THE PROBLEM
Every prompt, every file, every embedding sits in plaintext on machines you don't control — one breach, one subpoena, one curious admin away from becoming someone else's data. Policies promise. They can't prove.
So we created the blackbox.
→ SEE THE SILICON
01 / THE SILICON
CPU + GPU.
One sealed enclave.
AMD SEV-SNP and NVIDIA H100 confidential computing, fused into a single attested boundary. Memory encrypted. The CPU ↔ GPU bus encrypted. Keys exist only inside measured code.
- SEV-SNP
- H100 CC
- ML-KEM-768
- REMOTE ATTESTATION
02 / THE INFRASTRUCTURE
Zero-trust metal,
racked & attested.
Every node boots measured and proves what it runs before a single key is released. Workloads stay operator-blind end to end — signed responses, tamper-evident audit chains, policy enforced in silicon, not in a terms-of-service.
- CONFIDENTIAL CONTAINERS
- TRUSTEE KBS
- MEASURED BOOT
- OPERATOR-BLIND
03 / THE PRODUCTS
One enclave. A whole product line.
04 / DEEP DIVE — RAG WORKSPACE
Your documents. Your model.
Nobody else.
Employees ask questions from the web UI or straight from their terminal. Documents are parsed, chunked and indexed entirely inside the enclave — and every answer carries a signed proof of what ran and what was retrieved.
DEVICE E2E AEAD ENCLAVE
RAG SEALED ENCRYPTED
INDEX
- WEB UI
- TUI
- PER-SESSION KEYS
- SIGNED ANSWERS
05 / DEEP DIVE — DATA ROOMS
Share the answer.
Never the file.
One party brings the data, the other brings the algorithm. The run happens inside the enclave — neither side sees the other's assets — and only outputs that pass the policy and no-leak checks ever come out, signed, with a tamper-evident audit chain.
- POLICY-GATED
- SIGNED AUDIT CHAIN
- REVOCABLE
- OPERATOR-BLIND
FOR · LEGAL, M&A, COMPLIANCE
06 / DEEP DIVE — INTERCEPTOR
Every agent
on a leash.
The one product that doesn't run on blackbox — it runs on every employee machine. A fail-closed egress firewall that detects each process — claude, codex, mistral-agent — by PID and binary hash, and kills or allows every outbound flow against your signed policy. Enforced in the kernel, no TLS interception.
- PER-PROCESS POLICY
- SIGNED POLICY BUNDLES
- ZERO DEPENDENCIES
- LINUX + MACOS
FOR · SECURITY & PLATFORM TEAMS
GET ACCESS
Build on blackbox.
We are onboarding design partners in finance, healthcare, legal and defense. Bring a workload — leave with proofs.
© 2026 BLACKBOX — OPERATOR-BLIND BY CONSTRUCTION