Skip to content
DAY ZERO

Founder Formation & Technical Diligence Engine

Find the builder before the round.
Test the hard claim before the meeting.

DAY ZERO turns public technical artifacts into a small queue of founder-introduction candidates, then pressure-tests what actually matters: it reproduces the technical claim against a real baseline, and reads the architecture closely enough to say what is genuinely hard and what is only implementation work.

It assigns no founder score, keeps no leaderboard, and has contacted nobody. When its own sourcing rules failed, the failure was published rather than patched over.

102
repositories in the universe
3
INTRO_READY_AWU
35
reproduction samples
9
unseen validation cases
  1. 01

    Source

    Public artifacts — repository, paper, domain — converge on a builder, and the evidence has to clear a gate.

  2. 02

    Verify

    The claim is reproduced against a real baseline: claim → baseline → experiment → result.

  3. 03

    Diligence

    The artifact is read at the level of its architecture and threat model, up to a founder conversation.

  4. 04

    Learn

    A rule that fails re-enters sourcing instead of being quietly patched.

Stage · Source

Current 3

Three builders that survived evidence review and are worth spending relationship capital on. Not a ranking, not a top-N list — this is everything that cleared the bar, and the bar is not lowered to reach three.

01

multikernel/sandlock

multikernel/sandlock — process-based AI agent sandbox for Linux, no container

BUILDING · github + research + web

02

sipyourdrink-ltd/bernstein

bernstein — deterministic orchestrator for CLI coding agents

FORMING · github + web

03

scanaislop/aislop

aislop — code-quality and security gate for AI-authored code

FORMING · github + web

3 INTRO_READY_AWU — the operating unit is one lead that survives review, not one profile processed. No introduction has been made. Full records

Stage · Diligence

Flagship: sandlock

A Linux process sandbox that confines untrusted agent code with Landlock, seccomp-bpf and seccomp user notification — no root, no image, no hypervisor. Read at the level of its trust boundary, not its README.

Verdict

ADVANCE TO FOUNDER CONVERSATION

No public institutional financing identified in the reviewed sources. Not found — and that is a statement about what is public, not a claim that the company is bootstrapped.
Landlock + seccomp
Isolation boundary
Shared host kernel
Kernel vulnerabilities
Excluded from threat model
Stated by the project itself
358
GitHub stars
Descriptive only — never a surfacing input

The interesting layer is not the sandbox. Traditional isolation answers can this process reach that resource. A prompt-injected agent asks a different question: should this legitimate agent use this legitimate credential for this legitimate operation, against this destination, right now? A VM boundary does not answer that. sandlock’s HTTP-level policy and supervisor-held credentials try to.

Full diligence — architecture, threat model, competitive alternatives

Stage · Verify

The baseline is part of the claim

A published compression claim, tested against a pre-registered protocol on 35 samples the author did not choose. The protocol was committed before any measurement was taken.

Verdict

PARTIALLY REPRODUCED

Three of five pre-registered claims supported, two not. Both halves matter.
46.30%
JSON vs raw
median
28.41%
JSON vs minified
the comparison that matters
0.00%
Coding context vs raw
every quantile
1.0000
Probe retention
0 transformation errors

Measured against pretty-printed input the saving looks large. Measured against trivial whitespace minification — which costs nothing and takes one line — most of it is still there, but not all: minification alone supplies 30.84% of the 46.30% headline. The compression is real, lossless, and narrower than the marketing.

Full reproduction — claims, baselines, distributions, failures

Stage · Learn

The system failed, then the rules changed

Most sourcing projects publish the run that worked. This one publishes the run that did not, and keeps it published beside the repair.

v1 · frozen, then run

Zero passes

0 PASS2 PARTIAL4 MISS4 UNKNOWN

The strongest true positive in the cohort failed on a rule built to stop false positives: all of its evidence lived on GitHub, and v1 counted that as one source.

v1 ad0b7ae00630

v2 · post-hoc exploratory

Independence redefined

2 PASS1 PARTIAL3 MISS4 UNKNOWN

Independence became evidence modalities and distinct events rather than distinct hostnames — while getting stricter on four of five axes. Same cohort, so this proves nothing on its own.

v2 435dfb8a568d

Unseen cohort · out-of-sample

Nine cases v2 never saw

2 PASS0 PARTIAL1 MISS6 UNKNOWN

Selected deterministically and committed before any evidence was retrieved. Out-of-sample with respect to rule design — not to venture performance, since every case is a known portfolio company.

freeze 662392ab2e9e

What the unseen test broke next

Perspective AI passed the v2 gate on a marketing repository

It cleared convergence using a content repo — SCSS, no licence. v2 verifies that evidence is independent; it does not require that the evidence is technically deep at the convergence stage. That is a real design weakness, and it was found by the very cohort meant to test the repair.

The rule was not changed after seeing the result. A depth requirement at the convergence gate is a candidate for a future v3 — and no v3 has been validated, so none is claimed.

Method

Six rules the system runs on

No global score

No founder score, no probability of founding, no leaderboard. Nine technical dimensions are assessed separately and never combined. The database schema has no score column, and a test enforces it.

Attention is not construction

Stars, forks and followers are recorded as description and are barred from every surfacing decision. The measured spread between attention and construction runs four orders of magnitude.

Evidence has a state

Observed, project claim, inferred, unknown, not found. A builder's own post is authoritative that they said something — never that it is true.

Freeze before you measure

Rules and cohorts are hashed and committed before the results they govern exist. The git history is the proof, not the prose.

Career stage is optional

Two thirds of builders cannot be classified as young builder or operator-founder without guessing, so they are left unclassified. The eligibility rules cannot read the field at all.

No inferred departures

Nobody is ever inferred to be leaving a job from silence, inactivity, a deleted post or a bio edit. Only an explicit public statement counts.

Verify the sequence yourself

v1 rules frozenad0b7ae00630f7948e7c4444440af7c20fed61169370e46e076cd8f575a3566cv2 rules frozen435dfb8a568d8f07124125b08566cc9ced48f4d17ef76064978905968287f434unseen cohort freeze commit662392ab2e9e2eeec6549e08b2819d65aa03d4d8

Each hash predates the result it governs, and the commit order shows it. See the full timeline