 0.8671 | — |
| Jailbreak | 0.8623 | 0.8426 |
| Closed-book hallucination (advisory) | 0.769 | — |
| MACRO | 0.8795 (6 axes) | 0.9159 (2 axes) |
How these numbers are measured. Every AUROC here is computed on entire datasets held out from training — not rows set aside, but sources the model never saw in any form. Cross-referencing this checkpoint's training-era corpus against the two test sets' sources yields 0 shared sources out of 18 for the English test and 0 out of 26 for the multilingual one. In-distribution numbers, which most LLM-safety vendors publish, systematically reward memorization — our numbers are lower, and that's exactly the point.
Three axes — profanity, out-of-scope, prompt-complexity — run in the same forward pass but are covered by neither test set yet, so they ship in annotate-only mode until an operator promotes them.
Checkpoint gladg_v3_psjbft_ep0, corpora corpus_ood_test_v4 / corpus_ood_test_v5_ml. Closed-book is shipped as advisory: it raises a high-confidence flag for human review on confidently-incorrect answers, not a hard block. Full per-axis breakdown, latency, and methodology on the G-1 product page.
The same real-time trust layer now covers agentic tool-calls, live web search, three new detection axes, and a threshold simulator to move the safety line — and gets harder to fool the more it is used.
Inspects the full Model Context Protocol lifecycle — tool discovery, calls, results, resources — with allow / warn / block verdicts. Stops tool poisoning, indirect injection and data exfiltration.
Optional 8B-class safety judge for maximum depth, reading internal states across the safety axes.
Closed-book truthfulness recalibrated per served model, with a conformal false-positive guarantee and hot-reload.
Three horizons, one loop, under human supervision: an immediate Policy Lens threshold, a fast episodic-memory correction, a structural gated retraining — incidents are memorised, not trained on, until a human decides. How it works →
Every fetched page screened before it can ground an answer — injection blocked, safe pages read.
A dedicated crisis / self-harm detector — including euphemisms and short queries.
Profanity, out-of-scope, prompt-complexity — same forward pass, annotate-only until an operator promotes them.
out_of_scope rejects before the upstream call; prompt_complexity routes cheap vs. capable models — a guardrail that saves tokens instead of spending them.
A counterfactual threshold simulator over your own logged requests, validated against your reviewers' corrections.
The trust layer in detail: architecture, Constitutional Intelligence, the compliance platform, benchmarks, and how it deploys inside your perimeter.
Three research pillars, peer-reviewed work (MuPAX, EVIDENCE, NSP), and what comes after G-1: GLAD-Manifold, our physical, geometric world model.
The full technical whitepaper for compliance officers, Chief Risk Officers, and AI leadership. Architecture, compliance, three enterprise use cases.