Report a Security Issue | Dweve Trust Centre
Submit a security vulnerability through the recorded Trust route with affected surface, reproduction steps, impact, receipt, owner, and status tracking.
Documented|||Internally confirmed against a current Dweve record, implementation or owner-provided fact as of the displayed date; not a claim of independent audit or certification
Pre-release|||Built or prepared for the planned external release
Future event|||The method and evidence contract are current; the named real-world event has not yet occurred
Ask for missing information, report a concern, challenge a copyright decision, or tell us where a public record is unclear. The message enters the same recorded contact route.
Trust is not a promise|||it is built into the system
The public evidence behind Dweve Loom, its data route, operating boundaries and release controls. Documented means internally confirmed as of the displayed date; independent assurance is named separately when it exists.
Inspect the public record|||Open the Loom record
The commitment is public|||the evidence stays up to date
Dweve is a voluntary signatory to the EU General-Purpose AI Code of Practice and participates in the Signatory Taskforce. This dossier explains what that commitment means in Dweve's architecture and where the evidence is kept.
Read our position|||Inspect the change record
One model family|||one accountable record
Dweve Loom 1.0 is the only Dweve model. The registry separates its adaptive model identity, captured states, access routes and factual release state without treating Loom as one static hash.
Open the registry|||Read the Loom record
A model is one thread|||Loom is the weave
Loom is built around constraint learning and a typed execution graph. It combines perception, memory, retrieval, domain specialists, solvers, and verification. This record states what changes, what is sealed, and what can be replayed.
Read the architecture|||Inspect training content
Every source family is named|||every admission still has to prove itself
The register publishes 772 supplied training and knowledge-source entries across 19 groups. Each entry states its licence gate, usable slice, and purpose. Exact releases enter Loom 1.0 only after their rights, provenance, privacy, and evidence checks pass.
Inspect the source register|||Read the copyright policy
Training register|||772 sources · current
Collection starts with rules|||not with a fetch
Winnow checks source policy, robots.txt, rates, targets, and request records. Spindle governs provenance and promotion. Loom consumes governed material and can use Winnow as a tool.
Inspect the controls|||Contact the rights desk
Copyright control record|||Public channel open
The model record travels|||with the integration
Downstream teams need current capabilities, limits, interfaces, evaluation context, and changes. Dweve publishes the common record first and scopes private details only where necessary.
Inspect the package|||Request more information
Every release carries|||a verifiable origin
Dweve's release-bound policy covers Loom text and code output plus the image output Dweve ships. Loom does not generate video. C2PA Content Credentials carry the machine-readable provenance record, and route-specific validation runs before an external route opens.
Inspect the marking policy|||Report a model issue
Output transparency|||Release-bound controls
Capability needs authority|||before action
Dweve tools are built for legitimate, governed work. A technically possible action is not automatically permitted. Purpose, authority, evidence, human responsibility, and deployment policy remain part of the execution boundary.
Send the concern once|||we route the record
Copyright, downstream information, model safety, security, privacy, and model-quality concerns enter one recorded route. Choose the topic, preserve useful evidence, and receive a submission reference.
Choose a reporting route|||Return to the Trust Centre
No silent revisions|||no missing history
Material changes to the model record, source policy, public controls, and machine-readable files are listed here with their effect. Human and machine feeds carry the same version.
Read the current release|||Open the JSON record
GPAI Code signatory|||Dweve signed voluntarily and publishes the implementation path
Signatory Taskforce|||Dweve participates in the working forum for signatories
External access|||Invite-only external access is planned for 1 September 2026
Training source register|||772 supplied source entries are public; exact release admissions remain evidence-bound
Full voluntary scope|||Transparency, copyright, safety, and security measures are included
The hub is organised by the question a reader needs answered. Model identity is separate from training content. Copyright controls are separate from acceptable use. Each record exposes its own status.
How to read the status|||Public evidence map|||Ten records|||Missing fields stay visible
AI transparency|||Signatory position, voluntary scope, governance, and claim boundaries
Loom model record|||Architecture, modalities, state, replay, and operating data policy
Training content|||772 supplied source entries, deterministic admission, and release-specific evidence status
Copyright and crawling|||Winnow controls, rights route, and machine-readable policy
Downstream documentation|||The common integration and evaluation information package
Generated content|||Output scope, trace attachment, and marking controls
Acceptable use|||Purpose, authority, refusal, review, and appeal boundaries
Reporting desk|||One route for copyright, safety, security, privacy, and model concerns
Change record|||Version history in HTML, JSON, and Atom
Compliance cost|||Scope, period, inclusions, and exclusions for the compliance programme
From an outside source|||to an accountable output
Winnow acquires under a declared source policy. Spindle preserves provenance and decides what becomes governed knowledge. Loom uses that state and can call Winnow for current information.
Three control layers|||Source-to-output route|||Typed hand-offs|||No hidden scrape path
Access policy|||Robots, rates, target safety, and operator rules apply before collection
Provenance|||Source, address, time, status, and content identity stay attached
Runtime boundary|||Loom receives governed material or invokes Winnow through a tool boundary
Winnow|||Discovers, fetches, parses, and records according to source rules
Spindle|||Assesses provenance, evidence, quality, disagreement, and promotion
Loom|||Selects the relevant cognitive weave and records what it used
Output record|||The answer carries its trace, sources, state, and execution context
Loom is currently in internal-only testing. External invite-only access is planned for 1 September 2026 across individual and combined product routes. The public record makes the remaining release-readiness steps explicit.
Internal now|||Invite-only next|||Versioned after
Current posture|||Release status line|||Three states|||Dates are not hidden
Internal testing|||Dweve teams operate the current pre-release system internally
External invite-only|||Testers, partners, investors, and selected participants enter by invitation
Post-market record|||Usage, incidents, evaluations, and changes continue after access opens
Now|||Internal-only pre-release testing with public records being prepared
Before 1 September|||Complete the external-access controls and keep each admitted item bound to its controlled Spindle record
From 1 September|||Invite-only external operation with versioned monitoring and change publication
A public record needs|||a public way to challenge it
The reporting desk separates the subject while keeping one submission route. Sensitive material should be described first, not pasted into a public or general-purpose field.
Reporting posture|||Choose the right desk|||Recorded route|||One submission, clear owner
Public entry point|||Every route starts from the same accessible form
Submission record|||Successful delivery returns a reference from the contact system
Subject ownership|||The selected topic determines the internal owner and evidence request
Rightsholder request|||Raise a source, reservation, removal, or copyright concern
Downstream request|||Ask for integration, evaluation, capability, or limitation information
Model safety|||Report harmful behavior, unexpected capability, or a failed control
Security|||Report a vulnerability without exposing exploit details publicly
Voluntary participation|||without invented classification
Dweve records Loom as a general-purpose AI model under Article 3(63). The Commission's 10²³-FLOP criterion is indicative, not a safe harbour. No public designation of Loom as a GPAI model with systemic risk has been found as of 1 August 2026.
Signatory|||Taskforce|||Voluntary full scope
Status boundary|||Dweve public position|||Current record|||Precise, not overstated
Voluntary signatory|||Dweve has chosen the Code path before external release
Taskforce participant|||Dweve contributes through the official signatory working forum
No public designation found|||No public Commission record currently states that Loom has been designated as a GPAI model with systemic risk
Code implementation|||Public model, training, copyright, downstream, safety, and monitoring records