Every AI chatbot is handed a hidden list of rules before it ever talks to you — who it is, what it must never say. Here are of them, from companies, pulled apart and laid side by side — then flipped over to look at the jailbreaks built to break them.
Source data: the CL4R1T4S & L1B3RT4S archives by Pliny · @elder-plinius, plus leaked-system-prompts by @jujumilk3. This project just visualizes their public collections.
Each cell counts how often a company's rulebooks bring up a touchy subject. Darker = more airtime. It's a map of what each lab is nervous about — not a scorecard of who's "safer." Top 24 companies by length shown; all are in the archive.
Some labs hand their AI a sticky note. Others hand it a novel. Toggle between sheer length and bossiness — how many "must / never / always" commands they cram in per 1,000 words. Top 24 shown.
All leaked files. Hover to lift the redaction; click any to read the raw prompt on GitHub. Search by model or company.
Line up any two rulebooks and see exactly what changed — red leaves, green arrives. Default view puts an old Claude next to a new one, so you can watch the rulebook grow as the labs bolt on instruction after instruction.
Flip the dossier over. Everything above is the defense — the rulebooks. This is the attack: Pliny's L1B3RT4S jailbreak archive, read only in the aggregate — which techniques show up most across files targeting models. No exploit text is reproduced here — just the shape of the attack surface.
Read as a taxonomy, not a toolkit — counts of technique keywords, aggregated across the collection.