01
multikernel/sandlock
BUILDING · github + research + web
Founder Formation & Technical Diligence Engine
DAY ZERO turns public technical artifacts into a small queue of founder-introduction candidates, then pressure-tests what actually matters: it reproduces the technical claim against a real baseline, and reads the architecture closely enough to say what is genuinely hard and what is only implementation work.
Source
Verify
Diligence
Learn
Stage · Source
Three builders that survived evidence review and are worth spending relationship capital on. Not a ranking, not a top-N list — this is everything that cleared the bar, and the bar is not lowered to reach three.
01
BUILDING · github + research + web
02
FORMING · github + web
03
FORMING · github + web
Stage · Diligence
A Linux process sandbox that confines untrusted agent code with Landlock, seccomp-bpf and seccomp user notification — no root, no image, no hypervisor. Read at the level of its trust boundary, not its README.
Verdict
ADVANCE TO FOUNDER CONVERSATION
The interesting layer is not the sandbox. Traditional isolation answers can this process reach that resource. A prompt-injected agent asks a different question: should this legitimate agent use this legitimate credential for this legitimate operation, against this destination, right now? A VM boundary does not answer that. sandlock’s HTTP-level policy and supervisor-held credentials try to.
Full diligence — architecture, threat model, competitive alternativesStage · Verify
A published compression claim, tested against a pre-registered protocol on 35 samples the author did not choose. The protocol was committed before any measurement was taken.
Verdict
PARTIALLY REPRODUCED
Measured against pretty-printed input the saving looks large. Measured against trivial whitespace minification — which costs nothing and takes one line — most of it is still there, but not all: minification alone supplies 30.84% of the 46.30% headline. The compression is real, lossless, and narrower than the marketing.
Full reproduction — claims, baselines, distributions, failuresStage · Learn
Most sourcing projects publish the run that worked. This one publishes the run that did not, and keeps it published beside the repair.
v1 · frozen, then run
v1 ad0b7ae00630…
v2 · post-hoc exploratory
v2 435dfb8a568d…
Unseen cohort · out-of-sample
freeze 662392ab2e9e…
What the unseen test broke next
It cleared convergence using a content repo — SCSS, no licence. v2 verifies that evidence is independent; it does not require that the evidence is technically deep at the convergence stage. That is a real design weakness, and it was found by the very cohort meant to test the repair.
Method
Verify the sequence yourself
ad0b7ae00630f7948e7c4444440af7c20fed61169370e46e076cd8f575a3566cv2 rules frozen435dfb8a568d8f07124125b08566cc9ced48f4d17ef76064978905968287f434unseen cohort freeze commit662392ab2e9e2eeec6549e08b2819d65aa03d4d8