AI infrastructureBuilt for operator custody

Turn the intelligence you rent into capability you own.

Route model calls. Keep the consented record. Train on hardware you control. Retain the resulting model, with the policy and evidence to use it on your own terms.

The ownership loop

  1. 01
    RouteFrontier APIs + your own models
  2. 02
    LearnYour corpus, evals, and training
  3. 03
    KeepModel, policy, and run evidence

End-to-end loop in build. Read the current status ↗

Ownership has
an exit test.

Unplug from the frontier labs and reproduce a declared fraction of a real workload, at a declared quality bar, from the operator's own model, corpus, evals, and policy, with no Caletta service required. That fraction is the Sovereignty Ratio. It is reported for one task on named hardware, with the evaluator, cost, and held-out period attached. If the ratio does not rise, the rest is only better-instrumented dependency.

A custody domain is the set of machines the operator enrolls and controls: one laptop, a workstation, an on-prem cluster, or datacenter capacity under their administration. Apple silicon is the first measured substrate, not the architectural ceiling.

The Exchange Dial applies to each connection in both directions: what the operator sends, and what the operator accepts. Its named levels run from nothing, through metrics and weight updates, to derived signal and raw work. Weight updates are not treated as private by definition; adapters can leak training data, so each level needs its own evidence.

ownership loop · current status · claim ledger · all groundwork

From model call
to owned capability.

owned runtime

route · distill · train · keep control

Loop
llm-router mlx-mesh distillation

Learned routing and consented corpus capture in llm-router, followed by distillation and training inside the operator's custody domain. Routing and capture are built and publication pending. The first end-to-end test is code-review triage on a permission-clean corpus Caletta already owns.

Control

Policy, brokered credentials, routed egress, disposable Macs, native Mac control, and browser automation form the operator-owned boundary. A local screen for protected data in outbound traffic is in build; it is intended to flag possible mistakes, not certify compliance.

Substrate
apple pure Go single binaries local-first

cgo-free Apple bindings, static Go binaries, and clear trust boundaries.

Built, measured,
and still in progress.

Each project carries its own evidence and release status.

Explore the components.

Build on your own terms.

Let’s talk

groundwork · github.com/calettalabs · travis@tmc.dev