Inference
For private model execution
Attest
/01 PROTOCOL LAYER- ✓ Composite CPU + GPU quotes
- ✓ Signed serving images
- ✓ Encrypted prompt delivery
- ✓ Per-response receipts
Enclave runs AI inside attested hardware. Keep prompts private, verify every receipt, and settle agent inference in USDC.
/
PRIVATE IN. PROVABLE OUT.
/
THE PROTOCOL
From an encrypted prompt to a verifiable receipt, Enclave brings private compute and agent commerce into one flow.

Keep model, memory and policy inside the enclave, with a wallet and an enforced spending mandate.

Settle per inference through x402. Confidential transfers shield amounts while addresses remain visible.

Give auditors scoped view keys and receipt exports without opening private prompts or model outputs.
/
TECHNOLOGY
/
THE INFERENCE LIFECYCLE
No secret is released until the hardware attestation verifies. Trust is checked before the first token.
/
THE FOUNDATION
/01
NVIDIA CC
/02
CPU TEE
/03
Arc
/04
USDC
/05
x402
A staged path from private inference to sealed agent commerce and frontier-scale compute.
Explore the architecture↗Milestones describe the product roadmap. Availability is announced as each phase is ready.

Encrypted requests, composite attestation, signed inference receipts, Arc anchoring and USDC settlement.
Explore this stage ↗
An enclave runtime for model, memory and policy, with wallets, on-chain mandates and private payments.
Explore this stage ↗
Attested model listings, provider stakes, fee accounting, receipt exports and scoped compliance tools.
Explore this stage ↗
Multi-GPU Blackwell clusters and fine-tuning inside the enclave extend the confidential execution boundary.
Explore this stage ↗For private model execution
For agents that transact
For verifiable oversight
The intended execution path keeps prompts, model memory and outputs inside an attested CPU and GPU environment. Requests are encrypted, TLS terminates in the confidential virtual machine, and operational records contain hashes rather than plaintext inputs or outputs.
A receipt records the model hash, code hash, input and output hashes, attestation reference, timestamp and signature. It provides provenance for an approved execution environment. It does not prove that the model’s answer is correct.
The protocol is designed for per-call USDC settlement through x402 or Nanopayments. Arc confidential transfers shield amounts; addresses remain visible. Agent mandates set spending limits.
Sealed agents keep their model, memory and policy inside the enclave. The planned runtime connects these agents to a wallet, spending mandates and signed receipts for their actions.
This is an interactive product preview. It uses sample models and simulated usage, receipts, payments and agents. No GPU inference is performed, no funds move, and no receipt is anchored on a blockchain.

Why a CPU and GPU quote must verify before keys, prompts or model weights are released.

The anatomy of a signed inference receipt and the limits of what it proves.

How per-call settlement and mandates fit into the sealed agent lifecycle.