Hermetic
Hermetic is confidential compute for AI agents. Agents run inside hardware enclaves, and every session leaves a receipt anchored on Robinhood Chain. Anyone can audit where the agent ran. Nobody can read what it saw.
Your data goes in.
Nothing comes out.
Every useful agent asks for the keys.
Your wallet, your history, your documents. Today you hand them over and hope. Hermetic gives the agent a room it cannot leave, and gives you a receipt that proves it stayed inside. The protocol is deliberately small: four movements, each one checkable by anyone.
A room the agent cannot leave
The agent, its model and its tools run in an Intel TDX virtual machine with an NVIDIA H100 in confidential computing mode. Memory is encrypted by the hardware, on the CPU and on the GPU. The operator runs the machine and still cannot open what runs inside it.
Sealed before it leaves you
Your agent asks the enclave for its attestation first, checks it against the public registry of approved builds, and only then encrypts its input to a key that exists inside that enclave and nowhere else.
A receipt on Robinhood Chain
When the session closes, the hardware's signed quote becomes a receipt: the build, the model digest, the policy, the operator. Its hash is written to Robinhood Chain. Thirty-two bytes. No input, no output, no prompt.
An operator with something at stake
Operators bond $HERMETIC to serve sessions. An invalid quote, a build that is not in the registry, or a proven leak gets the bond slashed, and part of it pays whoever proved it.
Sealed session
The app opens a session with an enclave and checks its hardware quote against Intel's root before a single word is sent. Every answer comes back signed by a key that exists only inside that enclave.
Close the session and it becomes a receipt: the attestation and the signatures, never the words. You keep the answer. The chain keeps thirty-two bytes that prove where it came from. The terminal below is a simulation; the app is the real thing.
Agent SDK
Open a session, verify the enclave before a byte is sent, run, close. The SDK refuses to talk to an enclave it cannot verify.
Operator node
Run TDX and H100 hardware, bond $HERMETIC, serve sealed sessions and earn the operator share of every fee.
Receipt verifier
Take any receipt and check it against the chain, without the data and without asking Hermetic. Runs in your browser today.
Who sees what
The whole design fits in this table. The content stays with you. The identity of the run is public, so anyone can audit it, forever.
Today, with your own key, Hermetic never sees a word. With the protocol relay, our server forwards your request in transit and stores nothing; end-to-end encryption to the enclave key removes even that.
| You | Operator | Hermetic | Chain | |
|---|---|---|---|---|
| Your input | ||||
| The agent's answer | ||||
| Which code and model ran | ||||
| The policy it ran under | ||||
| That the session happened |
$HERMETIC
The token is the bond behind every enclave. Operators put it at risk to serve sessions, users spend it to pay less, and holders decide which builds the network trusts.
Operators stake $HERMETIC to serve sessions. An invalid quote, an unlisted build or a proven leak is slashed, and the reporter is paid from the bond.
Sessions are priced in USDG or in $HERMETIC. Paying in $HERMETIC costs less, and the protocol share of every fee buys it back.
Holders vote on the measurement registry: which enclave builds, which model digests and which policies count as Hermetic.
Field notes
Questions
Including the ones about what Hermetic cannot do. The trust model goes further.
No, and we will not call it one. Hermetic relies on hardware enclaves: the guarantee is that the CPU and GPU vendors' roots of trust are sound and that the measured code does what it says. That is a strong, practical guarantee, but it is a trust assumption, not a mathematical proof. The trust model page lists exactly what you are trusting.
Not without breaking the hardware. Memory inside a TDX virtual machine and on an H100 in confidential computing mode is encrypted with keys the host never sees. The operator runs the box; it cannot open what runs inside it.
A receipt hash, the enclave measurement, the model digest, the policy hash and the operator's address. No input, no output, no prompt, no embedding of either.
Today, the open-weights models RedPill serves inside a TEE: GLM, Qwen, DeepSeek, Kimi, gpt-oss and others, listed live in the app. Each signed receipt names the model and the upstream that served it.
Operators bond $HERMETIC to serve sessions. An invalid attestation, a build that is not in the registry, or a proven leak gets the bond slashed, and part of it goes to whoever proved it.
The app is. It talks to a model running in an Intel TDX enclave operated by Phala, verifies the hardware quote and every signed answer in your browser, and builds a session receipt. The registry that seals receipts is live on Robinhood Chain, and Hermetic does not run its own enclaves yet. The status page says exactly what runs and what comes next.
drag the seal