Cura Mirai
A companion app for children with a quiet signal for the parent, built on a deterministic governance kernel that holds the safety decisions outside the model. In early access.
Duration
Ongoing
Team
1
Scale
Product
Scope
Global

Overview
Cura Mirai is a companion app for children, with a quiet signal for their parent. A child talks to Mira on their own phone or tablet, in their own language. A safety engine reads every message for genuine signs of harm, and when something matters the parent gets a short alert in plain words. No transcripts, no dashboards, no diagnoses, no keyword feed. The parent stays the parent.
Underneath the app is a governance kernel that decides what the product is allowed to do. It is deliberately not a model.
Why it exists
Haven, the LGBTQIA+ youth companion elsewhere in this portfolio, ran into a wall. The underlying model's terms of service prevented proper crisis escalation for minors, so when a young person expressed harmful intent the system went along with it rather than acting.
That is not a prompt problem. A guardrail living inside a model can be argued with by anyone patient enough, and it disappears entirely the moment the model is slow, rate-limited or down. Cura Mirai is the response: a layer that sits outside the model, holds the safety decisions itself, and keeps working when the model does not.
The kernel
The kernel is code, not AI. Deterministic, auditable and model-agnostic by construction. It runs on FastAPI and Pydantic with no vendor SDK, speaking raw HTTPS, so it stays portable across providers rather than inheriting whichever one it was written against.
Its modules separate along the decisions being made rather than along the data: a signal detector with pluggable strategies, an accumulator that holds history so a pattern is distinguishable from a single bad evening, a policy registry and a policy evaluator, an escalation state machine built as a one-way ratchet with irreversibility floors, a consent enforcer, a hash-chained audit logger, a jurisdiction resolver, and a commissioner that asks the model bounded questions and nothing more.
Two properties matter more than the module list. Governance state is hidden from the model, because a safety control that can be talked out of its decision is not a control. And any model failure resolves to maximum safety rather than to silence, because a detector that fails by returning nothing looks exactly like a child who said nothing worrying.
Taxonomy and ontology
Every safety behaviour is defined by a versioned policy pack rather than by code, and the two halves of that do different jobs.
The taxonomy names what can happen. It runs across three axes, because the mitigations differ: the child's own indicators, harm directed at them by others, and risk in the system's own output, since a product that can cause harm has to appear in its own taxonomy. It currently holds 423 sub-signals across 24 domains, each marked for whether it is even detectable in a chat at all. Thirty-eight are marked no, meaning structurally invisible to us rather than merely unbuilt, because they live on a channel the product does not touch.
The ontology declares what follows. A pack carries a jurisdiction path, an authority tier, an instrument type, a pedigree, age bands, what it inherits, a clarification protocol and its crisis resources. Its indicators each bind to a taxonomy row and carry their own authority, source citation, false-positive guardrail and severity. Its rules carry a condition, the action triggered and their detector dependencies.
So the join is explicit. The taxonomy supplies the nouns and the ontology says what each noun means here, on whose authority, for which ages, under which jurisdiction, and what it licenses the system to do. Eight packs are active, holding 24 indicators across 7 signal categories, derived from the CDC, the AAP, the 988 Suicide and Crisis Lifeline, NIMH, the FBI, NCMEC, Thorn, the WHO and Childhelp. Adding a jurisdiction is a file. Adding an authority is a field. Neither is a release.
The matching phrases themselves are deliberately never published. They are the one part of the system where disclosure would directly reduce a child's safety, because the reader most motivated to study them is a child who does not want an adult told.
What it measurably does
The architecture documentation is public, and it is generated from the packs, the taxonomy, the test suite and a live scoring run rather than written by hand.
Run against a labelled corpus with the language model switched off, the deterministic layer produces zero false positives across 47 benign messages, and catches 16 of 16 acute-concern messages in a category that a rule actually consumes. That last clause is the one that matters. A signal no rule listens for is raised and silently discarded, and that failure was real here: a child disclosing physical abuse at home was detected and dropped for months because the detector emitted a category no pack consumed. It is now an enforced invariant, tested on every run.
Zero false positives is the binding constraint rather than the headline. A parent alarmed about homework stops reading alerts, and an alert nobody reads protects nobody.
What is honestly still open
The published evidence states its own limits, because a safety system that cannot be inspected is asking for trust it has not earned.
The pedigree on every pack reads extracted rather than authored, meaning encoded from public guidance rather than written by a clinician. The test corpus is 82 messages written by the same person who wrote the system, which is weak evidence by construction, and widening it with messages from outside is an open item. Pattern-level detection catches 2 of 19, because those signals are designed to accumulate over time and a one-shot corpus understates them. One routing question sits with counsel: what the account holder sees when the child's disclosure implicates the account holder.
Status
The app, the kernel, the packs and the architecture documentation are built, and the product is opening to a small group of families first at published per-child pricing. The kernel is designed to wrap any model, and the child safety application is the first thing it governs rather than the only thing it could.
Project Artifacts
Project Details
Industry
AI Governance
Duration
Ongoing
Team Size
1
Direct Reports
0
Scale
Product
Scope
Global
Budget
Undisclosed
Platforms
Responsive web today, native apps in progress
Regulatory
Standard
Engagement
Architecture, research and product build
