We research machines that compute on encrypted data and prove their work.

Urizen advances verifiable private computation: machine-checked theory, confidential execution, and proof-carrying systems. From that research we build Nibiru, the engine for private execution with public proof of correctness, and Baobab, the verifiable control layer for AI agents.

Confidentiality (FHE) Integrity (ZK) Mutual trust (MPC)
Lean 4 Proof theory machine-checked — end to end, no gaps · reproducible signed builds

01 · Research

Cutting-edge work across the private-computation stack.

Six threads, one discipline: nothing ships on trust. Every layer — from the mathematics to the runtime to the agent on top — must prove what it did.

R1

Confidential execution

Programs run on encrypted data. The machine computes; it never sees.

R2

Proof-carrying computation

Every run compresses into one compact receipt anyone can check in milliseconds.

R3

Mutual trust

Two parties compute together without revealing their private inputs to each other.

R4

Machine-checked foundations

The theory behind the stack is proven end to end in Lean 4 — no gaps, no hand-waving.

R5

Certified agent control

Context, tool authority, and state promotion governed by certificates — refusal over guesswork.

R6

Proof-settled markets

Receipts as settlement objects: payment, reputation, and audit move on proof.

Nibiru · Operating model

One runtime, four market surfaces.

Nibiru is infrastructure a buyer, provider, or agent uses today: define the private job, run it without blind trust, issue a portable receipt, and let settlement move on proof.

01

Job manifest

Program, input/output commitments, provider identity, price, timeout, and proof requirements become the market object.

02

Trust runtime

Providers run Nibiru to execute confidential jobs without becoming the trusted party for data, logic, or settlement.

03

Portable receipt

Verifiers check that the committed work ran correctly, while private inputs and proprietary logic stay sealed.

04

Settlement namespace

Receipts update payment, provider reputation, audit trails, and future capacity without relying on opaque logs.

Nibiru · The whole pipeline

The full transaction runs today.

Not a diagram — a working pipeline. Encrypted custody through proof-backed settlement to authenticated recovery, end to end, built from byte-identical reproducible signed releases — and proven across a continuous 24-hour, 100-transaction endurance run.

  1. 01

    Encrypted custody

    The customer payload enters under authenticated, resumable custody. Keys stay with the owner; the provider never holds them.

  2. 02

    Private execution

    The provider runs the confidential job on ciphertext. It never sees the data or the proprietary logic it is executing.

  3. 03

    Proof-backed claim

    Execution finalizes into one externally verifiable claim: correctness proven, private material sealed the entire way.

  4. 04

    One-use settlement

    The claim converts into a single duplicate-safe settlement record. Pay once, on proof — not on a promise.

  5. 05

    Authenticated recovery

    Signed, recipient-encrypted state recovers end to end. Nothing is lost across failure, and nothing leaks in the process.

Nibiru · Trust runtime for compute markets

Nibiru turns raw compute into trust-bearing capacity.

The strategy is not to compete on cheap GPUs. It is to give compute and inference providers a runtime for jobs ordinary markets cannot serve: confidential, verifiable, and settlement-ready.

Private job execution

Confidential work

Sensitive inputs, policies, bids, models, or state stay sealed while a provider runs the job.

Job receipts

Proof-settled output

A portable receipt lets buyers, auditors, contracts, or agents verify that the committed work was done correctly.

Bilateral privacy

Shared trust

When data and program owners differ, the receipt path does not require one intermediary to hold both parties’ private inputs.

job manifest sealed execution portable receipt independent verification payment or reputation settles

Nibiru · Business wedge

Start with compact, high-value decisions where trust is the product.

Nibiru is strongest when a third party needs cheap verification and the computation is valuable enough that leakage, fraud, dispute, or audit risk matters.

data owner

holds keys and encrypts

FHE VM

runs on ciphertext

ZK receipt

proves correct run

untrusted operator - never sees the private work

verifier

checks in milliseconds

verifier accepts operator reputation updates payment route unlocks bad receipts fail closed

Nibiru · Flagship demonstration

Heimdall: privacy-preserving KYC.

