Partner with us

THE ASSURANCE NOTES / UPDATED 23 SEP 2026

Trust starts with
what you can check.

Specific tests establish specific facts. Explore Custodian’s validation results and the scope of each configuration.

Hardware validationRelease evidenceDeployment scope

HARDWARE VALIDATION / 23 SEPTEMBER 2026

More models. The same custody principle.

Custodian ran Mistral 7B Instruct v0.3 and Llama 3.1 Nemotron Nano 8B v1 with vLLM inside a VoltageGPU Intel TDX guest with an NVIDIA H100 80 GB in confidential mode. CPU and GPU evidence was checked before the lab release.

Two models. Six controlled scenarios passed.

Each case passed an instruction-output check and generated model output before the trigger. The worker then stopped, output stopped changing, and restart without authorization was refused.

Observed worker exit after deadline or trigger
ScenarioMistral 7BNemotron Nano 8B
Shortened lease expiry678.39 ms688.55 ms
Customer withdrawal at renewal22,421.19 ms22,724.21 ms
Broker outage on renewal679.84 ms675.08 ms

Withdrawal is enforced through renewal; its timing includes the renewal request and evidence checks. These are individual observations of worker exit, not instantaneous revocation or a latency SLA. The Qwen run below measured a different endpoint: complete shutdown including cleanup.

Test configuration

Two holder roles ran in the same lab process, with a loopback broker under one administrative account. Public model checkpoints were encrypted for the custody flow and decrypted into private memory-backed storage with swap disabled. The expiry case shortened a live lease; the other cases applied withdrawal or broker unavailability on renewal.

This run validates hardware-backed release and supervised inference behavior for these configurations. Independently administered organizations, an owner-approved immutable serving image, sustained renewal and recovery, and the full Kubernetes/Kata/Trustee integration are separate validation milestones. Worker exit and cleanup observations do not establish physical GPU-memory erasure.

Selected results from Custodian’s 23 September 2026 H100 hardware evaluation.

Download the results summary

Explore the H100 walkthrough

HARDWARE VALIDATION / 19 SEPTEMBER 2026

Real inference. Tested control.

Custodian ran Qwen3.5-35B-A3B-FP8 with vLLM on an NVIDIA RTX PRO 6000 Blackwell Server Edition GPU in confidential mode, inside an Intel TDX guest supplied by VoltageGPU. Fresh CPU and GPU evidence was checked before the lab release.

Three authorization-loss scenarios passed

Each case generated real model output before the trigger, stopped the worker, completed its cgroup cleanup, confirmed output stopped changing, and refused restart without authorization.

Observed complete shutdown after trigger or deadline
ScenarioObservation
Authenticated lease expiry1,996.10 ms
Customer withdrawal at renewal2,337.52 ms
Broker outage during renewal1,895.24 ms

These are individual controlled observations, including kernel and GPU cleanup, not a latency SLA. Customer withdrawal is observed at renewal or expiry. Each scenario used one short generation; this was not a sustained load test.

The matching Linux test suite recorded 509 passed and zero skipped. Separate hardware checks rejected a wrong GPU nonce, report tampering, a missing certificate chain and a changed GPU measurement pin. NVIDIA’s remote v4 attestation and policy validation also succeeded as a separate diagnostic.

Test configuration and interpretation

The model is public test data: 35 billion total parameters, 3 billion active, FP8. Decrypted checkpoints used private memory-backed storage, with swap disabled. Public source weights and the lab preparation key were present on the rented VM; this run does not establish that all copies of weights or keys existed only in memory.

Both holder roles ran in the lab test process. The stock guest did not establish an owner-approved dm-verity serving image. The run tests hardware-backed release and supervised inference lifetime; separately administered parties, host-resistant time and complete physical memory erasure require their own evidence.

The NVIDIA vendor-service check was a separate diagnostic, not a continuously refreshed requirement in this release path. The Blackwell run and earlier H100 and measured-image runs used different configurations and should be read separately.

Source: Custodian Blackwell validation, 19 September 2026; archived Qwen lifecycle result, final Linux test report and hardware evidence. The summary below contains selected public results; raw infrastructure captures are not published.

Download the results summary

Explore the Qwen walkthrough

GCP CPU VALIDATION / 23 SEPTEMBER 2026

Tamper-Resistance Validation.

A controlled GCP CPU evaluation exercised Custodian’s encrypted model-bundle checks and Linux dm-verity using synthetic model files and a disposable 8 MiB data image.

  • Modified ciphertext: bundle opening was refused and partial plaintext output was removed.
  • Model identity mismatch: a bundle was refused when the supplied expected inventory digest did not match it.
  • Corrupted filesystem block: verification failed and the kernel refused the affected read with an I/O error.

