Before you continue...

CARLOS is an AI-enabled project, and all CARLOS software to date has been entirely produced using a combination of LLM-based coding products from Anthropic, OpenAI, and open-weight alternatives. Whilst CARLOS represents an approach to apply these products toward new standards of openness and release of corporate ownership of internet-based software and data, we realise that there are folks for whom use of these products is unacceptable. With that said, if folks will continue to use AI to produce software, our mission is to show that AI unlocks ways to produce better software for everyone.

One of the principles behind the project is full disclosure of AI use, and AI-written language, starting here.

Trust classes

Know what a host can see.

Pick a class up front. Declare what the host is left holding. Get placed where that's allowed. CARLOS doesn't choose your posture; it makes you say it out loud.

🤖 That's factor X for AI-slop lines you'll spot across this site.

The six classes

Ordered S ≤ A < B < C. The A variants are flavours of A, not grades.

S Stateless Holds no user data at all: a static file tree, or a binary with no persistent user state. There is nothing for a host to see. carlosframework.com · rastrillo.org · carloku.com
A1 Host-blind Keys live on the user's own devices; the instance never holds one that opens user content. The only residue is transport shape: who connects when, object sizes, timing. No content-derived identifiers at rest. Slopbox — padded fixed-size blobs, encrypted filenames
A2 Host-blind, declared residue Content sealed as in A1, plus an enumerated application-level residue that the app publishes in the open. An undeclared plaintext surface is a class violation regardless of intent, because the declaration is what makes the class auditable. Keymail — routing headers · Kass — log timestamps · Eleven — thread membership · Woodstar
A/pub Public by design A host-blind app whose plaintext surfaces are public on purpose, listed one by one. A box hosting public posts learns nothing a browser would not. Woodstar — public posts; blobs and direct messages stay sealed
B Sealed single-tenant Sealed everywhere it rests outside the live process: parked database, replica, blobs. The running instance holds a key in memory while awake, because unattended automation requires plaintext. A cold artifact leak yields nothing; a live-host compromise yields data. an internal finance ledger, one instance per team
C Host-sighted Plaintext at rest as a deliberate, recorded decision: support visibility, SQL over personal data, payments. Confidentiality rests on operator policy and tenant isolation rather than on mathematics, and stated plainly rather than implied quietly. Tito — the defining example

Placement follows the class

Nothing that sees gets placed where nobody is accountable for seeing.

Hosts rank by who controls the box. A workload runs only where the host is trusted enough for its class: C never lands on a shared pool; A can go anywhere, because there's nothing on it to see.

The class belongs to a workload, not a product. An E2EE app with an automation sidecar is two answers: the app is A, the sidecar is B, and each is placed on its own terms.

A declaration names the workload, its class, every plaintext surface, and where the keys live. Then the CARLOS test: publish the database and see what leaks. A leaks its declared residue and nothing more. B's cold copy leaks nothing. C leaks the data, and said so up front.

Examples show classes, not adoption. Nothing is certified against an external standard yet. What auditors get is a declaration they can test, not a paragraph they have to believe.

Licensing is the other axis

A trust class says what a host can see. A licence class says what a customer can do with the code. CARLOS doesn't dictate: you choose.

L1 Libre Free as in freedom and free of charge. Anyone may run, change and redistribute it. The operator earns from hosting or support, or not at all. amadan · the framework and this site
L2 Source-available, commercial You can read it and self-host it; commercial use or redistribution needs a licence from the author. Slopbox · Eleven as intended (its repository carries MPL-2.0 today)
L3 Open source, with a hosted offering Fully open, and the author also runs it for you. The hosted service is the product; the code is the guarantee you can leave. Oficina, as intended
L4 Closed source, hosted only The author runs it and does not ship the code. Ownership for the customer means their instance, their data and their trust class, not the software. a conventional SaaS moving onto CARLOS
L5 Closed source, hosted and on-prem The author ships a binary the customer may run on their own boxes under licence, and also hosts it. One codebase, every deployment mode. Like status-quo SaaS, but better. Tito · Jelly, in development

The two axes are independent. An L5 app can be class A; an L1 app can be class C. A gallery entry names both, or says which has not been published yet.

Remixability is the third

Trust says what a host can see. Licence says what a customer may do. Remixability says what an agent, or a person with a fork, can actually do today. Three flags, each yes or no.

R·fork Forkable The source is available and a fork that stays close to upstream keeps working with the shared glue: sign-on, the edge, hibernation, the trust class, push notifications, integrations. Drift far enough and you are on your own, which is fair. follows from the licence: L1 to L3 yes, L4 and L5 no
R·drive Agent-driveable The app opts actions in as typed tools, so an agent reaches the same handler a person does, through the same middleware, with a confirmation sentence on every write. The framework provides this; the app has to switch it on. the model supports it; no app has published tools yet
R·build Agent-rebuildable The app publishes a skill at its well-known URL, so an agent can fork it, change it and redeploy it without a person reading the code first. The framework publishes two skills; each app owes its own. the model supports it; no app has published a skill yet

All three are possible for every app in the family, because every app has the same shape. The gallery records which ones have done it, not which ones could.

See who declares what

Every app in the gallery carries its class, or admits it hasn't published one.