Skip to content Skip to content

For grantmakers and technical funders

What a grant to Palimpsest pays for

Palimpsest measures censorship. It watches what governments and their AI models quietly remove from the public record, publishes each measurement as an open JSON file within hours of taking it, and seals its own record so that nobody, including the person who runs it, can revise a published number afterwards. It is MIT licensed and fully open source. It has no sponsor, no paywall and no advertising, and it never monetizes the people or the topics it observes. Everything below is that same claim broken into parts, each one sitting directly above the file you can check it against.

Open a funding conversation Read the source Browse the live readings

not loaded

sealed attestations in the eval registry, each one a frozen probe set and a named model, chained to the entry before it

chain state: not loaded

measured: not loaded

eval-registry-latest.json · the chain itself

not loaded

entries in the sealed erasure ledger, a second and separate hash chain covering the censorship observations

chain state: not loaded

measured: not loaded

erasure-observatory-latest.json · the ledger itself

not loaded

one step forecasts scored against what actually happened next, including every one the published band got wrong

coverage: not loaded

measured: not loaded

forecast-ledger-latest.json · history

01 · What this is

One instrument, pointed at two places the record gets rewritten

Stated without jargon, in one paragraph, because a funder should not need the vocabulary of the field to decide whether this matters.

When a government censors, the evidence is an absence: a post that was there yesterday and is gone today, a website that stops resolving, an answer a chatbot used to give and now will not. Absences are hard to cite, which is why censorship is so often reported as anecdote. Palimpsest turns those absences into measurements. It archives public material first, watches for what disappears, probes AI models with the same frozen set of questions week after week to see what they quietly stop answering, and publishes each reading as a dated, openly licensed file with the raw evidence attached. Because a record of erasure is itself worth erasing, every entry is hashed into an append only chain whose root is stamped outside this project, so a reader can prove offline that nothing published was later edited.

  • The censorship observatory Deletion, blocking and rewriting measured as data across the network layer, the model layer and the narrative layer, refreshing on its own schedule without a human in the loop. Live observatory, erasure observatory, the brief.
  • The verifiable eval registry AI evaluations sealed at publication. The questions are frozen and hash committed before any model is queried, so a suite cannot be quietly reshaped to flatter a result, and Chinese state aligned models and Western frontier models are held to the same machinery. Two frozen suites run with no model in common. The registry, the Generative Firewall Index.
  • Both are free to everyone, forever Every reading is a public file. There is no gated tier, no dataset held back, no commercial version. Data and method for researchers, every dataset published.

02 · Is it real

It is running right now, and you can check it without asking us

The strongest thing this project can offer a funder is not a description of itself. It is a set of files that were written by machines on a schedule, that carry their own timestamps, and that fail verification if anyone touches them.

The numbers in this column are fetched from those files as you read. If a fetch fails, the card says so in red instead of showing a figure.

The sealed record

not loaded

attestations in the eval chain, of which not loaded are sealed model runs and not loaded are pre registrations committing a probe set before the model saw it.

chain verified
not loaded
models covered
not loaded
merkle root
not loaded
head hash
not loaded
first entry
not loaded
verify offline
not loaded

measured: not loaded

The external anchor

A chain you keep to yourself proves nothing. Both roots are stamped outside this project, so the publication date of a root is attested by something that has no interest in Palimpsest being right.

OpenTimestamps
not loaded
Internet Archive
not loaded
registry root
not loaded
erasure root
not loaded
reconciliation
not loaded

stamped: not loaded

anchors-latest.json · every stamp ever taken

  • The code is the whole project Collectors, processors, verifiers, tests and the site itself are in one public repository under MIT. github.com/beepboop2025/palimpsest.
  • The signals refresh unattended Each signal is a scheduled workflow that writes a dated file, and its run history is public. Every scheduled run.
  • There is a test suite, and it is the honest kind Alongside the ordinary unit tests are tests that exist to stop the project fooling itself, for example that a transport failure is never recorded as a takedown, that an empty corpus makes the index abstain rather than print a zero, and that the published cadence matches the actual cron. The tests.
  • Anyone can verify the chains offline Two commands, standard library only, no key and no server. Change one sealed byte and the verifier names the break. How the sealing works.

