Eltanin

Compute Zero Trust / Experimental MVP

No protected compute
without authorization.

Evaluate a local authorization path for scoped, expiring compute leases. Read the evidence before choosing a protection boundary.

Try the authorization walkthrough

MVP 1.0 is in progress. Linux/NVIDIA device-level protection remains unvalidated; Apple functional evidence does not satisfy that gate.

Three evidence classes. Three distinct meanings.

E1 / Pure & simulated

Deterministic correctness

Fake-backend tests exercise policy, leases, local IPC and the ALLOW/DENY launch path. They provide no accelerator or device-protection evidence.

E2 / Physical Apple Silicon

Real accelerator function

Physical M3 Max evidence covers discovery, real Metal compute and managed application-level ALLOW/DENY flow. DeviceEnforce and DeviceRevoke remain unsupported or not evaluated.

E3 / Bare-metal Linux + NVIDIA

Device protection gate

The required device-level enforcement evidence is still pending. E2 cannot replace it; an Apple-only PASS remains blocked on E3.

Authorize locally. Explain locally.

The evaluable path uses OS-observed caller identity, default-deny policy, a scoped lease and a supervised workload launch. Local audit records explain decisions; telemetry is not authorization authority. Cloud is absent from the per-compute hot path.

The quickstart uses a fake backend and harmless echo workload. It verifies authorization, not GPU enforcement. Launcher identity is distinct from workload executable identity; the current limitations are documented.

Read the supported security boundary

Evaluate within the current scope

Source builds and the authorization walkthrough support Linux and Apple Silicon macOS. There is no polished installer or hosted service. Windows, AMD/Intel, enterprise fleet governance and production-grade privileged-attacker resistance are outside this MVP.

Installation, policy, limitations & evidence · Evaluation questions · Report a vulnerability privately