Partner with us

CustodianShared custody for sovereign AI.

Ship the Model.Keep the Keys.Stay Sovereign.

Deploy valuable AI models on sovereign and enterprise infrastructure. Model owners and customers retain independent key shares, with the key reconstructed inside the attested runtime once the agreed release checks pass.

Shared custody. Independent approvals. Verified release.

For model builders, sovereign AI and enterprise deployments.

SHARED CUSTODY2 OF 2
Model ownerIndependent key share
Deploying customerIndependent key share
CustodianCoordinates. Verifies. Records.0 key shares held
Attested runtime (TEE)Key reconstructed in protected runtime memory
2 / 2
ILLUSTRATIVE RELEASE TOPOLOGY↓ Sealed shares only
TESTED ON REAL HARDWAREIntel TDXAMD SEV-SNPNVIDIA H100NVIDIA RTX PRO 6000
Blackwell
See the scope of each validation

01 / THE ARRANGEMENT

Shared conditions.
Independent decisions.

A customer needs local control. A model builder needs enforceable release conditions. Custodian brings those requirements into one custody arrangement, with each holder checking for itself.

01

Agree before release.

The owner signs the policy. The approved model, runtime and release conditions become inputs each holder checks.

02

Verify at the boundary.

Each holder checks fresh evidence and seals its share to the attested workload’s transport key.

03

Keep permission bounded.

A quorum authorizes a lease. Renewals must satisfy the policy again, and time-bounded evidence limits that lease.

02 / BOTH SIDES OF THE AGREEMENT

Different interests.
A shared way forward.

For model builders expanding beyond their own cloud, and the sovereign and enterprise customers who need to run those models on theirs.

A

FOR MODEL BUILDERS

Let your model go further.

Set the conditions under which encrypted weights can be unlocked. Approve serving builds, govern derivative rights and retain a say in future releases.

  • Owner-side key splitting and provisioning
  • Signed model and release policies
  • Withdrawal of your share from future releases
B

FOR SOVEREIGN & ENTERPRISE AI

Bring the model to your boundary.

Participate in custody on infrastructure you control. Verify evidence independently and hold your own share in the release decision.

  • Customer-controlled shareholder service
  • Attested execution on approved infrastructure
  • Bounded policies for disconnected environments

A 2-of-2 arrangement gives each holder a veto. Availability, recovery and continuity terms must be agreed by both parties.

03 / PERMISSION IS CONDITIONAL

Two approvals.
One controlled release.

A valuable model. A sovereign customer. A GPU host outside the model owner’s control.

Follow the release, then change the conditions.

INTERACTIVE WALKTHROUGH

Illustration based on validation reports. No live attestation or key release.

Play the flow. Change a condition.

Model owner

Sets the release conditions

Awaiting verification

Deploying customer

Controls its own approval

Awaiting verification

Custodian

Coordinates the request

0key shares held
CUSTOMER-CHOSEN INFRASTRUCTUREThird-party host

Confidential runtime

Intel TDX guest · NVIDIA H100

Locked

Encrypted model weights await a release decision.

Build declaredEvidence pending

The host is outside the custody quorum. The broker never receives a plaintext key in this topology.

STEP 01 / 05Approved release

A runtime asks to start.

The workload declares its serving build and requests a session. Encrypted model weights remain locked while the release conditions are checked.

Holder approvals
0 / 2
Release decision
Pending
Custodian’s key shares
Always 0
BASED ON A HARDWARE RUN

The 17 September 2026 release used two remote holders, Intel TDX and an NVIDIA H100. All 16 required checks were reported verified.

Read the validation scope

Historical scope: the GPU measurement was not pinned. The measured filesystem was tested in a separate CPU run. Animation speed is illustrative.

Validation scope

QWEN ON BLACKWELL / 19 SEPTEMBER 2026

Real models. Tested control.

Follow a real model from encrypted weights to inference. Then see what happens when authorization ends.

Qwen3.5-35B-A3B-FP8Intel TDXNVIDIA RTX PRO 6000 Blackwell

Recorded-run illustration. No live GPU connection.

