Skip to content

For education & research

Learn AI governance by running the real thing.

AI is already everywhere on campus while acceptable-use policy and governance lag behind (EDUCAUSE, 2025). Olivares AI is an open, self-hostable platform a student, lab, or whole institution can run for free — on your own infrastructure, with the data staying on campus.

Ground truth for enterprise AI.

Community · AGPL-3.0

What you run today, for free

This is the complete Community product for up to 3 users, not a campus-only edition. Run it on infrastructure you control and learn from the same governance loop you would operate in an institution.

  • Self-hosted with no phone-home and no vendor account required to try it. Your access map, policy and audit data stay in your environment.
  • Read the source, modify it and learn from it under AGPL-3.0. The connector SDK is Apache-2.0 for integrations you can reuse independently.
  • The secure-first documentation starts with a quickstart and a seed-demo path, so a learner can build a useful local estate before connecting real systems.
  • The free story is Community itself: the complete open product within its published user cap, with no separate campus commercial programme.

For students & individual learners

Study a real governance system, not a slide deck

Build an access map that distinguishes read from read/write, put policy in the execution path, and inspect an auditable ledger of decisions. The system is read-first and its actuation is deliberately narrow, so you can learn both what governance can prove and where its boundaries are.

Olivares AI is beta / pre-1.0. At the first public release, Community support will run through the public repository and GitHub Discussions; issues, reasoning and implementation will stay inspectable.

For educators

Turn acceptable-use policy into an enforceable decision

Deny-closed policy can stop disallowed campus access and the ledger can attribute who did what across shared accounts. Attribution is firm only when a per-agent or per-session identity is propagated into the access. Otherwise the shared binding is surfaced as a governance finding, never a fabricated name.

Read the full campus enforcement and attribution story

For researchers

Move quickly inside a governed boundary

Use the platform to operationalize your funder’s mandate and produce technical evidence. It does not certify NIH or NSF compliance.

Governed sandboxes

Run isolated, ephemeral scenarios against mocked resources, never production. An unmocked request returns a deterministic miss instead of reaching a real store, network or secret.

Reproducible evaluations

Score against versioned golden suites. A run with no scorer is recorded as “skipped”, never a silent pass; raw outputs are not persisted, only a one-way hash and scrubbed label.

Controlled-access data

Keep NIH/NSF controlled-access data off public AI surfaces with two deny-closed gates: a classification clearance ladder and DLP egress. A shipped test loads the policy preset and proves both denials.

The controlled-access policy is grounded in NIH notice NOT-OD-25-081 . The policy pack is technical enforcement and operator evidence, not legal advice or a funder seal.

For the institution

Procurement and compliance readiness, with evidence

Self-hosting changes the assessment: your institution runs the runtime, storage and network boundaries. Olivares AI publishes the mappings and guides a reviewer can inspect without claiming an assurance it does not hold.

A self-hosted HECVAT posture

Most hosting, datacenter, backup and vendor-staff-access rows are “not applicable — self-hosted”. The institution operates the runtime and verifies controls in its own deployment.

FERPA technical mapping

The compliance catalog includes a FERPA overlay for access, consent, disclosure records, minimization and transmission. It is a technical mapping, not a certification.

Campus identity interoperability

The open core consumes a signature-verified eduGAIN/InCommon aggregate and maps eduPerson attributes. This is standards interoperability, not partnership or endorsement by eduGAIN, InCommon or REFEDS.

Review guides, honest gaps

HECVAT-4 and VPAT readiness guides are published. No SOC 2 or ISO certification is held yet; readiness is documented and certification work is engaged when a concrete institution requires it.

The honest boundary

What this is — and isn’t

A useful campus evaluation starts with what the product can prove today and where responsibility stays with the operator.

Open & self-hostable
It is an open, self-hostable governance and observation layer for AI on your infrastructure. The control plane can run offline / air-gapped on your own hardware, so attribution and policy data never leave campus.
Read-first
It is read-first and deny-closed. It observes and governs broadly; it does not broadly actuate. Where it can take an action, that surface is live, on-demand, or a declared seam.
Release stage
It is pre-1.0. Actuation is deliberately narrow and mostly provision-gated; every surface is labelled as live, on-demand or a declared seam.
Air gap
It does not run your models, and it is not air-gapped inference. The air gap is the control plane. Only self-hosted models (vLLM, Ollama) run offline; hosted models like Claude do not.
Assurance
It is not a certification. FERPA, HECVAT, NIH, ISO and EU AI Act materials are readiness mappings and technical enforcement — not legal advice and not a seal.
Affiliation
Olivares AI is not affiliated with Internet2 NET+, is not listed in the programme, and displays no community-programme logos.

See what AI on your campus already touches

Free, on your own infrastructure. Start with the access map, then decide what to enforce and what evidence to keep.