Blindproof
Blindproof mask

Blindproof

The Private Inference Subnet

Larvatus prodeo — “I advance masked.” — Descartes

Miners run LLM inference on data they mathematically cannot read — and are paid only when a public proof confirms the work ran exactly right.

DETERMINISTIC · PROVEN · PRIVATE · SETTLED

Illustration: a blindfolded watchmaker assembling a movement by touch
01 / 06

The Problem

Trustless private inference does not exist.

Every AI service today can read your prompts.

The state of the art is hardware enclaves (TEEs). But enclaves don’t remove trust — they relocate it to the chip vendor and its supply chain.

There, the incentive to extract secrets is enormous, and the theft is a nearly perfect crime: the victim never learns how their secrets got out.

For these industries, “trust the chip” is exactly the trust that cannot be given:

  • Finance
  • Insurance
  • Defense
  • Healthcare
  • Law
02 / 06

The Solution

The Blindproof stack: four layers, each built on the one below.

One event, two money streams

A single verification moves both at once: the miner’s validator weight rises (emissions) and the client’s escrowed fee releases (revenue).

Subsidy and product settle on the same mathematical event.

Pick a tier:
  1. 4

    Settlement

    Verified on-chain in ~20 ms, before payment. Every job is checked, then paid — not sampled.

  2. 3

    Private inference

    Masked execution on the same verified rails: every value a miner holds is noise.

  3. 2

    Proven inference

    Each piece of computation carries a ZK proof that it produced exactly the canonical output.

  4. 1

    Deterministic inference

    Byte-identical execution across GPU types, so verification is a hash comparison.

03 / 06
Illustration: a workshop of blindfolded watchmakers at their benches
The machines that perform the compute never see a plain-text prompt or a plain-text answer.

How It Works

The client masks, goes offline, and returns to a verified answer.

  1. Masked prompt

    The client masks its prompt and submits. Every value a miner receives is noise.

  2. Deterministic execution

    Miners run the pinned open-weight model with byte-identical results across GPUs, so outputs compare directly.

  3. Proof per piece

    Each piece of computation carries a ZK proof. Validators run anchored checks and a cross-miner determinism vote.

  4. Settlement on verification

    Payment follows the proof, on every job. A false credit is slashable by any watcher for a bounty.

Every paid job leaves a proof bundle hashed on-chain.

04 / 06

The Benefit

Private inference is the difference between AI as a tool and AI as surveillance.

For the market

AI is moving into every meeting, inbox, calendar, and dataset. Once AI sees everything, private inference becomes the default requirement.

Microsoft’s CEO calls this the Reverse Information Paradox: enterprises pay for intelligence twice — once in fees, again in the proprietary knowledge their prompts reveal.

A business that prompts a frontier model teaches its vendor how it makes its money.

Most businesses, and nearly all individuals, cannot afford a GPU fleet on standby — and renting “confidential” hardware reopens the trust gap. On Blindproof, trust rests in proofs, not operators. A network whose machines cannot read the data has no operator to breach.

For Bittensor

Blindproof answers the hardest standing criticisms of the ecosystem.

TodayOn Blindproof
Verify, then payEmissions and fees move on trust, before anyone proves the work.Verification is the payment event.
Auditable revenueSubnet revenue is self-reported.The ledger is on-chain. Anyone can check it.
Real feesMany subnets run on emissions alone.Every job carries a customer fee from day one.
Deterministic scoringScoring is sampled and subjective.Weights are a deterministic function of public proofs.
05 / 06

The Team

Built by people who wouldn’t trust the chip.

Mark Gleason

Founder & CEO

Decades of senior AI leadership in regulated financial services, with a background spanning economics, computer science, and cybersecurity. Leads Paradatum’s work on deterministic, verifiable AI infrastructure — the foundation Blindproof runs on.

Jeanette Straughn

Co-founder

Co-founder of Paradatum. Builds the partnerships, operations, and company behind the protocol, turning verifiable private inference into a product regulated organizations can adopt.

Network
Live on Bittensor testnet, netuid 575
Code
blindproof-subnet on GitHub
Contact
info@paradatum.ai
06 / 06