Confidential execution
Programs run on encrypted data. The machine computes; it never sees.
We research machines that compute on encrypted data and prove their work. Urizen advances verifiable private computation: machine-checked theory, confidential execution, and proof-carrying systems. From that research we build Nibiru, the engine for private execution with public proof of correctness, Baobab, the verifiable control layer for AI agents, and Anansi, the harness that joins them into governed agentic AI.
01 · Research
Six threads, one discipline: nothing ships on trust. Every layer — from the mathematics to the runtime to the agent on top — must prove what it did.
Programs run on encrypted data. The machine computes; it never sees.
Every run compresses into one compact receipt anyone can check in milliseconds.
Two parties compute together without revealing their private inputs to each other.
The theory behind the stack is proven end to end in Lean 4 — no gaps, no hand-waving.
Context, tool authority, and state promotion governed by certificates — refusal over guesswork.
Receipts as settlement objects: payment, reputation, and audit move on proof.
We do not ask you to trust the machine.
We make the machine prove itself.
02 · Systems
A trust runtime for confidential compute: private execution in, portable receipt out, settlement on proof. Running the full custody-to-settlement transaction today as an experimental MVP.
Explore the engine The productThe verifiable control layer for agentic workflows: deliberation separated from executable authority, tool calls gated by declared policy, and only verified state moves forward. Early access with design partners.
Meet Baobab The demonstrationPrivacy-preserving KYC built on Nibiru: encrypted signals in, a signed verifiable decision out — and the provider never sees the subject, the relying party, or the purpose. Experimental MVP with design partners.
Meet Heimdall The harnessThe governed execution harness for agentic AI: one runtime contract that joins the engine, the control layer, and private identity — so model proposals become governed, verifiable actions. Release candidate.
Meet AnansiNibiru · Operating model
Nibiru is infrastructure a buyer, provider, or agent uses today: define the private job, run it without blind trust, issue a portable receipt, and let settlement move on proof.
Program, input/output commitments, provider identity, price, timeout, and proof requirements become the market object.
Providers run Nibiru to execute confidential jobs without becoming the trusted party for data, logic, or settlement.
Verifiers check that the committed work ran correctly, while private inputs and proprietary logic stay sealed.
Receipts update payment, provider reputation, audit trails, and future capacity without relying on opaque logs.
Nibiru · The whole pipeline
Not a diagram — a working pipeline. Encrypted custody through proof-backed settlement to authenticated recovery, end to end, built from byte-identical reproducible signed releases — and proven across a continuous 24-hour, 100-transaction endurance run.
The customer payload enters under authenticated, resumable custody. Keys stay with the owner; the provider never holds them.
The provider runs the confidential job on ciphertext. It never sees the data or the proprietary logic it is executing.
Execution finalizes into one externally verifiable claim: correctness proven, private material sealed the entire way.
The claim converts into a single duplicate-safe settlement record. Pay once, on proof — not on a promise.
Signed, recipient-encrypted state recovers end to end. Nothing is lost across failure, and nothing leaks in the process.
An operator's word that the job ran as promised. Audit it later, if you can.
A receipt anyone can check in milliseconds. The data stays sealed, and the claim stands on its own.
Nibiru · One job, three windows
What a run looks like from the outside. The provider works on ciphertext the whole way; the receipt is the only thing that needs to be believed — and it doesn't ask to be.
$ nibiru submit --program sealed --input sealed
program committed 0x323a…5d53 (commitment only)
input committed 0x003c…cb57 (commitment only)
keys owner-held never leave this machine
→ job accepted · provider receives ciphertext only
trace hiddenpublic surface: commitments + valid-transition flag
0x3597 ··· 4eedverified in milliseconds · nothing was decrypted
Nibiru · Trust runtime for compute markets
The strategy is not to compete on cheap GPUs. It is to give compute and inference providers a runtime for jobs ordinary markets cannot serve: confidential, verifiable, and settlement-ready.
Confidential work
Sensitive inputs, policies, bids, models, or state stay sealed while a provider runs the job.
Proof-settled output
A portable receipt lets buyers, auditors, contracts, or agents verify that the committed work was done correctly.
Shared trust
When data and program owners differ, the receipt path does not require one intermediary to hold both parties’ private inputs.
Nibiru · Business wedge
Nibiru is strongest when a third party needs cheap verification and the computation is valuable enough that leakage, fraud, dispute, or audit risk matters.
holds keys and encrypts
runs on ciphertext
proves correct run
untrusted operator - never sees the private work
checks in milliseconds
Nibiru · Flagship demonstration
Heimdall proves a customer clears KYC and AML — without any party seeing their documents. Encrypted signals go in; a signed, independently checkable pass or fail comes out. In the live four-role flow, the provider’s request carries neither who the subject is, who is asking, nor why — identity stays in the client’s private context.
Heimdall is an experimental MVP for a bounded design-partner integration — not a regulated KYC product or production service.
Nibiru · Engine telemetry
A representative proof-settled run: private program, private input, one public receipt anyone can check in milliseconds. The proof theory is machine-checked in Lean 4, the stack builds reproducibly from signed releases — and the demo build just cleared a continuous 24-hour endurance campaign, 100 transactions for 100.
Baobab · First commercial product
Agents are getting more autonomous; their authority should not be. Baobab is the verifiable control layer for agentic workflows: it separates deliberation from executable authority, gates tool calls and retries against declared policy, and lets only independently verified state move forward — with a receipt for every accepted, rejected, or unresolved outcome.
For declared-tool agentic workflows in regulated operations — finance, compliance, procurement, settlement. Certificates cover declared workflows and tool traces, not free-text model reasoning. Early access with design partners; not yet generally available.
Anansi · The harness
Anansi turns model proposals into governed, private, and verifiable actions. It sits between your agent framework and your models, tools, and providers — packaging Nibiru, Baobab, and Heimdall behind one runtime contract. Model text, on its own, carries no executive authority.
For declared workflows on supported frameworks. Anansi governs what models may do — it makes no model-quality claims. Release candidate; early access with design partners.
Lab · Commercial sequence
The first commercial wedge is Baobab: certified control and audit receipts for agentic workflows. Proof-settled confidential jobs follow on the provider stack, and the long arc is a registry where receipts become reputation, capacity, and settlement infrastructure.
Nibiru · Who it serves
Nibiru sits above raw compute supply: it makes outsourced work legible enough to buy, sell, audit, rank, and settle.
Add confidential proof-settled jobs to existing capacity without becoming a trusted counterparty.
Prove a committed model or policy version ran while protecting customer data and proprietary logic.
Release payment, update reputation, and settle disputes on receipts rather than logs.
Delegate external work and require a receipt before action, payment, or compliance sign-off.
Confidential jobs - verified, not asserted.
Nibiru makes outsourced compute legible: private work in, private result out, portable receipt for verification, reputation, audit, and settlement.Request access
Thanks — your request is ready to send.
If you need to reach us directly, write to hello@urizen.ai. We read every request.