PRIVACY_PROTOCOL: ENABLED

AI that can't see you back.

Confidential, verifiable AI inference — settled on Base. Your prompt and the model weights never leave the hardware enclave, and every run ships a cryptographic proof it executed correctly. Encrypted in. Verified out.

  • operator-blind TEE
  • on-chain attestation
  • x402 · USDC on Base
enclave://blindcompute
$ blindcompute run --confidential
PRIVACY_PROTOCOLENABLED
ENCRYPTIONACTIVE
ENCLAVEIntel TDX · H100
INPUTsealed · operator-blind
ATTESTATIONVERIFIED ✓
SETTLEMENTBase · USDC · x402

Built on confidential compute

NVIDIA
Intel
AMD
Coinbase
Ethereum
Hugging Face
NVIDIA
Intel
AMD
Coinbase
Ethereum
Hugging Face
TEE
How it works

The operator runs the model — and never sees your data.

Your request is encrypted to the enclave's attested public key, so it decrypts only inside a sealed TEE (Intel TDX + NVIDIA H100 confidential computing). The GPU host can't read your prompt, your output, or the model weights — and every run emits a hardware attestation, verified on Base.

  • Encrypted end-to-end to the enclave
  • Runs in a hardware-isolated TEE
  • Attestation verified on Base

Confidential, verifiable, and yours.

The two guarantees no centralized provider gives you — enforced by hardware and anchored on Base.

Operator-blind

Your prompt and the model weights never leave the enclave.

request · sealed to enclave key
7f3a c1e0 9b22 4e8d a01f
a4d8 6610 ee01 77bc 9d3e
02bc 9f47 3a5d c8e2 41a0
d1e9 04af 88c3 5b6f e220
6c11 7a90 02de 9ff4 1b8a
// operator sees ciphertext only
Verifiable

A hardware attestation proves the right model ran, untampered.

attestation
measurement0x9b…2b9695
enclaveIntel TDX · H100
modelllama-3.1-8b
VERIFIEDon Base

Route across confidential backends — Phala, Atoma, or your own GPU-TEE nodes.

Phala
Atoma
Native

The platform

One endpoint. Private, verifiable, paid.

Requests are encrypted to the enclave's attested key and only decrypt inside a TEE. The GPU host — and BlindCompute — never see your prompt, your output, or the model weights.

request · sealed to enclave key
7f3a c1e0 9b22 4e8d a01f
a4d8 6610 ee01 77bc 9d3e
02bc 9f47 3a5d c8e2 41a0
d1e9 04af 88c3 5b6f e220
6c11 7a90 02de 9ff4 1b8a
// operator sees ciphertext only

$ blindcompute pricing --compare
Pricing

Pay only for what you call.

Inference settles per request in USDC over x402 — no seats, no lock-in. Hold $BLIND to cut the rate; the discount scales with the share of supply you hold, not its price.

TEE — Standard

Operator-blind inference in a hardware enclave (Intel TDX + NVIDIA H100 CC), behind one OpenAI-compatible endpoint. The agent-economy default.

$0.90/ 1M tokens

  • Confidential TEE inference
  • Hardware attestation on Base
  • Pay-per-call USDC (x402)
// recommended

ZK-Receipt

Everything in Standard, plus a portable, on-chain-verifiable ZK receipt per call — succinct proof the correct, attested model ran. For audit-grade claims.

$2.40/ 1M tokens

  • Portable ZK receipt per call
  • Reputation-weighted routing
  • $BLIND staking discounts

FHE — Max

Dedicated GPU-TEE nodes with priority routing and an SLA, plus an FHE path (Fhenix / Inco on Base) for designated operations. Testnet preview.

from $9.50/ 1M tokens

  • Dedicated GPU-TEE nodes
  • FHE on select operations
  • Custom SLA + support

// $BLIND holder discounts

launching on Clanker · 100B supply · 1B = 1%

The rates above settle in USDC, so they stay stable. Hold $BLIND to discount them — tiers are set by share of supply, not token price, so your discount is fixed from day one, even before the market prices the token.

10M$BLIND

0.01% of supply

10% off every call

100M$BLIND

0.1% of supply

20% off + priority routing

1B$BLIND

1% of supply

35% off + first-in-queue

Indicative testnet tiers — final thresholds locked at token launch.