compute onwhat you can't see.
Void is a confidential AI network — run models on encrypted data with fully homomorphic encryption and zero-knowledge proofs, so prompts, data, and model weights stay hidden even from the nodes that compute them.
0x9f3a 7c1e 44b2 a0d5 88e70x31e8 b04f 92c7 d1a3 5f90✓ zk-snark · 0x…e9d2 · 1.2syour data never
leaves the void.
Fully homomorphic encryption means a node can run a model on your input without ever seeing it. The words below are encrypted — and the network still computed on them.
every job
comes with a receipt.
Each confidential job mints a zero-knowledge proof — the input, the model, and the output, verifiable by anyone, readable by no one.
encrypt, compute,
prove, verify.
encrypt
you encrypt your prompt, your data, and the model — locally, with your key.
cipher/fhecompute
nodes run the model on the ciphertext. they never see a single plaintext bit.
compute/runprove
a zk-snark proves the computation was correct — without revealing the inputs.
cipher/proofsverify
anyone checks the proof. only you can decrypt the result.
build/attestationthings you can't
run anywhere else.
medical records
run diagnostics on patient data no hospital would ever share.
financeprivate portfolios
inference on positions and trades without exposing the book.
legalprivileged documents
summarize case files that can't leave the firm.
weightsclosed model weights
serve a proprietary model without shipping the weights.
agentsautonomous agents
agents that reason over secrets and prove what they did.
identityzero-knowledge identity
verify who someone is without learning who they are.
2,318 nodes,
zero plaintext.
A global mesh of enclaves runs encrypted jobs and proves their work. No single node ever sees a full input, a full weight set, or a full output.
the enclave,
in hardware.
Photos via Pexels, credited below.





where the
void is going.
confidential inference + zk-snark receipts live
tune a model on data the trainer never reads
n parties compute on shared secrets, none of them see all
permissionless enclaves + $VOID staking on chain
short
answers.
is this really private?
Yes. Fully homomorphic encryption lets nodes compute on ciphertext directly — they process your data without ever decrypting it. The zero-knowledge proof then shows the computation was correct, still without revealing the input.
what can I run?
Any model that fits the enclave. Today that's up to 7B parameters for inference; encrypted fine-tuning and multi-party compute are on the roadmap.
how is a wrong result caught?
Every job mints a zk-snark. If a node fakes an output, the proof won't verify, the node loses its stake, and the job reruns on honest enclaves.
who can see my data?
Only you, with your key. Not the nodes, not the protocol, not the network operator. Void is designed so the operator can't read your traffic even if they wanted to.
the model never
sees the secret.
Run AI on the data you could never hand over. Everything else is just a server.