Heimdall proves a customer clears KYC and AML — without any party seeing their documents. Encrypted signals go in; a signed, independently checkable pass or fail comes out. In the live four-role flow, the provider’s request carries neither who the subject is, who is asking, nor why — identity stays in the client’s private context.

  • Nothing to leak. Checks run on encrypted signals; the provider receives neither the subject, the relying party, nor the purpose.
  • Portable decision. A signed pass or fail ships with a ~1 kB receipt a bank, marketplace, or auditor can verify.
  • One-use, role-separated. Issuer, finalizer, client, and provider run as separated roles; every decision binds to a single purpose, exactly once — and malformed requests fail closed.

Heimdall is an experimental MVP for a bounded design-partner integration — not a regulated KYC product or production service.

Nibiru · Engine telemetry

Real runs, not roadmap.

A representative proof-settled run: private program, private input, one public receipt anyone can check in milliseconds. The proof theory is machine-checked in Lean 4, the stack builds reproducibly from signed releases — and the demo build just cleared a continuous 24-hour endurance campaign, 100 transactions for 100.

External checks / run
1
Private run + receipt, warm
≈48s
Receipt verification
8ms
Public receipt size
O(1)
Endurance run, 24 h continuous
100/100

Baobab · First commercial product

Baobab: certified control for agentic workflows.

Agents are getting more autonomous; their authority should not be. Baobab is the verifiable control layer for agentic workflows: it separates deliberation from executable authority, gates tool calls and retries against declared policy, and lets only independently verified state move forward — with a receipt for every accepted, rejected, or unresolved outcome.

  • Refusal is the feature. Out-of-policy tool calls and unsafe context compactions are rejected before invocation — fail-closed, with the state root unchanged.
  • Deliberation is not authority. Agents reason over broad context — but nothing becomes executable authority without an explicit rule or a pinned verifier accepting it.
  • Honest, auditable outcomes. ~68–89% certified context reduction on retained fixtures; failed external calls are recorded as effect-uncertain, never disguised as rollback — and every outcome carries a receipt.

For declared-tool agentic workflows in regulated operations — finance, compliance, procurement, settlement. Certificates cover declared workflows and tool traces, not free-text model reasoning. Early access with design partners; not yet generally available.

Lab · Commercial sequence

First certified control; then confidential jobs; then the receipt namespace.

The first commercial wedge is Baobab: certified control and audit receipts for agentic workflows. Proof-settled confidential jobs follow on the provider stack, and the long arc is a registry where receipts become reputation, capacity, and settlement infrastructure.

Near-term wedges

  • Certified agent control and audit receipts for agentic workflows in regulated operations.
  • Verifiable confidential auctions, RFQ clearing, and solver selection.
  • Regulated decisioning receipts for policy, eligibility, underwriting, and audit.
  • Compact fraud and risk scorecards where raw data or logic cannot be shared.
  • Private model evaluation and licensing receipts.
  • Provider benchmark and reserved-capacity receipts.

Business model

  • Baobab SDK licensing with a per-receipt credential tier.
  • Trust-runtime license for compute and inference providers.
  • Usage fee per valid receipt or premium job settlement.
  • Marketplace sidecar integrations for existing GPU and inference networks.
  • Registry for job manifests, provider reputation, and settlement events.
  • Reserved confidential capacity and provider certification.

Nibiru · Who it serves

A trust layer for buyers, providers, agents, and markets.

Nibiru sits above raw compute supply: it makes outsourced work legible enough to buy, sell, audit, rank, and settle.

Compute providers

Add confidential proof-settled jobs to existing capacity without becoming a trusted counterparty.

Inference providers

Prove a committed model or policy version ran while protecting customer data and proprietary logic.

Markets and protocols

Release payment, update reputation, and settle disputes on receipts rather than logs.

Agents and auditors

Delegate external work and require a receipt before action, payment, or compliance sign-off.

Pay on receipts, not promises.

Confidential jobs - verified, not asserted.

Nibiru makes outsourced compute legible: private work in, private result out, portable receipt for verification, reputation, audit, and settlement.