Source and model transparency

A production-grade open-source repository with explicit boundaries.

SafeRide publishes its reviewed mobile app, website, owned API, local infrastructure, public-safe AI tooling, tests, and release evidence under approved open licenses without exposing restricted people or operational records.

Brief

Public-interest technology needs public accountability.

The public surface includes the Android client, owned API, local infrastructure, website, on-device assistant configuration, release checksums, model cards, and clear statements about what is tested, restricted, or still pending.

Visible

clean source snapshot for public review

Separate

code, content, model, and dataset terms

v0.5.8

hash-bound LiteRT-LM testing artifact

SafeRide source-review desk with repository, Android device, and architecture notes

Supporting detail

What reviewers can inspect publicly.

Client

The Android client shows the product contract.

Screens, navigation, draft persistence, case tracking, privacy controls, and content packs can be reviewed directly in the repository.

Backend

The owned API and local infrastructure are reviewable.

The mirror includes the current first-party API, Postgres migrations, local services, storage contracts, and privacy controls used by the migration branch.

Assistant

The tested local model path is hash-bound.

The v0.5.8 LiteRT-LM model, immutable revision, byte size, checksum, runtime, and Android testing limits are published without claiming production or survivor-facing approval.

Launch site

The website is part of the audit surface.

Routes, metadata, sitemap, robots policy, contact inbox, and public copy are treated as launch artifacts that reviewers can test, not marketing afterthoughts.

Android client

Expo and React Native power the app screens, navigation, offline draft storage, privacy controls, decoy mode, quick exit, and case workflows.

Local assistant

The Gemma 4 E2B registry binds the exact v0.5.8 LiteRT-LM file, immutable URL, checksum, storage lifecycle, survivor-centred prompt, and fail-closed capability controls.

Backend transition

The current branch includes the first-party SafeRide API and local Postgres/object-storage stack. Older Supabase material is historical and excluded from the public mirror.

Launch transparency

The website publishes canonical release metadata, APK checksum, model links, source-mirror provenance, safety boundaries, sitemap coverage, and contact paths.

What contributors can audit now

  1. 1Review privacy claims against draft storage, consent screens, data export, decoy PIN, and quick-exit utilities.
  2. 2Review the first-party API and local-infrastructure migration while preserving local-first behaviour.
  3. 3Verify the Android preview and on-device model against the published hashes and stated device limits.
  4. 4Validate legal and support content with Kenyan GBV, medical, legal, and safeguarding experts.

Review the public source, model, and release evidence.

Read pilot updates