Governed sandboxes
Run isolated, ephemeral scenarios against mocked resources, never production. An unmocked request returns a deterministic miss instead of reaching a real store, network or secret.
For education & research
AI is already everywhere on campus while acceptable-use policy and governance lag behind (EDUCAUSE, 2025). Olivares AI is an open, self-hostable platform a student, lab, or whole institution can run for free — on your own infrastructure, with the data staying on campus.
Ground truth for enterprise AI.
Community · AGPL-3.0
This is the complete Community product for up to 3 users, not a campus-only edition. Run it on infrastructure you control and learn from the same governance loop you would operate in an institution.
For students & individual learners
Build an access map that distinguishes read from read/write, put policy in the execution path, and inspect an auditable ledger of decisions. The system is read-first and its actuation is deliberately narrow, so you can learn both what governance can prove and where its boundaries are.
Olivares AI is beta / pre-1.0. At the first public release, Community support will run through the public repository and GitHub Discussions; issues, reasoning and implementation will stay inspectable.
For educators
Deny-closed policy can stop disallowed campus access and the ledger can attribute who did what across shared accounts. Attribution is firm only when a per-agent or per-session identity is propagated into the access. Otherwise the shared binding is surfaced as a governance finding, never a fabricated name.
Read the full campus enforcement and attribution storyFor researchers
Use the platform to operationalize your funder’s mandate and produce technical evidence. It does not certify NIH or NSF compliance.
Run isolated, ephemeral scenarios against mocked resources, never production. An unmocked request returns a deterministic miss instead of reaching a real store, network or secret.
Score against versioned golden suites. A run with no scorer is recorded as “skipped”, never a silent pass; raw outputs are not persisted, only a one-way hash and scrubbed label.
Keep NIH/NSF controlled-access data off public AI surfaces with two deny-closed gates: a classification clearance ladder and DLP egress. A shipped test loads the policy preset and proves both denials.
The controlled-access policy is grounded in NIH notice NOT-OD-25-081 . The policy pack is technical enforcement and operator evidence, not legal advice or a funder seal.
For the institution
Self-hosting changes the assessment: your institution runs the runtime, storage and network boundaries. Olivares AI publishes the mappings and guides a reviewer can inspect without claiming an assurance it does not hold.
Most hosting, datacenter, backup and vendor-staff-access rows are “not applicable — self-hosted”. The institution operates the runtime and verifies controls in its own deployment.
The compliance catalog includes a FERPA overlay for access, consent, disclosure records, minimization and transmission. It is a technical mapping, not a certification.
The open core consumes a signature-verified eduGAIN/InCommon aggregate and maps eduPerson attributes. This is standards interoperability, not partnership or endorsement by eduGAIN, InCommon or REFEDS.
HECVAT-4 and VPAT readiness guides are published. No SOC 2 or ISO certification is held yet; readiness is documented and certification work is engaged when a concrete institution requires it.
The honest boundary
A useful campus evaluation starts with what the product can prove today and where responsibility stays with the operator.
Free, on your own infrastructure. Start with the access map, then decide what to enforce and what evidence to keep.