What is Hermetic
Hermetic is confidential compute for AI agents. An agent that needs to see sensitive data, a wallet history, a set of API keys, a folder of statements, runs inside a hardware enclave. The data is encrypted before it leaves you and is only ever decrypted inside that enclave. When the session ends, the enclave's attestation is turned into a receipt, and the hash of that receipt is anchored on Robinhood Chain.
The result is a split that ordinary agent infrastructure cannot offer:
- The content is private. Your input and the agent's answer are never visible to the machine's operator, to Hermetic, or to the chain.
- The run is public. Which hardware, which build, which model and which policy were used is recorded and can be verified by anyone, at any time, without your data.
Your data goes in. Nothing comes out.
Why agents need this
A language model you chat with sees what you type. An agent sees what it can reach. To trade for you it reads your positions; to file for you it reads your documents; to act for you it holds your keys. The more useful the agent, the more it has to see, and today the only guarantee you get about where that data goes is a privacy policy.
Hermetic replaces the policy with a measurement. The enclave proves, with a signature rooted in the CPU and GPU vendors' hardware, exactly what code ran. If the code says "retain nothing, call only this host", the receipt shows that this was the code that ran.
The pieces
| Piece | What it is |
|---|---|
| Enclave | An Intel TDX virtual machine with an NVIDIA H100 in confidential computing mode, running a measured Hermetic build. |
| Session | One sealed exchange between your agent and an enclave: open, verify, run, close. |
| Receipt | The record a session leaves: measurement, model digest, policy hash, input and output commitments, operator. |
| Registry | The on-chain list of enclave builds, model digests and policies the network accepts. |
| Operator | Whoever runs the hardware. Operators bond $HERMETIC and are slashed for invalid attestations or proven leaks. |
What Hermetic is not
Hermetic is not a zero-knowledge system. Enclaves are a hardware trust assumption, and we describe exactly what that assumption covers in the trust model. It is also not a model provider: Hermetic runs open-weights models whose digests are pinned in the registry.
Read next: Status and roadmap, then the quickstart.
Try it now
The app runs a real session today: a model served inside an Intel TDX enclave operated by Phala, a hardware quote verified in your browser against Intel's root, a signed receipt for every answer, and a session receipt you can download and seal on Robinhood Chain. Status and roadmap lists what is live and what is not.