Trust architecture

Two worlds. One wall between them.

Your life on one side. The network's work on the other. The architecture is designed so it can never cross over — enforced by hardware, not by policy or promise. This page explains how, and labels every claim by how proven it is today.

Proven today existing, demonstrated technology In engineering designed, being built Pilot measures hypothesis the 100-Vault pilot tests

HOUSEHOLD ENVIRONMENT

Private models In engineering

Your AI runs here — your assistant, your family memory, your automations. Standard practice for local AI; the Vault's implementation is in build.

Personal data store In engineering

Documents, photos, calendar, finances — encrypted at rest, with keys held on the device.

Customer keys held locally Proven today

Secure-element key storage is mature, shipping technology. The Vault's identity and your encryption keys are designed to live in dedicated secure silicon — unreadable by Sarv.

ENTERPRISE WORKLOADS

Isolated ephemeral enclave In engineering

Grid jobs are designed to run in a separate environment with its own memory and no architectural path to the household side.

No access to household data Pilot measures

The separation is designed to be enforced below the operating system — and the pilot's job is to attack it, audit it, and publish the results before enterprise workloads ship.

Wiped when the job completes In engineering

Every enclave is designed to be destroyed after use — zeroised keys, cleared memory, nothing persisting into the next job.

Hard-separated by design — proven in public, or not shipped.

Hardware root of trust

Trust you can verify, not trust you have to believe.

Attested hardware Proven today

Remote attestation is established technology. Each Vault is designed to prove what it is before it receives work — a modified or emulated node simply gets none.

Signed workloads In engineering

Every workload class is reviewed and cryptographically signed by Sarv. The Vault refuses anything unsigned — no anonymous code, ever.

Encrypted end to end Proven today

Jobs are split, encrypted in transit, and results encrypted to keys the customer holds. The goal: a Vault processes fragments it cannot read, for a network that cannot see the whole.

Auditable by outsiders Pilot measures

Independent security audit and published attestation are gating milestones before enterprise workloads ship. We'd rather be checked than believed.

Honest limits

What we don't claim.

No system is unbreakable, and we won't pretend otherwise — including ours, especially before it's built. What we claim is narrower: this is the architecture we are engineering towards, each claim above carries its evidence status, and nothing ships to enterprise customers before external audit. Security here is a direction of travel with named milestones — external audit, published attestation, bug bounty — not a marketing adjective. If a claim on this site ever outruns its evidence, that's a bug: tell us and we'll fix it.

Join the network

Private by design.
Verified in public.

Join the Network