Trust, replaced by proof

Privacy by proof,
not by promise.

Most AI providers protect your data with a policy — words in a document you can't check. WeAI is a native macOS client where the guarantee is cryptographic: every connection verifies a hardware attestation before a single byte of plaintext leaves your Mac, and the decryption keys live inside the enclave — so nobody in the middle can inspect your data. Even if they wanted to.

macOS 14+ · Apple Silicon v0.1.9 · 23 MB SHA-256 pinned below
weai · secure channel ATTESTING
$weai connect swiss-ai/apertus-70b
requesting attestation reportreceived
verifying vendor signatureok · AMD SEV-SNP
enclave measurementmatch
binding session key to enclavepinned
decryption keysenclave-only
# any mismatch ⇒ refused — nothing sent
channel sealed — plaintext may now leave this Mac
verification runs in the client, on your machine — before any prompt is transmitted
Speaks to
TinfoilTEE 0Gweb3 io.netweb3 Hyperbolicweb3 Veniceweb3 Akashweb3 LM Studiolocal Ollamalocal
§ 01Policy vs. proof

Two kinds of “we can't see your data.”
Only one can be checked.

The words are identical. What stands behind them is not.

The policy model
“We do not train on your data. Your conversations are private.”

A sentence in a privacy policy. You can't verify it, you can't enforce it, and you'd never know if it were quietly broken — by an employee, an acquisition, a subpoena, or a breach. The provider holds the keys; you hold a promise.

TRUST REQUIRED · UNVERIFIABLE
The proof model
“Here is a signed hardware attestation. Check it yourself — before you send anything.”

With WeAI and attested backends like Tinfoil, the enclave proves — cryptographically, per connection — exactly what code is running and that decryption keys exist only inside its boundary. Your client checks the proof first. If it doesn't hold, no plaintext is sent. Not a promise. A protocol.

TRUST REMOVED · VERIFIED CLIENT-SIDE

No proof, no plaintext.

The one rule WeAI never bends: attestation is verified before transmission, or the prompt stays on your Mac. There is no fallback, no “send anyway,” no silent downgrade.

verify(attestation) == expected_measurement  ∥  abort()

§ 02The handshake

How a connection earns your prompt

Four checks, executed by the client on your machine. Each one can kill the connection; all four must pass before anything leaves.

01

Demand the report

The enclave must produce an attestation report — a statement of the exact code and hardware state it is running — signed by the silicon itself (AMD SEV-SNP, Intel TDX, NVIDIA CC).

No report → no connection.

02

Check the measurement

The report's code measurement is compared against the expected, auditable build of the inference stack. A provider can't swap in logging code without changing the measurement.

Mismatch → connection refused.

03

Pin keys to the enclave

The session key is bound into the attested boundary. Decryption keys are generated and held inside the enclave — they never exist on any disk, in any log, or in any operator's hands.

Keys outside → impossible by construction.

04

Send — sealed

Only now does plaintext leave your Mac, encrypted end-to-end into the enclave. Anyone in between — networks, clouds, us — sees ciphertext and nothing else.

Recorded traffic stays ciphertext.

§ 03Choose your trust level

One client. Four ways to run.
Trust is always labeled.

Every provider in WeAI carries an explicit trust class in the UI — you always know exactly who could, in principle, see a prompt. For many of them the honest answer is: no one.

Local

LM Studio, Ollama or the built-in engine, on your own Apple Silicon. Nothing leaves the machine — the strongest privacy there is.

Trust requiredNone. It's your hardware.

Friend mesh

Borrow a friend's GPU over a mutually-authenticated, post-quantum SecureChannel (X25519 + ML-KEM-768). Invites are Ed25519-signed; relays only ever carry ciphertext.

Trust requiredPeople you explicitly invited.

Attested cloud

Frontier-scale models inside hardware enclaves — e.g. Tinfoil. Attestation verified before plaintext, keys sealed inside. Cloud convenience without cloud trust.

Trust requiredThe silicon — and math.

