Trusted distributed AI infrastructure

How do you run sensitive AI on a computer owned by a stranger?

That is the question Sarv exists to answer. The Sarv Grid is a trust and orchestration layer for AI compute — designed to verify every node, isolate every workload, and account for every job. The Sarv Vault is the first hardware built for it.

Why Sarv is different

Distributed compute exists.
Trusted compute doesn't. Yet.

Networks that rent out spare machines are already here — and they work for jobs nobody cares about. But the valuable work of the next decade — private documents, medical notes, legal files, personal assistants — can't run on a stranger's computer on a promise. Someone has to build the layer that makes it verifiable. That's the company we're building.

What exists today

Distributed compute

Plenty of networks sell raw spare capacity. The bargain is simple: cheap power, no guarantees about whose machine runs your job or what happens to your data. Fine for rendering frames. Not fine for anything sensitive.

What Sarv is building

Trusted compute

Every node proves what it is before it earns work. Every workload runs sealed, is wiped when done, and leaves an auditable record. Trust stops being a policy you hope for and becomes a property you can check.

Status, honestly: the trust architecture below is our engineering target, described in full on the Trust & Security page — with each claim labelled by what exists today, what's in engineering, and what the pilot must measure.

The core idea, end to end

One request. Eight proofs.

Follow a single AI job through the Sarv Grid — from the moment it enters the network to the moment every trace of it is gone. This pipeline is the product.

01
Request
A client submits an AI job — private by default, tagged with its requirements.
02
Attestation
The node proves it's genuine, untampered hardware running known software.
03
Verification
The scheduler checks that proof against the job's policy before offering work.
04
Isolation
The job is sealed in an ephemeral enclave — designed to be blind to the owner's side.
05
Scheduling
Work is placed where energy is cheaper and cleaner at that moment.
06
Inference
The job runs. No path to the owner's files, keys or assistant.
07
Zeroisation
Enclave destroyed, keys wiped, memory cleared. Nothing persists.
08
Settlement
Metered, logged, auditable. The network accounts for every job it ran.
Hardware-attested sealed wiped accounted Engineering target — evidence status on the Trust page

The problem

Every time you ask an AI a question, your words leave your home.

They travel hundreds of miles to a warehouse of computers owned by someone else. Your questions, your photos, your private documents — processed on machines you will never see, by companies you will never meet. And those warehouses are thirsty.

~950 TWh
Projected global data-centre electricity demand by 2030 — more than Japan uses today.
Expected growth in electricity use by AI-optimised data centres between 2025 and 2030.
A few
Companies own the machines, the models — and effectively, your data.
The centralisation problem Sarv exists to answer

The idea, in two minutes

What if the cloud came home?

SARV 3-MINUTE EXPLAINER · concept film · all £ figures shown are illustrative

Prefer to read? The whole story, page by page — start with the Grid, or jump straight to how a job stays safe on a stranger's machine.

What Sarv actually is

The network first.
The hardware follows.

Most people meet Sarv through the Vault. But the company is the Grid — the trust, verification and orchestration technology. The Vault is simply the first machine built to carry it.

Sarv Grid The technology

The trust and orchestration layer: attestation, workload isolation, energy-aware scheduling, zeroisation, settlement. This is the moat — and the thing no distributed-compute network has built. How the Grid works →

Sarv Vault First reference hardware

A small, quiet appliance for homes and businesses: private AI for its owner, verified capacity for the Grid. It proves the model end-to-end — and it must be worth owning even if it never earned a penny. Meet the Vault →

Other trusted hardware The direction

Any machine that can pass attestation could one day join — Apple Silicon, PCs, enterprise appliances. The Grid doesn't care whose box it runs on. It cares what the box can prove.

The big idea

One Vault is useful. A verified network of Vaults is infrastructure.

Private AI first

The Vault's first job is yours: a capable assistant designed so your documents, photos and context stay on your machine.

Trusted infrastructure

Nodes prove what they are; workloads run sealed and are wiped clean. Verification, not promises, is what makes strangers' computers usable.

Better utilisation

Capacity that already exists — already paid for, already powered, roughly 94% idle — becomes useful instead of wasted.

Owner economics last

When trusted utilisation works, owners share in what their hardware earns. A consequence of the model — never the reason for it.

Radical transparency

What we know — and what we don't, yet.

Sarv is a concept becoming a company. The trust architecture is an engineering target, not a shipped product; the private-AI appliance is real and buildable today; the Grid's economics are hypotheses. Every £ figure marked * is illustrative. Security claims on this site are labelled by evidence status — and the experiment that must prove them is already designed. We'd rather show you the experiment than sell you the fantasy.

The mission: 100 Vaults, six months →

The mission right now

100 Vaults. Six months.
Every hypothesis measured.

Join the network