Blindproof
Blindproof mask

Blindproof

The Private Inference Subnet

Larvatus prodeo — “I advance masked.” — Descartes

Miners run LLM inference on data they mathematically cannot read — and are paid only when a public proof confirms the work ran exactly right.

Get early access →Miners, validators, and design partners: join before the subnet opens to outside miners in Q1 2027.

DETERMINISTIC · PRIVATE · PROVEN · SETTLED

Illustration: a blindfolded watchmaker assembling a movement by touch
01 / 07

The Problem

Trustless private inference does not exist.

Every AI service today can read your prompts.

The state of the art is hardware enclaves (TEEs). But enclaves don’t remove trust — they relocate it to the chip vendor and its supply chain.

There, the incentive to extract secrets is enormous, and the theft is a nearly perfect crime: the victim never learns how their secrets got out.

For these industries, “trust the chip” is exactly the trust that cannot be given:

  • Finance
  • Insurance
  • Defense
  • Healthcare
  • Law
02 / 07

The Solution

The Blindproof stack: four layers, each built on the one below.

One event, two money streams

A single verification moves both at once: the miner’s validator weight rises (emissions) and the client’s escrowed fee releases (revenue).

Subsidy and product settle on the same mathematical event.

Pick a tier:
  1. 4

    SettlementTestnet

    Every job is checked, then paid — not sampled. Weights settled on testnet on 5 Oct 2026; fee escrow is designed.

  2. 3

    Private inferenceResearch

    Masked execution on the same verified rails: every value a miner holds is noise.

  3. 2

    Proven inferencePrototype

    Each piece of computation carries a ZK proof that it produced exactly the canonical output.

  4. 1

    Deterministic inferenceMeasured

    Byte-identical execution across GPU types, so verification is a hash comparison.

03 / 07
Illustration: a workshop of blindfolded watchmakers at their benches
The machines that perform the compute never see a plain-text prompt or a plain-text answer.

How Blindproof Works

The design: the client masks, goes offline, and returns to a verified answer.

  1. Masked prompt

    The client masks its prompt and submits. Every value a miner receives is noise.

  2. Deterministic execution

    Miners run the pinned open-weight model with byte-identical results across GPUs, so outputs compare directly.

  3. Proof per piece

    Each piece of computation carries a ZK proof. Validators run anchored checks and a cross-miner determinism vote.

  4. Settlement on verification

    Payment follows the proof, on every job. A false credit is slashable by any watcher for a bounty.

Every paid job leaves a proof bundle hashed on-chain.

On testnet so far: steps 2 and 4 have settled end to end on Bittensor testnet with mock inference and mock proofs. Masking runs in off-chain prototypes. See the evidence · See the roadmap

04 / 07

The Benefit

Private inference is the difference between AI as a tool and AI as surveillance.

For the market

AI is moving into every meeting, inbox, calendar, and dataset. Once AI sees everything, private inference becomes the default requirement.

Microsoft’s CEO calls this the Reverse Information Paradox: enterprises pay for intelligence twice — once in fees, again in the proprietary knowledge their prompts reveal.

A business that prompts a frontier model teaches its vendor how it makes its money.

Enterprises need proof, privacy, and determinism before they can use Bittensor. Individuals need private AI that can’t be sold. Why now: enterprises and individuals

Most businesses, and nearly all individuals, cannot afford a GPU fleet on standby — and renting “confidential” hardware reopens the trust gap. On Blindproof, trust rests in proofs, not operators. A network whose machines cannot read the data has no operator to breach.

For Bittensor

Blindproof answers the hardest standing criticisms of the ecosystem. Read our answer to the TAO bear case.

TodayOn Blindproof
Verify, then payEmissions and fees move on trust, before anyone proves the work.Verification is the payment event.
Auditable revenueSubnet revenue is self-reported.The ledger is on-chain. Anyone can check it.
Real feesMany subnets run on emissions alone.Every job carries a customer fee from day one.
Deterministic scoringScoring is sampled and subjective.Weights are a deterministic function of public proofs.
05 / 07

The TAO Bear Case

Critics say Bittensor shows supply but can’t prove real demand. Blindproof answers them four ways.

  1. Don’t just compete on cheap tokens.

    Sell deterministic, private, verifiable compute: something commodity inference cannot easily provide.

  2. Make every paid job provable.

    Every customer job is tied to a verifiable on-chain record.

    The proof becomes the invoice.

  3. Make real demand visible.

    Put customer fees alongside network subsidies in public. Anyone can see how much activity comes from real customers versus network incentives, and judge whether genuine demand is emerging.

  4. Make decentralization a privacy advantage.

    Centralized compute requires customers to trust one provider with enough information to potentially reconstruct the whole workload.

    With decentralized, masked compute, the workload can be split across independent nodes so that no single participant has the complete picture. The information needed to reconstruct the whole workload is distributed across the network.

    Splitting the workload makes decentralized compute a credible privacy advantage over centralized compute: not simply because the data is masked, but because no single party has the complete picture.

The result

Blindproof doesn’t just help Bittensor prove that customers are buying compute. Blindproof gives that compute a differentiated reason to exist: private, verifiable computation that benefits from being decentralized.

Read the full bear case

06 / 07

The Team

Built by people who wouldn’t trust the chip.

Mark Gleason

Founder & CEO

Decades of senior AI leadership in regulated financial services, with a background spanning economics, computer science, and cybersecurity. Earlier, a software engineer on defense research programs, a cybersecurity researcher at the Naval War College, and inventor of DBX, a high-speed analytics database engine. Leads Paradatum’s work on deterministic, verifiable AI infrastructure — the foundation Blindproof runs on.

Jeanette Straughn

Co-founder

Co-founder of Paradatum. A former global head of data governance, with deep experience in audit, compliance, and ontology engineering. Builds the partnerships, operations, and company behind the protocol, turning verifiable private inference into a product regulated organizations can adopt.

Contact
info@paradatum.ai
07 / 07