Web3 / decentralized

Open compute markets — 0G, io.net, Hyperbolic, Venice, Akash, Chutes. No single company in the loop; WeAI labels exactly what is and isn't verifiable per provider.

Trust requiredDistributed operators, labeled honestly.

Any OpenAI-compatible tool can ride along: point Cursor, Continue or your SDK at http://127.0.0.1:4380/v1 and it inherits the same verified routing.

§ 04Your data at rest

The strongest promise is the one
you don't have to make.

WeAI's default is to write nothing down. Everything below is opt-in, disclosed before you turn it on, and reversible — and where it isn't reversible, we say so first.

wDrive

Files encrypted on your Mac before they go anywhere, content-addressed and anchored to 0G by merkle root — so anyone can verify the bytes without being able to read them. Chunk dedup, version history, shared vaults, and a verifier page that uses none of our code.

Trust requiredNone for reading. Math for the rest.

Conversation history

Off by default — with it off, your chats live in memory and are gone at quit. Switch it on and threads are sealed under a key held in your Keychain combined with your passphrase. Neither factor alone opens anything. Changing the passphrase re-wraps 32 bytes; it never re-encrypts the archive.

Trust requiredYour Mac, and your memory.

No public keys at rest

Nothing stored on disk is protected by RSA, P-256 or X25519 — the algorithms a future quantum computer breaks. Harvest now, decrypt later attacks stored data through its key wrapping, and symmetric AEAD is not in that category. The property is achieved by subtraction, so there is no hybrid to get wrong.

Trust requiredChaCha20-Poly1305, and nothing else.

Publishing a replica to 0G is permanent and public. It is unreadable without your passphrase — that is the whole protection — but it can never be recalled, only left unopened. WeAI tells you this before the first push, not after.

§ 05Side by side

Policy cloud vs. WeAI

Same question — “who can read my prompts?” — answered structurally.

Typical AI cloud WeAI + attested backend
The guarantee A privacy policy. Revocable, unverifiable, changes with a legal-page edit. Hardware attestation, cryptographically verified on every connection.
Who can read prompts Provider staff, compromised insiders, acquirers, anyone with a subpoena or a breach. No one outside the enclave boundary — the operator included.
Verification None offered. You are asked to believe. Client-side, before any plaintext is transmitted. Fail = refuse.
Key custody Provider-managed keys; decryption happens on their servers, under their control. Decryption keys exist only inside the attested enclave.
Local models First-class: LM Studio, Ollama, built-in engine. Zero bytes leave the Mac.
Peer-to-peer compute Borrow a friend's GPU over a post-quantum channel (X25519 + ML-KEM-768).
Client A closed web page you re-download on every visit. Native macOS app with a documented architecture and an honest, public threat model.
§ 06Get WeAI

Download. Verify. Then trust.

Practice what the product preaches: check the artifact's SHA-256 before you run it.

WeAI for macOS

Native SwiftUI app for Apple Silicon. Ships with a zero-setup demo engine — useful in the first ten seconds, verifiable ever after.

v0.1.9 macOS 14+ Apple Silicon (arm64) 23 MB dmg
SHA-256 · WeAI.dmg
f5110a7e6743a0224a3d8267d86f93ed553cd03d42bf664be1b80760726223df
# verify before first launch
$ shasum -a 256 ~/Downloads/WeAI.dmg
# must print f5110a7e…0726223df — anything else: delete it
Developer ID signed, notarization pending — first launch: right-click →  Open (macOS 15+: System Settings → Privacy & Security → Open Anyway) Prefer to compile it yourself? ./scripts/bundle.sh Windows & Linux: on the roadmap — macOS first, done right
§ 07Questions, answered straight

