blackbox

THE PROBLEM



Every prompt, every file, every embedding sits in plaintext on machines you don't control — one breach, one subpoena, one curious admin away from becoming someone else's data. Policies promise. They can't prove.

So we created the blackbox.

SEE THE SILICON

01 / THE SILICON

CPU + GPU.
One sealed enclave.

AMD SEV-SNP and NVIDIA H100 confidential computing, fused into a single attested boundary. Memory encrypted. The CPU ↔ GPU bus encrypted. Keys exist only inside measured code.

  • SEV-SNP
  • H100 CC
  • ML-KEM-768
  • REMOTE ATTESTATION

02 / THE INFRASTRUCTURE

Zero-trust metal,
racked & attested.

Every node boots measured and proves what it runs before a single key is released. Workloads stay operator-blind end to end — signed responses, tamper-evident audit chains, policy enforced in silicon, not in a terms-of-service.

  • CONFIDENTIAL CONTAINERS
  • TRUSTEE KBS
  • MEASURED BOOT
  • OPERATOR-BLIND

03 / THE PRODUCTS

One enclave. A whole product line.

AI Security Audit Continuous audit of your AI usage — signed chains, compliance evidence packs. FOR · CISOs & COMPLIANCE TEAMS Private Compute Run jobs on data you're never allowed to see. Results out — nothing else. FOR · DEVELOPERS & DATA PARTNERSHIPS Verifier Offline proof checks for every response — no trust in us required. FOR · AUDITORS & REGULATORS

04 / DEEP DIVE — RAG WORKSPACE

Your documents. Your model.
Nobody else.

Employees ask questions from the web UI or straight from their terminal. Documents are parsed, chunked and indexed entirely inside the enclave — and every answer carries a signed proof of what ran and what was retrieved.

EMPLOYEE
DEVICE
E2E AEAD ENCLAVE
RAG
SEALED ENCRYPTED
INDEX
workspace.blackbox.eu — live demo
blackbox RAG workspace: chat over sealed documents with a 22-check proof panel
  • WEB UI
  • TUI
  • PER-SESSION KEYS
  • SIGNED ANSWERS

05 / DEEP DIVE — DATA ROOMS

Share the answer.
Never the file.

One party brings the data, the other brings the algorithm. The run happens inside the enclave — neither side sees the other's assets — and only outputs that pass the policy and no-leak checks ever come out, signed, with a tamper-evident audit chain.

  • POLICY-GATED
  • SIGNED AUDIT CHAIN
  • REVOCABLE
  • OPERATOR-BLIND

FOR · LEGAL, M&A, COMPLIANCE

06 / DEEP DIVE — INTERCEPTOR

Every agent
on a leash.

The one product that doesn't run on blackbox — it runs on every employee machine. A fail-closed egress firewall that detects each process — claude, codex, mistral-agent — by PID and binary hash, and kills or allows every outbound flow against your signed policy. Enforced in the kernel, no TLS interception.

  • PER-PROCESS POLICY
  • SIGNED POLICY BUNDLES
  • ZERO DEPENDENCIES
  • LINUX + MACOS

FOR · SECURITY & PLATFORM TEAMS

GET ACCESS

Build on blackbox.

We are onboarding design partners in finance, healthcare, legal and defense. Bring a workload — leave with proofs.

© 2026 BLACKBOX — OPERATOR-BLIND BY CONSTRUCTION

ATTESTINGMEASURING BOOT…nbsp;ENCLAVE…