Skip to content

KOTOBA CLOUD / WHITE HAT RESEARCH

Empower those who protect.

Bring our strengths together. Bring light back to the world.

Some notice the dangers others overlook.

Some look deeper into systems, determined to make them better.

Some use that knowledge to protect everyday lives.

kotoba.cloud supports the curiosity and creativity of white hats.

One person’s discovery becomes a community’s strength.

Together, that strength can change the world.

Investigate authorized code. Validate the finding. Ship the fix. Specialized LLM inference for verified white-hat researchers, with a free research allowance.

Preparing for launch — the selected model returned a real response on the dedicated deployment. Site inference remains closed until identity verification and review are connected.

01 / INVESTIGATE

Review the code

Inspect code you own or are authorized to review for authorization gaps and input validation issues.

02 / VALIDATE

Ground the finding

Work through reachability, impact and false positives to produce evidence-backed findings.

03 / REMEDIATE

Close the loop

Prepare fixes, regression tests and reports for responsible disclosure.

A model built for investigation

TEXT / VISION / MoE

Qwen3.8 Flash Next

A real response has been verified on the dedicated deployment. Scaling up from idle can take several minutes. Access remains gated while identity verification and review are connected.

qwen3.8-flash-next-whitehacker

Model card ↗

One verified identity. A free research workspace.

  1. Account

    Sign in with your existing account. A connected wallet alone is not verified identity.

  2. eKYC

    Identity verification runs on Stripe Identity only. Completing the document and selfie check at verify.stripe.com approves the account automatically (ekyc 365d, screening 24h, trust 60 points).

  3. AML / CTF

    Sanctions and PEP screening, risk review and additional checks where needed. Pending, expired or suspended records cannot infer.

  4. Free research

    Confirm authorization and research scope, then use the free allowance. Ongoing review keeps eligibility current.

$0 for verified researchers

Planned launch allowance: 50 requests per day, up to 2,048 output tokens per request. Usage stops at the limit. No automatic charges.

Preparing for launch — the selected model returned a real response on the dedicated deployment. Site inference remains closed until identity verification and review are connected.

Research terms & data notice

Do not enter identity documents, face images, private keys or API keys here. Before provider setup, application data is not sent or saved.

Research workspace

Research terms & data notice

For authorized code review, vulnerability triage and remediation. No unauthorized intrusion, credential theft, destructive activity or third-party research without permission. Identity verification does not grant research authorization.

First-party browser identity verification is in development. Documents, face images, names and birth dates will never be sent to the inference model. The service is designed to retain minimal verification status, expiry, evidence references, review and usage records. Verification intake remains closed until providers, retention periods, transfer destinations, deletion and appeal contacts are finalized and published.

PEP status or a possible name match is not automatically a finding of wrongdoing. Additional checks and human review are planned. Legal AML/CTF obligations depend on the operator and service jurisdictions.

Confirm the Stable Principal

Sign in to confirm the Stable Principal. That is the first finishable step. Hosted apply is not offered.

Finishable now: sign in, confirm the Stable Principal, then connect to the database.

Start with a Base Account

Three execution planes. Boundaries intact.

The services connect without becoming one giant trust domain. Each authority remains separately governed.

CONTROL + IDENTITY

Kotoba Cloud

Passkey verifies a Stable Principal. The control plane publishes the topology and authority floor used by CLI deploy.

auth.kotoba.cloud · api.kotoba.cloud

One release CID, executable from multiple providers

A release CID fixes the namespace head, definitions, raw Wasm, compile receipts, and reproducibility evidence in one IPLD graph. Names and GitHub remain discovery and provenance.

Bundle

Close definitions, Wasm artifacts, and compile receipts under one release CID.

Replicate

Store the same complete closure at no fewer than two independent storage origins.

Verify + Run

Verify every byte and routed peer IDs, then execute by release CID and export.

Shell
# install and run the live Ed25519 + ML-DSA-65 reference package
kotoba package add kotoba-lang/reference-math@0.1.0 --catalog-cid bafkreidcy5stqvnyfpmud6ozz5qz3supd3r3uzk7glmntuv36ezliaxstm
kotoba package run kotoba-lang/reference-math  # 42

kotoba library inspect <name|CID|#hash> --store .kotoba/codebase --namespace demo

# dry-run by default
kotoba library publish --store .kotoba/codebase --namespace demo --hosted

# replicate one exact release closure
kotoba library publish --store .kotoba/codebase --namespace demo --hosted --dry-run false \
  --pqc-seed-file <ml-dsa-seed> \
  --provider east=https://east.example --provider-token-file <east-token> \
  --provider west=https://west.example --provider-token-file <west-token>

# qualification and execution are release-CID addressed
kotoba library verify ipfs://<release-cid> --store .kotoba/codebase \
  --provider east=https://east.example --provider west=https://west.example
kotoba library run ipfs://<release-cid> --entry answer --store .kotoba/codebase \
  --provider east=https://east.example --provider west=https://west.example

# rotate or revoke the Principal-pinned ML-DSA key; both finish with Passkey
kotoba pq-key rotate --current-pqc-seed-file <current> \
  --next-pqc-seed-file <next> --expected-epoch 1
kotoba pq-key revoke --current-pqc-seed-file <current> --expected-epoch 2

Post-quantum signatures are mandatory, not optional. Publication requires both a Passkey session and an ML-DSA-65 signature pinned to the Principal. External authenticators and distributed qualification remain separately verified boundaries.

Open the library catalog and dependency graph

From AI-written code to admitted computation

Write

Agents and humans write freely in readable, data-oriented code.

Admit

Kotoba checks types, effects, capabilities, resources, and target support.

Bind

The host and provider bind Passkey identity and a resource-scoped grant.

Run

Kotoba Cloud Database keeps artifacts and receipts; Kotoba Cloud AI and Itonami perform admitted work.

Shell
kotoba research --scope <approved-scope> --task code-review
# requests are admitted by Kotoba Cloud before inference

Boundaries make connection possible.

Discovery is not delegation

kotoba.cloud makes each origin discoverable without merging storage, compute, and agent work into one trust domain. Receipts record every origin separately.

Existing auth.kotobase.net Passkeys do not migrate automatically. The new RP requires a verified Principal link.