FAQ

Q·01What does a hardware attestation actually prove?
It's a statement signed by the CPU/GPU vendor's silicon (AMD SEV-SNP, Intel TDX, NVIDIA Confidential Computing) that says: this exact code, with this exact measurement, is running inside an isolated enclave whose memory even the host operating system and the cloud operator cannot read. Your client compares that measurement against the expected build. Software alone can't forge it — the signature chain roots in the hardware.
Q·02What happens when a backend can't produce an attestation?
Then WeAI never pretends otherwise. Every provider carries an explicit trust class in the UI — local, friend mesh, attested (TEE), web3, or policy-trust aggregator — so an unverifiable endpoint is visibly labeled as one. The “no proof, no plaintext” rule applies to the attested class; for everything else you decide with open eyes, and local inference is always one click away.
Q·03Can WeAI itself read my prompts?
No — structurally. WeAI is a client that runs on your Mac; there is no WeAI server in the request path. Prompts go from your machine directly to the backend you chose: your own GPU, a friend's node over an end-to-end encrypted channel, or an attested enclave. Keys live in your macOS Keychain and in the enclave — never with us. We couldn't build a log of your conversations if we tried, and that's the point.
Q·04Is it quantum-safe?
The friend-mesh SecureChannel uses a hybrid X-Wing key exchange — X25519 plus ML-KEM-768 — so a session recorded today stays secret unless both elliptic-curve and lattice cryptography fall. That defeats “harvest now, decrypt later.” Only vetted, standardized primitives via Apple CryptoKit; no custom crypto anywhere.
Q·05How is this different from just using Tinfoil directly?
Tinfoil is one excellent backend; WeAI is the native client above all of them. You get attested cloud enclaves when you need frontier scale, your own hardware when you don't, a post-quantum friend mesh in between, and web3 markets when you want no single company in the loop — one app, one API (127.0.0.1:4380/v1), with the trust level of every route labeled.
Q·06Is this production-ready?
It's an experimental preview, and we document it like one: the architecture & threat-model pages label every single claim as implemented or planned — including what is not secured yet. We'd rather earn trust the same way the protocol does: by being checkable.
ATTESTATION DOSSIER · EXAMPLE SESSION

Sealed & verified — the full story

weai · 0G attested node · swiss-ai/apertus-70b · AMD SEV-SNP + H100 CC

Backend0G · marketplace of independent GPU providers, each in a TEE
Modelswiss-ai/apertus-70b — open weights, so any node can serve it
EnclaveAMD SEV-SNP · NVIDIA H100 confidential-computing mode
ChannelX25519 → HKDF-SHA256 → ChaCha20-Poly1305
Verifiedclient-side, before any plaintext left this Mac
Retentionzero — by construction, not by policy

§ A · The 0G key exchange

  1. 01The 0G node boots the open inference stack inside an enclave; SEV-SNP measures every byte of it.
  2. 02Inside that boundary the enclave generates an ephemeral X25519 keypair — the private half physically cannot leave.
  3. 03The public half is bound into the attestation report, signed by the silicon itself (VCEK → ASK → ARK, rooted in AMD).
  4. 04WeAI verifies the signature chain and checks the measurement against the expected open build — a mismatch kills the connection here.
  5. 05Only then: ECDH over X25519, keys derived via HKDF-SHA256, one ChaCha20-Poly1305 key per direction.
  6. 06Custody: your Mac's memory and the enclave's memory. Never on disk, never in a log — and never with the 0G node operator, who relays ciphertext only.

§ B · How the inference ran

  1. 01Your prompt was encrypted on this Mac and sent as sealed frames — each one AEAD-authenticated and sequence-bound, so nothing can be replayed or reordered.
  2. 02Decryption happened only past the attested boundary; the H100 ran in confidential-computing mode with encrypted GPU memory.
  3. 03apertus-70b generated the answer in place; tokens streamed back through the same sealed channel, encrypted before they left the enclave.
  4. 04On session close both sides dropped their keys — traffic recorded on the wire today stays ciphertext.
  5. 05Nothing persisted: no plaintext at rest, no prompt logs, nothing for an operator, acquirer or subpoena to read.

Illustrative protocol transcript, not a record of a real session — it shows the mechanism WeAI enforces. 0G's own curated catalogue today centres on models like DeepSeek v3, Qwen3.6 and GLM-5; Apertus is open-weights and reaches you via Swisscom, the Public AI network, Hugging Face or your own hardware. Every claim is labeled implemented vs planned in the architecture & threat model.