Blog
Benchmarks, design decisions and how-tos: building AI agents in Synsema, and deploying them with a permission manifest, sealed secrets and an audit trail. Every post is also Markdown: add .md to its URL.
7 results for confidential-computing
For some workloads the interesting question is not which model is best, but whether the data is allowed to leave at all. A model inside the process answers that with no egress, no vendor in the trust chain and no bill per token — and the price it charges is in latency and model size.
The calibrated probability that decides what a person sees no longer has to come from an API. An open-source System One checkpoint on your own disk answers the same typed questions with no key, no network and no cost per token — and the same program runs against either one.
Nitro Enclaves, confidential VMs, dstack, chain-anchored — four places to put the part of your product the operator must not read, and how to pick one without a six-week spike.
A confidential deployment nobody verifies is an ordinary deployment with extra cost. Here is the checklist a serious counterparty runs, what your side has to publish for it to pass, and the limits worth stating yourself before they ask.
A trusted execution environment hides your data from the operator. It does not stop your own code from leaking it, and it does not tell the client what is running inside. Synsema does both — information-flow labels and attestation are part of the language, not a library.
Every line inside the box costs more to write, more to change and more to verify — and each change invalidates the measurement your customers pinned. The split between the confidential core and the ordinary product is the highest-leverage decision in the design.
A walkthrough, from an empty file to a service whose client verifies the code before sending anything — labels on, an attested identity, and the same checks running in CI with the development driver.