03 · Is it a public good

Free, open, unsponsored, and structurally unable to sell you out

Public good is a claim about structure, not intention, so each line here points at the thing that makes it true rather than at a promise.

  • MIT licensed, in full Code and data both. Anyone may run it, fork it, or replace the maintainer entirely. LICENSE.
  • No paywall and no gated tier Every reading on this site is a plain JSON file served to anyone who asks, with a history file beside it. There is no premium dataset and no embargo window. The readings index.
  • No sponsor and no advertising Nothing on this site is placed. Individual support is voluntary, taken in crypto, with no donor list kept. The individual support page.
  • It never monetizes the people it observes The subject of measurement is the act of suppression. There is no product built on the speakers, no profile of any individual, and no data sold about anyone. SAFETY.md.
  • Built to be cited and replicated, not depended on Method notes, a codebook and a citation file are published so the work survives this maintainer. Methodology, how to cite.

Individual donors have their own page and it stays deliberately separate from this one. If you are giving personally rather than institutionally, start there. Funding of either kind pays for measurement infrastructure only.

04 · Is it rigorous

It keeps a public score of its own forecasts, misses included

Any observatory can publish a number. The question that separates an instrument from a dashboard is whether it says how wrong it expects to be, and then reports back when it was wrong.

Palimpsest scores every signal prequentially: each reading is forecast from only its own past, never refitted with hindsight, and scored by a proper rule against a fixed quantile baseline. The misses are published in full, because a forecast record with the misses removed is worth nothing.

Calibration of the published bands

not loaded

of readings fell inside the 80 percent band, over not loaded one step forecasts across not loaded signals. A band that is honest should land near its nominal rate, not above it.

not loaded

measured: not loaded

forecast-ledger-latest.json

Per signal, including where the adaptive band lost to the baseline

Signal Forecasts Coverage Nominal Misses Beats baseline
not loaded

not loaded

The worst miss on each signal

This table is the point of the section. These are the readings the published interval failed to contain, taken straight from the ledger with nothing removed. Values are in each signal's own units and do not compare across rows.

Signal Step Forecast 80% band Actual Missed by
not loaded

not loaded

not loaded

not loaded

When methods disagree, the interval is the answer

not loaded

not loaded

not loaded

OONI
not loaded
Censored Planet
not loaded
agreement
not loaded
weighted midpoint
not loaded

not loaded

measured: not loaded

vantage-fusion-latest.json

  • The scoring method is one a reviewer can attack Strictly prequential forecasts, adaptive conformal bands valid under distribution shift, scored by the Weighted Interval Score against a fixed quantile baseline. The point forecast is a random walk on purpose, because the claim being tested is calibration and not sharpness. The scorer.
  • Movement is checked against its own measurement coverage Before a signal is allowed to look like news, it is tested against the possibility that only the sample size moved. A verdict that does not survive that conditioning is published as coverage confounded rather than as a finding. coverage-guard-latest.json.
  • The detection method is retrodicted against documented events The censor attention scorer is run unmodified over six documented censorship events from 2020 to 2023, reconstructed from public documentation, and the top ranked term is the event's own term in all six, never a high volume background term. What is not validated by that exercise is stated in the same document. docs/VALIDATION.md.
  • The human coding study is published as unfinished The sampler, the codebook and the frozen blind sheet for the generative firewall labels are in the repository, drawn with a disclosed seed and with the shortfalls in the rare cells recorded rather than hidden. The answer key is deliberately withheld until both coders finish, because it carries the machine label for every row; its digest is published now, so the key released afterwards is checkable against a commitment that predates the labels, and CI recomputes the seal on the published sheet every run. The two coder pass has not been run, so no inter rater agreement figure is published and none is claimed. Funding that study is one of the things this page is asking for. The frozen study, the codebook, the agreement script that is waiting on coders.

05 · Is it safe

Watch the censor, never the censored

Censorship measurement has a history of getting people detained. The safety rules here are architectural, written into how collection works rather than added as a policy page, and they are the reason several otherwise useful capabilities do not exist in this codebase.

