← Home

Standing disclosure

What we cannot do

The boundary of every claim on this site, stated by us rather than discovered by you.

Reviewed 14 September 2026

Maintained alongside the prototype. Updated when a limit moves.

Why this page exists

A company selling verifiability cannot ask to be taken on faith.

Every vendor describes the inside of its boundary thoroughly and the outside of it rarely. That asymmetry is precisely what makes attestation evidence easy to misread: the capability is documented, the limit is left for the reader to discover at the worst possible moment.

So this page is the other half. It is not a disclaimer appended to a sales claim. It is the list of things we are asked for, or could plausibly be assumed to provide, and do not.

If something here is out of date, it is a bug and we want to know. A limit that quietly disappears from this page without the underlying work being done would be worse than never publishing it.

The current state

What does not exist yet

There is no service to buy.

No public API, no operator onboarding, and no billing. The prototype places jobs on hardware we own ourselves. Intended pricing is published so it can be checked before anything is for sale — but nothing can be bought, and nothing on this site is an offer.

The network is not yet decentralized.

One coordinator, and every node in the pool belongs to us. The architecture is designed for independent operators; the deployment does not demonstrate it. We will describe the network as decentralized when at least one operator who is not us is running.

Four of seven attestation roots are unverified by us.

We have appraised Android, AWS Nitro and TPM 2.0 evidence first-hand. For Apple App Attest a verifier is written but no device evidence has ever been checked against it. Intel TDX, AMD SEV-SNP and NVIDIA Confidential Computing are documented from primary sources and nothing more. The comparison page marks each one.

Operator identity protection is decided, not deployed.

A TPM’s endorsement key cannot be rotated, so a stored list of them would identify every operator’s machine permanently and for the life of the hardware. Our decision is that the raw value is never written down: it is replaced by a keyed hash on arrival. That code exists, but nothing loads it yet, no TPM has enrolled, and the TPM verifier itself is not written. Until it runs this is a stated intention, not a property of the system.

GPU support is research.

No GPU has been attested, benchmarked, or placed. No confidential-execution result exists. The illustrations on this site are conceptual.

The limits of the evidence itself

What attestation does not prove

A measurement is not a guarantee of behaviour.

A launch measurement fixes what was loaded. It says nothing about whether that code is correct, or what it did afterwards.

Android proves key custody, not workload isolation.

Third parties cannot deploy code into TrustZone on stock Android. Integrity is inferred from verified boot rather than enforced by memory separation. A device that passes attestation is a device whose owner is still on the other side of the boundary.

An enclave measurement is not proof of isolation.

AWS Nitro PCRs measure the enclave image, the kernel, the parent instance and its IAM role. Isolation is a property AWS designs and asserts about its platform. No PCR measures it.

Confidential computing is not a property of every GPU.

NVIDIA implements it only on datacenter parts: H100, H200, B200, HGX B300 and the RTX PRO 6000 Blackwell Server Edition. No GeForce or consumer RTX card has a Confidential Computing mode, a device identity certificate, or the security processor that signs an attestation report. There is no evidence to verify, and no work on our side changes that.

A measured host is not an attested GPU.

A machine whose platform is measured by its TPM can still hold a GPU that attests nothing. The honest description of that machine is that the host is measured and the accelerator is not, and that its operator can read the workload. Should we ever offer capacity of that kind it will be named, priced and documented as a separate tier. The word attested does not travel from the host to the accelerator.

Capacity is bounded, never believed.

No evidence a machine can produce demonstrates what it can actually handle. An operator's stated capacity is a request. It is capped by the isolation level their attestation reports and by our own ceiling, and it is earned by completing real work.

Verified is not the same as acceptable.

Evidence can verify perfectly against a pinned root and still fail a customer's policy. We keep the two words distinct everywhere, because collapsing them is how a compliance package comes to mean less than it appears to.

A placement record is not proof of completion.

An evidence bundle records a verification and a placement decision, with its limitations attached. It is not a receipt for finished work or a statement about the output.

Freshness

Evidence expires faster than people expect.

Working with real hardware, we have measured Android attestation leaf certificates valid for roughly half an hour, and the AWS Nitro signing leaf at about three hours. By the time an auditor opens a compliance package, its certificates will not verify.

That is a property of the evidence, not a defect in it. It is also why the verification result and the moment it was reached are recorded as part of the artifact rather than left to be recomputed later.

Standing commitment

This page is meant to cost us something.

Naming the roots we have not appraised is less flattering than listing the ones we have. Saying the network is not yet decentralized is less flattering than saying it is designed to be. We would rather a reader find those sentences here than find them out later.

See what each root proves, and what it does not