SHARE A

Model builder

Awaiting evidence

SHARE B

Deploying customer

Awaiting evidence

Custodian

Coordinates sealed shares · holds no share

↓ Both approvals required
VoltageGPU confidential VMModel locked

Intel TDX guest

Key reconstruction and model decryption occur in the guest release path.

Qwen3.5-35B-A3B-FP8

vLLM · NVIDIA RTX PRO 6000 Blackwell

Encrypted weights · inference not started

STEP 01 / 06Customer withdraws

Encrypted weights await permission.

Follow verification, share release, model loading and inference. Then change the conditions for authorization.

Three hardware scenarios passed

Expiry, customer withdrawal and broker outage each stopped inference and refused unauthorized restart.

View Qwen results
  1. 01 Request
  2. 02 Verify
  3. 03 Unlock
  4. 04 Generate
  5. 05 End authorization
  6. 06 Stop
Explore the recorded results and test setup
Lease expiry
1,996.10 ms
Customer withdrawal
2,337.52 ms
Broker outage
1,895.24 ms

Individual complete-shutdown observations, including GPU cleanup. Customer withdrawal is detected on renewal. Animation timing is illustrative; these observations are not a latency SLA.

The public Qwen model ran on a stock Intel TDX guest with a confidential Blackwell GPU. Both holder roles ran in the lab test process. This run exercised hardware-backed release and the inference lifecycle; separately administered holders and an owner-approved measured serving image were outside this run.

Each case generated output, stopped the worker, completed cleanup, confirmed output stopped changing, and refused restart without authorization.

Download the results summary

04 / EVIDENCE BEFORE ASSURANCE

Beyond the architecture.
Into the hardware.

Founder-run validation on confidential infrastructure. Dated results, negative cases and explicit limits—so a security team can examine what actually happened.

Explore the configuration, date and evidence behind each validation.

Read the assurance notes

FROM INSIGHTS / RESEARCH & VALIDATION

When Model Artifacts Change, Should Access Continue?

Explore three recorded GCP checks and what they establish about model-artifact integrity.

Read the Insight

THE CUSTODIAN DIFFERENCE

Local deployment.
Shared control.

The customer gets the infrastructure boundary they need. The model owner keeps a say in how the weights are released.

01

Each party has a say.

Independent holders verify the conditions for release. In a two-party arrangement, both must agree.

02

Permission has conditions.

Release is bound to approved runtimes and current evidence, with authorization that expires.

03

Custodian holds no key share.

Custodian coordinates the workflow. The parties retain their own shares in this arrangement.

Explore the validation evidence

Withdrawal stops future authorized releases. It does not remotely erase a key already in use.

OPEN FOUNDATION

Built on WCM.

Custodian builds on Weight Custody Manifest (WCM), the open specification and SDK from AgenTrust for model-weight custody.

PUBLISHED BY VOLTAGEGPU

Contributing to
confidential AI infrastructure.

Engineering contributions from Custodian founder Mohammed Zoheb Shaik, documented by VoltageGPU.

01 / VERIFICATION

Two proofs.
Independently reproduced.

Intel TDX and NVIDIA H200 attestation reproduced with his own verifier, a caller-generated nonce, and a separately sourced NVIDIA trust root.

Read the acknowledgment

02 / TIME

What a guest clock
can establish.

Real-hardware research into TDX and SEV-SNP clock differences relevant to time-limited authorization.

Read the findings

03 / RELIABILITY

Attestation
under concurrency.

Reported quote-generation failures, informing guidance to serialize requests and retry only on EINVAL.

Read the guidance

LET’S BUILD THIS TOGETHER

Become a
design partner.

Help shape how valuable AI
moves across trust boundaries.

Mohammed Zoheb ShaikFounder, Custodian · Dubai, United Arab Emirates

Work directly with the founder to shape your custody requirements.

Connect on LinkedIn

We’re looking for model builders, sovereign AI programs and enterprises with a real deployment challenge. Help shape Custodian around your requirements.

  • Shape the product roadmap
  • Evaluate a real custody workflow
  • Define success together
Explore a design partnership zoheb@custodylabs.co

Founder-led collaboration. Shared priorities. Clear milestones.