xenoglyph

From pixels to purpose.

Detection tells you something is there. It does not tell you what it means, how sure the machine is, or what the reading rests on. xenoglyph is the layer that answers those questions — and refuses to answer when it cannot.

The ultimate instrument.
Two USPTO provisionals · priority March 2026
Open preprint of record · Zenodo DOI
Delaware C-corp · patent-pending
Start here

The short version — for the memo.

If you are forwarding this upward, this paragraph is written to be pasted.

xenoglyph is an exploitation layer for imagery: it bolts onto existing infrastructure and returns a defensible reading — a measured profile against dimensions a human authored, with the evidence and model provenance attached, and an explicit record of when it could not explain itself. Two products ship privately today (visual intelligence for analysis teams; edge inference on paperback-sized hardware). Two USPTO provisionals, priority March 2026. Output is emitted against published NATO and OGC standards, so a conformant consumer needs no bespoke parser. Pre-revenue: no customer, no third-party evaluation, and none claimed. Delaware C-corp. Contact: hello@xenoglyph.ai
Stage
Pre-revenue. 2 of 8 torches shipping privately.
IP
USPTO 64/129,348 · 64/231,134
Priority March 2026.
Published record
Zenodo preprint of record
10.5281/zenodo.19560958
Standards
STANAG 4774/4778 · 4559
MIL-STD-2525D/E · OGC API
Deployment
Air-gapped and on-premises. Data and weights need not leave the customer boundary. FIPS / NIST 800-53 / GovCloud postures are a deployment target, not an accreditation we hold.
Founder
Jacob Lyons, CEO
LinkedIn · X
Next step
hello@xenoglyph.ai
Demo and technical detail on request.
The position

Legible AI.

Most explainable AI is written after the fact: a black box decides, and a second system reconstructs a story about why. That story can be wrong about its own model, and it usually cannot be wrong out loud.

We invert it. The dimensions an operator wants read are authored by a human before the reading happens — in their own words, for their own domain. The engine measures against those axes and returns a profile, not a label. Legibility is not recovered afterwards; it is the input.

Human-authored axes

You wrote the vocabulary.

The instrument has no opinion of its own to explain. It reports how strongly an image reads against dimensions a person defined and can revise.

A profile, not a verdict

The analyst decides.

The output is a measured profile with the evidence attached. The judgement stays with the person accountable for it.

Measured illegibility

It reports when it cannot explain.

Where the reading has no backing evidence, the record says so, and the dossier computes the rate at which that happens. No deployment has produced that rate yet — so today this is a mechanism, not a measurement.

Provenance

Checkable without an NDA.

Method — engine

USPTO 64/129,348

Provisional patent application, confirmation 8323. Priority filed March 2026, Alexandria VA.

Method — multi-domain

USPTO 64/231,134

Companion profiling method, confirmation 9747. Filed April 2026, Alexandria VA.

Published record

Zenodo preprint

Visual semantic analysis of an unread manuscript, with an openly licensed dataset sibling.
10.5281/zenodo.19560958
10.5281/zenodo.19560769

The product

What every reading carries, and what it does not.

Ships with every reading

  • A confidence scorea ranking score, carried verbatim. Our code ships the note: “confidence is imago’s ranking score, NOT a probability.” No calibration is claimed, because none has been measured.
  • Model provenancemodel id, version and weights hash. Required, and never fabricated.
  • Supporting evidencea reference to the observation behind the conclusion, so a reviewer can disagree with it.
  • Saliency — the “why”the read that explains the detection — or, honestly, no backing map. The dossier computes an abstention rate from it. No deployment has produced one yet, so this is a mechanism, not a measurement.
  • Symbology and markinga standard symbol and a classification label, tamper-evidently bound to the record. Both self-declare aspirational: a curated symbol subset, and binding that detects modification rather than establishing non-repudiation — under the shipped default key, public in our source, a binding is forgeable.

