docketrouter
Tamper evidence

Verify the benchmark

Scores are only worth something if we cannot quietly change the questions after seeing how a model did. Every question in the bank and every graded answer is hashed into a Merkle tree. We publish the roots. Recompute them yourself from the published data, or hold us to a root we published before a run.

Item bank, as attested
13,149 questions · 2,612 blinded cases · 1,711 source opinions
A snapshot taken when the root below was published. The bank keeps growing, so the live counts are usually higher.
6aa3cddb1ec176281ab249b79db1b26c758ffb760f417b6b5588cb88aa2f2199
attested 2026-08-27 17:06:26 UTC

Runs

RunGraderCasesMeanResults root
deepseek/deepseek-v4-flash Raw (model alone)hll-grader-0.5200139%87a6e5ff1164882c38b0c2d0…
deepseek/deepseek-v4-flash With DocketRouterhll-grader-0.5117551%9b57440016a098b12c341218…

Grader source

The scoring code is mechanical and hashed with every attestation, so a score can always be tied to the exact code that produced it. One digest per scoring module:

ea2bcfb4d9b1c6c6f40d3ce34fca795c63fda673b2b8cd4a04d138a3a38d421e
bc31ff8673ad4880a5560f327f03d5ef788cef942f3f40396b057908e357c130
0840eae3b4415321ada7e041ed1e9b67762269e8ff7a1dd17b4eb9814315013e
58f4a1e983ef9c506eea6119c8271db6f270288d0b4651f9fb5a72e05aac5010

How to check it yourself

Recompute: canonical-JSON each item (keys sorted at every depth), leaf = sha256(0x00||json), sort leaves by item id, then fold pairs with sha256(0x01||left||right). The result must equal bank.merkle_root. For a run: leaf = sha256(0x00||canon({item, answer_sha256, score})), sort leaves, fold the same way.

The public split is downloadable at /api/v1/hll/public. A private question can be proven to have existed unchanged by revealing that one question plus its Merkle path, without publishing the rest of the private split.