Open models

Chittu is our model family. Its weights are open.

Chittu is the model track behind pinmbo. Two research releases are open on Hugging Face today: a small guard model and a from-scratch story model, both trained on synthetic data with no real child data in them. Neither serves a child yet. pinmbo’s safety comes from deterministic guards around whichever model answers, and the open models are our work toward putting that safety inside the model.

Tulifo/chittu-guard-v0-4bGuard model
# Guard model — standard transformers layout
from transformers import AutoModelForCausalLM
from transformers import AutoTokenizer

repo = "Tulifo/chittu-guard-v0-4b"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(repo)
Parameters4B
Training data5,250 synthetic examples
LicenceApache-2.0
Released27 Sep 2026
Tulifo/chittu-story-v0-26mStory model
# Story model — ships its own two-function loader.
# nanochat's model code must be importable
# (commit 92d63d4 or near; see the model card).
import sys
from huggingface_hub import snapshot_download
repo = "Tulifo/chittu-story-v0-26m"
repo_dir = snapshot_download(repo)
sys.path.insert(0, repo_dir)  # load.py is in repo_dir
from load import load, story
model, tok = load(repo_dir)
prompt = "tell me a story about a brave little sparrow"
print(story(model, tok, prompt))
Parameters26.3M
Training data2.33M swept stories
LicenceApache-2.0
Released27 Sep 2026

Where Chittu is going

Now

Two research releases

A 4B guard model and a 26M story model, open on Hugging Face, each with a card that lists every known failure.

Next

The story model’s next milestone

A longer training run on rented GPU, then the gates in our status ledger before it can ever serve a child: a free-generation quality eval, the red-team corpus in every language our guards read, and a signed training record.

Then

Safety inside the model, not only around it

That is the research direction. Every step ships with a card, and open weights stay the rule.

What the releases are

Two small models, both open, both trained on synthetic data, both documented to the last failure.

Kid-locked by construction

The story model was trained from scratch on nothing but children’s stories that Chittu’s own guards swept first.

Escalates, never improvises

The guard model answers a child’s message with one of four tokens or a safe reply. The tokens trigger scripted responses; the model never writes the crisis message itself.

No real child data

Both corpora are synthetic. The guard corpus was written and cross-reviewed by language models and contains no child’s words.

Every release ships with a card

Every evaluation result and every known failure listed. Where no person has read the generations yet, the card says so.

Run it yourself

Standard transformers weights for the guard model, a two-function loader for the story model, both small enough for a laptop.

Measured in the open

How the models compare with their peers, and what those comparisons do not show.