Live limits

  • The encoder reads a fixed window.It takes 77 tokens and truncates silently. We measured, found every shipping dimension over it, and repaired it — axes are now encoded as ensembles, so nothing is dropped to fit. Re-measured: 0 of 5,209 encoded texts are over it. Three dimensions name a judgement rather than a percept and are unscoreable at any length; a low score there is not evidence of absence.
  • No customer, no revenue, no third-party evaluation.None is claimed anywhere on this page.
  • No production integration.Conformance is measured on our side, by our own suite. Nobody has ingested this output in the field.
  • Out-of-sample gating is not evidenced.The only held-out artifact is a fixture naming a file that does not exist. We removed the claim rather than let a mock stand in for held-out ground.
  • No abstention rate has been measured.The dossier computes one per deployment; no deployment has run.
  • Confidence is not calibrated.A ranking score. No reliability curve has been measured, so none is claimed.
  • Symbology and label-binding self-declare aspirational.A curated symbol subset; integrity rather than non-repudiation until the operator supplies a key.
  • Two torches are shipping privately; six are not.MANTIS and APTERA. The engine is not a torch and is not counted as one — the same word our own data file uses.

And these are platform behaviours, evidenced per deployment in the deployment dossier — a per-deployment evidence pack with a named section for each, rather than fields on a row:

The second group costs the most to build and is the reason the first can be trusted. Anyone can ship a faster answer. The scarce thing is a defensible one — and a system that says I cannot tell out loud.

Interoperability

A bolt-on, not a rip-and-replace.

Programs already own the collection, the geometry, the workstation and the dissemination backbone. Replacing any of that is a decade-long fight nobody wants. xenoglyph bolts onto what is already there and fills the gap that keeps recurring across every one of those stacks: a per-detection record an analyst — and an accreditor — can actually defend.

What we are not

A collection system.

No sensors to buy, no platform to displace, no workstation to retrain onto. The instrument reads imagery that already exists in a program of record.

What we are

An exploitation layer.

One canonical, schema-validated output contract and thin adapters to the host, emitted against published specifications rather than a private format.

The value

Speaks the formats the host already speaks.

Output is emitted against open, published standards so a conformant consumer needs no bespoke parser — and can replace us later without a migration.

STANAG 4774 / 4778 — confidentiality labels, bound STANAG 4559 (NSILI) MIL-STD-2525D/E APP-6C/D OGC API — Features GeoJSON GeoPackage MGRS · UTM · DMS

The limit, stated here rather than on request: conformance is measured on OUR side — a versioned schema and a conformance suite against the published specifications. No third party has ingested this output in production. The emitters are tested; the integration is not yet evidence.

Deployable air-gapped and on-premises: the instrument does not require that data or weights leave the customer's boundary. Model upload and model validation inside that boundary are not built — the registry is in-process only today.

The platform

One engine. A family of torches.

The engine is a configurable instrument: an operator authors the vocabulary for their domain, and the engine returns a profile rather than a label. Each torch is that engine pointed at a domain — with the honest status of each stated plainly.

NameDomainStatus
xenoglyph The engine — reads meaning from images, not objects Shipping · private
MANTISVisual intelligence for teams who must act on what they seeShipping · private
APTERAEdge inference on hardware the size of a paperback — MobileCLIP + ONNX runtime, no acceleratorShipping · private
LumenDocument and manuscript analysisPreprint of record
pyroglyphWildfire intelligence — what a fire is doing, not just that it burnsPublic preview
PROGLYPHAdversarial self-review protocol for the instrument's own findingsIn development
NymphWearable interface — the profile at a glanceIn development
field-sightField and naturalist vertical — read the sign, not just the sceneIn development
aletheiaAirspace and formation analysisIn development

The edge family follows a wing-naming roadmap from APTERA outward. The fire is not for sale. The torches are.

Why trust it

The retirement record.

An early aerial-imagery capability conflated modern attributed earthworks with ancient ones. The claim was withdrawn, the page carrying it disabled, the capability demoted. Two research findings were withdrawn before publication the same way, on our own initiative, after our own review refuted them. The retirement registries live in the private product repositories and are available under NDA.

A system that has never publicly retired anything has either never been wrong or has never checked. We would rather you learn our limits here than find them yourself.