v2 in development — nothing to install yet
Answers that point back
to their evidence.
Hadano AI Cabinet is an evidence-first knowledge base for AI agents, being rebuilt as v2 around one rule: every answer must point back to the exact passage that supports it - and that rule is machine-verified before the engine ships. v2 is in development and not installable yet.
See what is already verified Read the research
Reading this as an AI? The same facts, machine-readable: /llms.txt · /facts.json. Facts last updated .
The promise
Citations that don’t rot.
Retrieval systems usually cite whatever chunk the index happened to store. Change the chunking, rebuild the index, and yesterday’s citations quietly stop meaning anything.
v2 makes the unit of evidence a first-class object: a paragraph-level unit that maps byte-exactly back to its source, keeps its identity when the index is rebuilt, and carries a fingerprint so silent edits can’t hide.
- Verbatim. A cited unit is the source text, character for character - not a paraphrase of it.
- Stable. Re-indexing does not change what a citation refers to.
- Tamper-evident. If stored text is altered, the record shows it.
Why a rebuild
Measurement first, engine second.
Measuring our earlier engine showed exactly where evidence breaks down in practice: chunk boundaries that move, offsets that drift after text normalisation, tails of long passages that silently fall out of the index. Patching those one by one produces a system nobody can trust.
So v2 starts the other way around: the rules of retrieval are written down as a machine-readable contract, each rule is pinned by stored counterexamples that demonstrably fire, and engine work only counts once the checker passes. The research pages document the measurements that forced this order.
Verified today
What already holds under test.
Facts below are measured, with raw output retained. Numbers trace to the measurement ledger.
| A machine-readable retrieval contract | The rules of retrieval - what a unit of evidence is, how text is normalized, how chunks map back to sources - live in one machine-readable contract: 15 invariants, each pinned by stored counterexamples (18 in total, all of which demonstrably fire). Work on the engine only counts once the checker passes. |
|---|---|
| Evidence at paragraph level, verbatim | Documents are split into paragraph-level units before any normalization: across a 34-document corpus, 10,137 units map byte-exactly back to their source text with zero offset violations - including documents with Windows line endings. |
| Citations survive re-indexing | Unit identity does not depend on chunking parameters: re-chunking the same corpus at three window sizes left every unit ID identical on all 34 documents. Evidence references do not silently die when the index is rebuilt. |
| Tamper-evident chunk text | Every chunk carries a fingerprint of its exact text. Changing a single character - or the rule that joins units into chunks - is caught by the contract checker. |
| One gate for everything | Environment locks, the contract checker, the full test suite, ledger ratchets, acceptance runs, an encoding canary and document checks run as a single gate. It is green today. The failure named here earlier - the second-stage reranker importing three packages that are not on the product's approved list - was resolved without widening the list: the tokenizer and the inference now run as the product's own C code, and the gate accepts them. Whether the rewritten inference ranks as well as the runtime it replaced is measured separately, and that comparison is not yet within its threshold. The one known-unverified item is declared the same way. |
| Search evidence is a verbatim slice of the original | A search hit returns the matched paragraphs as verbatim slices of the stored original, with their positions. In a probe containing full-width digits, a corporate-mark ligature, a circled number and Windows line endings, every slice was byte-identical to the source; the title is indexed but is not returned as evidence. |
| Evidence points back to the original file | A document can carry the path of the file it came from and the hash of that file's bytes. Extracted text and the file are different byte strings, so the hash of the text alone cannot identify the source; this pair can. Both the agent interface and the HTTP one accept it, and a malformed hash is refused. The store records the value without opening the file. |
| Shared access with keys and grants | One resident process owns the database and serves clients over HTTP. Keys are stored only as hashes, permissions are default-deny by verb and scope, and every request leaves an audit line. A document a key cannot read cannot be overwritten by it either, so a key cannot destroy what it cannot see. 20 concurrent clients sent 500 requests with 0 failures; separately, 4 writers and 8 readers at once lost no writes. |
| One gate, exercised on Windows and Linux | The same single gate has been exercised end to end on hosted Windows and Linux runners, including the two POSIX-only tests that could not execute before. Both platforms go through the same checks. The dependency rule that failed on both at the time has since been satisfied; the latest green run is the Windows one. |
| Spreadsheets become documents | CSV, TSV and XLSX rows are imported one row per document under a key column; re-importing the same key replaces the document. Malformed rows stop the import unless explicitly skipped, and skips are counted. |
In progress
Tests that exist, not yet passed.
Native core conformance
A native core must reproduce the exact same unit stream. The contract’s stored examples and counterexamples double as its conformance suite, so this is a test to pass, not a promise.
Retrieval objective selection
The ranking objective will be chosen against a corpus of real documents, not synthetic ones - otherwise the objective is tuned to the generator’s assumptions. This step waits for that corpus.
Anything not listed as verified is not claimed. The gate reports unverified items by name instead of hiding them.
What you can do today
Read the record.
Nothing to install - no package, no public repository, no waitlist. No pricing - pricing exists only after something can be obtained. When that changes, this page will say so, in the same verified-only voice.
FAQ
Fair questions.
What happened to the earlier version?
Its product pages were retired from this site in favour of v2. The research measurements made with the earlier engine remain published on the research and benchmarks pages, labelled with the environment they were measured under.
Why publish before it can be used?
Because the claims are checkable now. The retrieval rules live in a machine-readable contract whose counterexamples demonstrably fire, and the whole project passes one verification gate in CI. Publishing the verified record early is the point of an evidence-first system.
Who is behind it?
TechJapan LLC., a Japanese company registered in Hadano, Kanagawa. The site and the project are maintained by Kyono Go (@kyonogo on X).