Original inputs succeeded. Restoring the original ciphertext and data-image bytes restored successful opening or reading.

Test Configuration and Scope

The filesystem test used a disposable read-only data mapping, not the VM’s boot disk. The identity check supplied a mismatched expected digest; it was not a fine-tuning experiment. No fresh TDX evidence, GPU inference or protected GPU-serving image was part of this run.

These observations establish the tested integrity checks. They do not establish resistance to an administrator inside a running GPU guest or control over plaintext weights already copied outside the approved runtime.

Selected observations from Custodian’s recorded 23 September 2026 GCP CPU integrity evaluation. Detailed internal debugging records are not part of this public summary.

Read the Insight and Explore the Checks

01 / 17 SEPTEMBER 2026

A confidential GPU release.

A founder-run test on an NVIDIA H100 in confidential mode, inside an Intel TDX guest, used two remote holders. Each verified CPU and GPU evidence against its own challenge before returning a sealed share. The report records 16 required checks verified, with two checks not required by that manifest.

What this establishes

A working composite CPU/GPU release path, independent holder verification, and nonce-bound NVIDIA revocation checks for the supported certificates.

What it does not establish

The GPU measurement was not pinned to an approved value. The run did not include the later dm-verity image hardening. One H100 configuration does not establish multi-GPU, NVSwitch or Blackwell coverage.

NVIDIA did not provide a revocation answer for the FMC signing leaf in the captured tests. A GOOD answer for the per-device BROM certificate does not establish the signing leaf’s own revocation status. Older report wording was narrowed on 19 September.

The validation pack also records negative build tests: a second, different build on the same boot was refused, as was a genuine quote from another TDX guest claiming a build it had not recorded. The website walkthrough simplifies these into its changed-build scenario.

Source: Custodian NVIDIA Confidential GPU Assurance and Validation Pack; captures from 17 September 2026. These are historical results, not live device status.

02 / 18 SEPTEMBER 2026

Bind the release to the image.

A separate Intel TDX run booted from a read-only dm-verity root filesystem. The owner pinned the boot chain, including the kernel command line carrying the root hash. The release path incorporated the pinned image hash, and a write to the runtime code was refused by the kernel.

Also exercised

Pinned TLS connections to holders and monotonic owner-signed provisioning counters. Replaying an older counter was refused.

Remaining work

The image was sealed from a running guest rather than produced by a reproducible, clean build. This run had no GPU. A single run combining approved GPU measurements, the measured image and all subsequent changes remains a validation milestone.

Source: Custodian Hardening Report, 18 September 2026; associated rootfs and release captures.

03 / 19 SEPTEMBER 2026

Evidence cannot authorize forever.

The implementation now carries evidence deadlines from vendor checks through holders and quorum aggregation to lease creation. The lease is shortened to the earliest applicable deadline; reusing the same answer cannot restart the freshness window.

Code and captured-data validation

The evidence-window report describes 17 tests, six mutation checks and calculations against real vendor captures. It explicitly records that this change had not yet run through a release on the live estate.

Disconnected does not mean indefinitely offline

Imported evidence still expires. The captured NVIDIA OCSP answers had 24-hour validity. Delivery cadence must allow margin before the applicable expiry, and the holder’s trusted-time assumptions must be reviewed.

Source: Custodian Evidence Window, 19 September 2026. Full runtime deadline propagation remains part of production qualification.

04 / 19 SEPTEMBER 2026

Separation must be operational, too.

The latest deployment record moves both holders to AMD SEV-SNP confidential VMs, with party keys generated on each holder and pinned TLS links to the broker.

Deployment is not counterparty verification

The record says holder attestation reports were produced but not appraised by counterparties. Both holders still shared one cloud project, and one founder administered the test estate. These tests therefore do not establish independence between mutually distrustful organizations.

A production arrangement needs distinct administrative control, verified holder identity, protected storage and backup, and agreed recovery procedures. Custodian’s zero-share operator topology depends on those deployment choices.

Source: repository evidence record, “The shareholders moved onto confidential hardware,” 19 September 2026.

DESIGN PARTNERS / BUILD WITH US

Help shape what comes next.

Have a model that needs to run across a trust boundary? We’re inviting model builders, sovereign AI programs and enterprises to become design partners.

Mohammed Zoheb ShaikFounder, Custodian · Dubai, United Arab Emirates

Work directly with the founder to shape your custody requirements.

Connect on LinkedIn
Explore a design partnership

Partnerships begin with a scoped technical evaluation. Detailed reports and captures are shared as part of that discussion.