Your agent runs on a rig that even we can't read.

We own the machines. You get a key, and your agent runs on a rig we boot for you. The signing key is born on that rig and never leaves it. Prompts, memory and strategy stay inside. You get an attestation and receipts.

Scroll

how it works

Sealed on the rig. Signed on the rig.

The hardware is ours. You hold a key, we bring a rig up for you, and the signing key never exists outside it. The only things that come out are transactions and receipts.

You get a key

One key, issued by us. There is no cloud account to connect, nothing to provision and nothing to install.

We boot a rig on our hardware

A machine we own, running one agent and nothing else, and it hands you an attestation. The measurement tells you exactly what code is running before you trust it with anything.

The key is born inside

You fund the address it gives you. The private key never exists outside the enclave.

Think and sign on the rig

You watch it through receipts: transaction hashes, GPU-seconds, uptime. Contents stay inside.

The only exports are transactions and receipts.

the wall

What gets in, what gets out.

you rig enclave chain agent funds signed tx receipts keys, memory, prompts
  • funds go in
  • signed transactions go out
  • receipts come back to you
  • keys, memory and prompts hit the wall

where we are

What is enforced today.

Empra is in private beta and the attestation is simulated. That means the code path is real and checkable, and the hardware root is not there yet. Here is the line, drawn where it actually falls.

Enforced todayWhat hardware adds
Measured bootA hash of the rig bundle and its boot config. Recompute it yourself with one command.The same hash, folded into the machine's own boot chain.
Key custodyBorn in the signer, sealed at rest, returned by no method. A root operator on the host could still read it.Sealed from the host by the silicon, which is the part that is missing.
Policy boundaryEvery signature checked against a measured policy. Refusals recorded in a hash-chained log.Nothing. This is already enforced.
ReceiptsHash chained, signed by the rig key, anchored on chain in strict sequence.Nothing. This is already enforced.
Attestation rootA simulated root. It proves what code the rig claims to run, not that hardware protected it.An Intel or AMD root you can check without trusting us.

Every attestation and every receipt carries which mode produced it, and the running mode is readable at /api/config. A simulated attestation is never presented as a hardware one.

what stays on the rig

Three things worth attacking. None of them leave.

  1. 01KeysGenerated inside the enclave on first boot and used there. Nothing exports them, including us.
  2. 02MemoryHistory, embeddings and scratch files live on the rig's encrypted disk, keyed to the enclave. Snapshots are yours to take.
  3. 03StrategyPrompts, tools and any weights you bring are loaded into the enclave and inference runs on the rig, so they never cross the network. On confidential hardware the host cannot read them either.
  4. 04ReceiptsThe one thing that does come out. Transaction hashes, GPU-seconds and uptime, signed by the rig, every hour.

compared

Where the key lives.

Your laptopA cloud VMAn Empra rig
Who holds the signing keyYou, on diskThe VM, and its hostThe enclave. No one else.
Can the host read memoryYesYesNo
Attestation before you trust itNoNoYes
Single tenantYes, it is yoursRarelyAlways
What leaves the machineAnythingAnything the host wantsTransactions and receipts

what we can see

Our side of the wall.

The host has to bill you and keep the rig up. That is the whole list. Everything else is a blank to us, by construction.

we can see

rig uptime and hardware health
gpu-seconds billed to your account
transaction hashes the agent broadcast
network volume in and out, not contents
the enclave measurement you were given

we can't see

prompts, outputs and tool calls
memory, files and snapshots
weights or prompts you bring
the signing key
anything inside the enclave
rigr7-hel-02 enclaveh100 confidential mode measure9f3a 41c0 8b7e c21e uptime41 days signed12 by policy refused1 by policy gpu-seconds3,412 today network1.2 gb in / 0.4 gb out last tx0x4b17 signed on rig promptsnot visible memorynot visible keynot visible

rigs

One agent per rig.

A rig is a single-tenant machine we own and run. Your enclave is the only workload on it, so there is no neighbour sharing a cache. Pay by the hour or by the month, against the key we gave you.

By the hour

Hourly

A rig comes up when your agent needs one and goes away when it does not. You are billed for the seconds it worked.

  • H100 80GB, confidential mode
  • Encrypted NVMe, dedicated egress
  • Attestation on every boot
Get a key

By the month

Monthly

One of our machines held for you. Same rig, same enclave, same signing key, all month.

  • Everything in hourly
  • Persistent memory between runs
  • Robinhood Chain now, Base and Ethereum next
Get a key






questions

Things people ask.

Whose hardware is it?

Ours. Empra buys and runs the machines, so there is no cloud account to connect and no provisioning for you to do. You get a key, we bring a rig up, and you check what it is running before you fund it.

What does the attestation prove?

The measurement is a hash of the code the enclave booted. You compare it to the published build before you fund anything. If they differ, do not fund it.

What if Empra is compromised?

Today, in beta, an operator with root could read the signer's memory. That is exactly why the attestation says simulated and why we do not claim otherwise. On confidential hardware the enclave's memory is sealed from the host, and the GPU's compute region is fenced off by hardware firewalls rather than encrypted, which is a real distinction worth knowing. Either way we can turn the rig off, and no attestation fixes that.

Can I get my memory out?

Yes. Snapshots are encrypted to a key you hold and you can take one any time. We cannot read them.

Which chains?

Robinhood Chain now. Base and Ethereum next. Anything the agent can reach over RPC after that.

How is it billed?

By the hour or by the month, by GPU-seconds. The receipt is the bill.

Can two agents share a rig?

No. One agent per rig is the point.

get a key

Hold 1,000 empra, then take a rig.

The key is gated on the token. Connect the wallet that holds at least 1,000 empra, sign one message to prove it, and the key is yours along with a starting allowance of compute.

Already have a key? Open your rigs.