Chittu is our model family. Its weights are open.
Chittu is the model track behind pinmbo. Two research releases are open on Hugging Face today: a small guard model and a from-scratch story model, both trained on synthetic data with no real child data in them. Neither serves a child yet. pinmbo’s safety comes from deterministic guards around whichever model answers, and the open models are our work toward putting that safety inside the model.
# Guard model — standard transformers layout from transformers import AutoModelForCausalLM from transformers import AutoTokenizer repo = "Tulifo/chittu-guard-v0-4b" tok = AutoTokenizer.from_pretrained(repo) model = AutoModelForCausalLM.from_pretrained(repo)
# Story model — ships its own two-function loader. # nanochat's model code must be importable # (commit 92d63d4 or near; see the model card). import sys from huggingface_hub import snapshot_download repo = "Tulifo/chittu-story-v0-26m" repo_dir = snapshot_download(repo) sys.path.insert(0, repo_dir) # load.py is in repo_dir from load import load, story model, tok = load(repo_dir) prompt = "tell me a story about a brave little sparrow" print(story(model, tok, prompt))
Where Chittu is going
Two research releases
A 4B guard model and a 26M story model, open on Hugging Face, each with a card that lists every known failure.
The story model’s next milestone
A longer training run on rented GPU, then the gates in our status ledger before it can ever serve a child: a free-generation quality eval, the red-team corpus in every language our guards read, and a signed training record.
Safety inside the model, not only around it
That is the research direction. Every step ships with a card, and open weights stay the rule.
What the releases are
Two small models, both open, both trained on synthetic data, both documented to the last failure.
Kid-locked by construction
The story model was trained from scratch on nothing but children’s stories that Chittu’s own guards swept first.
Escalates, never improvises
The guard model answers a child’s message with one of four tokens or a safe reply. The tokens trigger scripted responses; the model never writes the crisis message itself.
No real child data
Both corpora are synthetic. The guard corpus was written and cross-reviewed by language models and contains no child’s words.
Every release ships with a card
Every evaluation result and every known failure listed. Where no person has read the generations yet, the card says so.
Run it yourself
Standard transformers weights for the guard model, a two-function loader for the story model, both small enough for a laptop.
Measured in the open
How the models compare with their peers, and what those comparisons do not show.