  • Public reads only Palimpsest looks at material that was already published in public, and at the fact that it later disappeared. It never deanonymizes a contributor and never profiles an individual.
  • Nobody inside the censoring jurisdiction is ever asked to act The system observes from outside. It places no person in country at risk to gather a data point. Where a vantage inside a censored network is used, it is volunteer hosted infrastructure of an existing measurement platform, and that constraint is surfaced on the reading rather than buried.
  • The subject is the state, not the speaker The unit of analysis is the act of suppression. The gazetteer identifies the vocabulary of censorship, not any person.
  • No state aligned model is ever the analyst The classifier patterns and the sensitive terms list are authored directly and are never delegated to a model aligned with the government being measured, because such a model quietly omits the most sensitive terms. That asymmetry is designed around on purpose. State aligned models are objects of measurement here, never instruments of it.
  • A deletion is never claimed lightly The detector probes a known live control post first each cycle. If the network looks unreliable the whole cycle is marked degraded and every deletion write is suppressed, so a flaky connection can never be recorded as censorship.
  • Offensive capability is out of scope, not backlogged Requests to add intrusion or deanonymization are declined as out of scope rather than triaged as features.

The rules above are published, versioned and enforceable against the code:

SAFETY.md · docs/ETHICS.md · SECURITY.md · docs/OSINT_SOURCES.md

Source safety overrides every other consideration, including completeness of measurement. If any part of this project could endanger a person, the private reporting route in SECURITY.md is the right channel and it reaches the maintainer with no public trace.

06 · What money buys

Four cost categories, each attached to a gap you can see on this page

Funding here buys measurement capacity and nothing else. Each category below names the specific limitation in the current published record that more of it removes.

No budget figures are published on this page. Ask through the repository and a current cost breakdown against these four categories will be prepared for you.

01 · Vantage points, the single largest running cost

Censorship is vantage dependent. Two independent methods can legitimately disagree because of routing, partial deployment or probe location, and when they do, the honest published answer is a range rather than a midpoint. Egress and vantage infrastructure is what narrows that range, and it is the largest recurring line in running this project.

The gap, live and unretouched:

not loaded

vantage-fusion-latest.json

02 · Archival storage and external anchoring

Deletion is only measurable if the original was captured first, so the archive grows every cycle and nothing is ever removed from it. Anchoring costs sit here too: each root has to be stamped outside this project for the seal to mean anything to a stranger.

The gap, live and unretouched:

not loaded

anchors-latest.json · the sealed ledger

03 · Model probe budget

The eval registry pays per query. Every sealed run is a frozen probe set put to a named model, and the value of the series comes from repeating it on a schedule for long enough that drift becomes visible. More budget means more models, more languages, and a denser series rather than a sparser one.

The gap, live and unretouched:

not loaded

eval-registry-latest.json

04 · Human validation studies

Machine labels are not evidence until humans have checked them. The sampling frame and codebook for the generative firewall labels are already written and published; the answer key is withheld until coding finishes, with its digest published so the eventual release is checkable against a commitment that predates the labels. What is missing is paid coder time, which is the difference between a plausible index and a validated one, and the reason no agreement figure appears anywhere on this site.

The gap, stated plainly: two independent coders have not yet worked the published sheets, so inter rater agreement is unmeasured and every model derived label on this site should be read as unvalidated until it is.

validation/CODEBOOK.md

07 · Contact

How to start a conversation

The repository is the front door, because it is the one route a stranger can verify reaches the person who actually maintains the project.

  • Funders and institutions Open an issue on the repository saying what you need to see. Diligence material, a cost breakdown against the four categories above, or a walkthrough of the verification path can all be prepared on request. github.com/beepboop2025/palimpsest/issues.
  • Anything touching a person's safety Use the private reporting route in SECURITY.md rather than a public issue. It reaches the maintainer with no public trace. SECURITY.md.
  • Individuals who want to give The individual support page takes contributions in crypto, keeps no donor list, and is deliberately separate from institutional funding. Support page.
  • Help that is not money Cite the data in research and journalism, replicate a reading and say where it disagreed, or volunteer as a coder for the validation study. Coders are the single most useful non financial contribution right now. For researchers, contributing.

This page names no institution, no team size and no funding total, because none of those are things a reader could check. What is checkable is on the page, and what is not has been left off it.

Palimpsest is MIT licensed and developed in the open as a public good. It watches the censor, never the censored. Every finding ships its raw evidence.
Home · Readings · For researchers · Individual support · Source