Agree before release.
The owner signs the policy. The approved model, runtime and release conditions become inputs each holder checks.
CustodianShared custody for sovereign AI.
Deploy valuable AI models on sovereign and enterprise infrastructure. Model owners and customers retain independent key shares, with the key reconstructed inside the attested runtime once the agreed release checks pass.
Shared custody. Independent approvals. Verified release.
For model builders, sovereign AI and enterprise deployments.
01 / THE ARRANGEMENT
A customer needs local control. A model builder needs enforceable release conditions. Custodian brings those requirements into one custody arrangement, with each holder checking for itself.
The owner signs the policy. The approved model, runtime and release conditions become inputs each holder checks.
Each holder checks fresh evidence and seals its share to the attested workload’s transport key.
A quorum authorizes a lease. Renewals must satisfy the policy again, and time-bounded evidence limits that lease.
02 / BOTH SIDES OF THE AGREEMENT
For model builders expanding beyond their own cloud, and the sovereign and enterprise customers who need to run those models on theirs.
FOR MODEL BUILDERS
Set the conditions under which encrypted weights can be unlocked. Approve serving builds, govern derivative rights and retain a say in future releases.
FOR SOVEREIGN & ENTERPRISE AI
Participate in custody on infrastructure you control. Verify evidence independently and hold your own share in the release decision.
A 2-of-2 arrangement gives each holder a veto. Availability, recovery and continuity terms must be agreed by both parties.
03 / PERMISSION IS CONDITIONAL
A valuable model. A sovereign customer. A GPU host outside the model owner’s control.
Follow the release, then change the conditions.
Sets the release conditions
Awaiting verificationControls its own approval
Awaiting verificationCoordinates the request
Intel TDX guest · NVIDIA H100
Encrypted model weights await a release decision.
The host is outside the custody quorum. The broker never receives a plaintext key in this topology.
The workload declares its serving build and requests a session. Encrypted model weights remain locked while the release conditions are checked.
The 17 September 2026 release used two remote holders, Intel TDX and an NVIDIA H100. All 16 required checks were reported verified.
Read the validation scopeHistorical scope: the GPU measurement was not pinned. The measured filesystem was tested in a separate CPU run. Animation speed is illustrative.
Validation scopeQWEN ON BLACKWELL / 19 SEPTEMBER 2026
Follow a real model from encrypted weights to inference. Then see what happens when authorization ends.
Awaiting evidence
Awaiting evidence
Coordinates sealed shares · holds no share
Key reconstruction and model decryption occur in the guest release path.
vLLM · NVIDIA RTX PRO 6000 Blackwell
Encrypted weights · inference not started
Follow verification, share release, model loading and inference. Then change the conditions for authorization.
Expiry, customer withdrawal and broker outage each stopped inference and refused unauthorized restart.
View Qwen resultsIndividual complete-shutdown observations, including GPU cleanup. Customer withdrawal is detected on renewal. Animation timing is illustrative; these observations are not a latency SLA.
The public Qwen model ran on a stock Intel TDX guest with a confidential Blackwell GPU. Both holder roles ran in the lab test process. This run exercised hardware-backed release and the inference lifecycle; separately administered holders and an owner-approved measured serving image were outside this run.
Each case generated output, stopped the worker, completed cleanup, confirmed output stopped changing, and refused restart without authorization.
Download the results summary04 / EVIDENCE BEFORE ASSURANCE
Founder-run validation on confidential infrastructure. Dated results, negative cases and explicit limits—so a security team can examine what actually happened.
Remote holders verified an Intel TDX guest and NVIDIA H100 before returning sealed shares. All 16 checks required by that manifest were reported verified.
A pinned, read-only dm-verity root extended the CPU release path to the runtime’s filesystem. Holder links used pinned TLS certificates.
Lease expiry is clamped to the earliest applicable evidence deadline, including vendor validity and the owner’s freshness policy.
Three authorization-loss scenarios. Inference stopped and unauthorized restart was refused.
Explore the Qwen run H100 / 23 SEP 2026Mistral and Llama Nemotron. Six controlled scenarios across lease expiry, withdrawal and broker outage.
Explore the H100 runsExplore the configuration, date and evidence behind each validation.
Read the assurance notesFROM INSIGHTS / RESEARCH & VALIDATION
Explore three recorded GCP checks and what they establish about model-artifact integrity.
THE CUSTODIAN DIFFERENCE
The customer gets the infrastructure boundary they need. The model owner keeps a say in how the weights are released.
Independent holders verify the conditions for release. In a two-party arrangement, both must agree.
Release is bound to approved runtimes and current evidence, with authorization that expires.
Custodian coordinates the workflow. The parties retain their own shares in this arrangement.
Withdrawal stops future authorized releases. It does not remotely erase a key already in use.
OPEN FOUNDATION
Custodian builds on Weight Custody Manifest (WCM), the open specification and SDK from AgenTrust for model-weight custody.
PUBLISHED BY VOLTAGEGPU
Engineering contributions from Custodian founder Mohammed Zoheb Shaik, documented by VoltageGPU.
01 / VERIFICATION
Intel TDX and NVIDIA H200 attestation reproduced with his own verifier, a caller-generated nonce, and a separately sourced NVIDIA trust root.
Read the acknowledgment02 / TIME
Real-hardware research into TDX and SEV-SNP clock differences relevant to time-limited authorization.
Read the findings03 / RELIABILITY
Reported quote-generation failures, informing guidance to serialize requests and retry only on EINVAL.
Read the guidanceLET’S BUILD THIS TOGETHER
Help shape how valuable AI
moves across trust boundaries.
Work directly with the founder to shape your custody requirements.
Connect on LinkedInWe’re looking for model builders, sovereign AI programs and enterprises with a real deployment challenge. Help shape Custodian around your requirements.
Founder-led collaboration. Shared priorities. Clear milestones.