$HERMETIC · pre-launch on Pons · Robinhood Chain

Hermetic

Hermetic is confidential compute for AI agents. Agents run inside hardware enclaves, and every session leaves a receipt anchored on Robinhood Chain. Anyone can audit where the agent ran. Nobody can read what it saw.

Your data goes in.
Nothing comes out.

Every useful agent asks for the keys.

Your wallet, your history, your documents. Today you hand them over and hope. Hermetic gives the agent a room it cannot leave, and gives you a receipt that proves it stayed inside. The protocol is deliberately small: four movements, each one checkable by anyone.

A room the agent cannot leave

The agent, its model and its tools run in an Intel TDX virtual machine with an NVIDIA H100 in confidential computing mode. Memory is encrypted by the hardware, on the CPU and on the GPU. The operator runs the machine and still cannot open what runs inside it.

fig. 01 · enclave

Sealed before it leaves you

Your agent asks the enclave for its attestation first, checks it against the public registry of approved builds, and only then encrypts its input to a key that exists inside that enclave and nowhere else.

fig. 02 · seal

A receipt on Robinhood Chain

When the session closes, the hardware's signed quote becomes a receipt: the build, the model digest, the policy, the operator. Its hash is written to Robinhood Chain. Thirty-two bytes. No input, no output, no prompt.

fig. 03 · anchor

An operator with something at stake

Operators bond $HERMETIC to serve sessions. An invalid quote, a build that is not in the registry, or a proven leak gets the bond slashed, and part of it pays whoever proved it.

fig. 04 · bond

Sealed session

The app opens a session with an enclave and checks its hardware quote against Intel's root before a single word is sent. Every answer comes back signed by a key that exists only inside that enclave.

Close the session and it becomes a receipt: the attestation and the signatures, never the words. You keep the answer. The chain keeps thirty-two bytes that prove where it came from. The terminal below is a simulation; the app is the real thing.

hermetic : zsh · simulated
~ %
Open a real session

Agent SDK

Open a session, verify the enclave before a byte is sent, run, close. The SDK refuses to talk to an enclave it cannot verify.

Read the quickstartin development

Operator node

Run TDX and H100 hardware, bond $HERMETIC, serve sealed sessions and earn the operator share of every fee.

Run a nodein development

Receipt verifier

Take any receipt and check it against the chain, without the data and without asking Hermetic. Runs in your browser today.

Who sees what

The whole design fits in this table. The content stays with you. The identity of the run is public, so anyone can audit it, forever.

Today, with your own key, Hermetic never sees a word. With the protocol relay, our server forwards your request in transit and stores nothing; end-to-end encryption to the enclave key removes even that.

YouOperatorHermeticChain
Your input
The agent's answer
Which code and model ran
The policy it ran under
That the session happened

$HERMETIC

The token is the bond behind every enclave. Operators put it at risk to serve sessions, users spend it to pay less, and holders decide which builds the network trusts.

Pre-launch on PonsOperators and token
Bond

Operators stake $HERMETIC to serve sessions. An invalid quote, an unlisted build or a proven leak is slashed, and the reporter is paid from the bond.

Pay

Sessions are priced in USDG or in $HERMETIC. Paying in $HERMETIC costs less, and the protocol share of every fee buys it back.

Govern

Holders vote on the measurement registry: which enclave builds, which model digests and which policies count as Hermetic.

Session fee, proposed splitset by governance
70% operator
20% cover
10%
10% buyback and burn

Field notes

Questions

Including the ones about what Hermetic cannot do. The trust model goes further.

No, and we will not call it one. Hermetic relies on hardware enclaves: the guarantee is that the CPU and GPU vendors' roots of trust are sound and that the measured code does what it says. That is a strong, practical guarantee, but it is a trust assumption, not a mathematical proof. The trust model page lists exactly what you are trusting.

Not without breaking the hardware. Memory inside a TDX virtual machine and on an H100 in confidential computing mode is encrypted with keys the host never sees. The operator runs the box; it cannot open what runs inside it.

A receipt hash, the enclave measurement, the model digest, the policy hash and the operator's address. No input, no output, no prompt, no embedding of either.

Today, the open-weights models RedPill serves inside a TEE: GLM, Qwen, DeepSeek, Kimi, gpt-oss and others, listed live in the app. Each signed receipt names the model and the upstream that served it.

Operators bond $HERMETIC to serve sessions. An invalid attestation, a build that is not in the registry, or a proven leak gets the bond slashed, and part of it goes to whoever proved it.

The app is. It talks to a model running in an Intel TDX enclave operated by Phala, verifies the hardware quote and every signed answer in your browser, and builds a session receipt. The registry that seals receipts is live on Robinhood Chain, and Hermetic does not run its own enclaves yet. The status page says exactly what runs and what comes next.

drag the seal

Sealed by design
© 2026 Hermetic