The Shield System · N-O-Y-B

Private AI,
proven.

A privacy-first AI platform: an encrypted assistant, an agentic coding and data-analysis tool, and a document workspace — built to help companies work with AI without surrendering their data.

02

Three parties, one secret

Every AI must read your actual words to answer you — that's physics, not policy. The question is where that reading happens and who else can see it. Shield's answer: only inside a sealed vault, and no one. This architecture is shared by every tool in the system.

YOUR BROWSER

The only readable copy

Conversations, memories, documents, and settings live exclusively in your browser's IndexedDB. Your device encrypts every message with HPKE before it travels anywhere.

THE SERVER

A blind courier

Our relay routes sealed packages it cannot open. It strips your identity before forwarding, so even the AI never knows who's asking. Plaintext seen: zero bytes.

THE ENCLAVE

A sealed vault

Inference runs inside a Tinfoil attested hardware enclave — a room with no windows. Not even the server operator can observe what happens inside.

03

Verifiable privacy

AI is only as trustworthy as where your data goes. Shield AI lets you dial in the level of privacy each task needs — from fast standard inference to cryptographically verified, fails-closed confidentiality.

LEVEL 1

Frontier harness

The frontier platform runs inference through its own harness and provider safeguards — the fast path for everyday, lower-sensitivity work.

LEVEL 2

ShieldCode + ZDR

Inference runs through ShieldCode with Zero Data Retention — your prompts and outputs are not stored or retained by the provider.

LEVEL 3

ShieldCode + Verified Privacy

Inference executes in an attested enclave, end-to-end encrypted, with cryptographic proof verified at all points before any data is sent. If a check fails, it fails closed — no silent fallback.

One workflow, three levels. Switch the privacy tier per task — no change to your tools or process.
04

Don't trust. Verify.

Three independent checks, on demand.

Encryption is only as good as the system running it. Shield ships a verification panel that lets you confirm — cryptographically, not contractually — that every layer is behaving.

  • Client check. The code in your browser is hash-compared against a tamper-proof copy published on IPFS.
  • Proxy check. The server proves its privacy policy with a RISC Zero zero-knowledge receipt — math, not a pinky swear.
  • Enclave check. Hardware attestation confirms the AI environment is genuine and untampered before any data is sent.
If any check fails, your browser refuses to send. A failed attestation, a stale receipt, or a mismatched code hash stops the conversation before a single byte of your data moves.
05

Built on

HPKE / EHBP
Messages sealed in the browser with hybrid public-key encryption. The relay sees only ciphertext.
Tinfoil Enclave
Hardware-protected inference. The model reads your words inside a sealed environment nobody can observe.
Remote Attestation
A hardware-backed identity check your browser runs before sending anything, every session.
RISC Zero ZK
Zero-knowledge proofs that the relay followed its privacy policy — guaranteed by math, not key holders.
IndexedDB
All conversations and memories stored in your browser's database. No server-side copy exists.
sqlite-vec
An in-browser vector database powering context retrieval — semantic memory that never leaves your device.
IPFS Code Pins
Compiled app and source published to a content-addressed network so auditors can verify the build end-to-end.
Local Vault
Passphrase-encrypted storage at rest. No recovery backdoor — by design, nobody can unlock it but you.
06

Shield Code

An AI coding agent that proves its path.

Shield Code is an agent, not a chat wrapper: it reads your codebase, edits files, runs commands, and coordinates multi-step work — with native tooling geared to data analysis. Terminal UI, signed desktop app, or web; the same verified stack everywhere.

  • Three modes. Build for full-access development, Plan for read-only exploration, Research for deep search and multi-step work — across terminal, desktop, and web.
  • Shield Proxy. Sign in once with Google OAuth — no API keys to manage. Verified routes light up a green privacy verified badge once enclave attestation passes.
  • Fails closed. The direct Tinfoil path verifies Sigstore code identity and TEE measurement, pins TLS to the attested enclave, and wraps requests in HPKE. No proof, no traffic — there is no silent fallback.
  • Next: Fully Verified Privacy. Zero-knowledge session receipts and forwarding proofs, validated by a small pinned local verifier — the same receipt family as the Shield browser client.
Honest scope: today, privacy verified means an attested enclave path — strong transport and destination assurance. The full receipt-backed proof chain is the next layer, and the badge will not claim it until it ships.
07

Markdown Maru ◎

The reading room for AI output.

Agents write files faster than you can read them. Markdown Maru is the small, agile workspace where you keep up: a beautiful document viewer with a live file tree, a real terminal, and an editor — one lightweight native window on macOS, Windows, and Linux.

  • Renders everything on the fly. Markdown, Mermaid diagrams, HTML, CSV, Word, Excel, PowerPoint, PDF, and images — inline, no Office install.
  • Agent-aware. Watches the filesystem, silently reloads clean buffers when your AI edits files, and flags changes with git M/U decorations in the tree.
  • A real terminal, in context. A full PTY anchored to your project — run your coding agent at the bottom while you read its report at the top.
  • Native and small. Tauri, not Electron — with multi-tab sessions, multi-window projects, and 30+ themes.
08

Privacy without compromise

Shield Assistant is the daily driver of the system — and being private never means being less capable.

Documents stay home
PDF, Word, Excel, and PowerPoint parsed entirely in your browser. The file itself is never uploaded.
Personas
Five built-in communication styles plus your own custom personas — stored locally, invisible to the server.
Profile learning
Shield learns your preferences over time, on your device, through the same encrypted channel. Toggle it anytime.
Four languages
English, 日本語, Bahasa Indonesia, and 繁體中文 — translated in-app, no translation requests sent anywhere.
Mobile, identical
iOS and Android wrappers run the same code with the same protections. No mobile trade-offs.
Export everything
Download your conversations as JSON, entirely in-browser. Your data was always yours to take.
Honest limits: encryption can't protect a device that's already compromised, and a forgotten vault passphrase is unrecoverable — by design. We document every limitation in the User Privacy Guide, because trust you can't audit isn't trust.

09 — Access

None of your business.
Exactly as it should be.

The Shield System is currently in private access.