E1 / Pure & simulated
Deterministic correctness
Fake-backend tests exercise policy, leases, local IPC and the ALLOW/DENY launch path. They provide no accelerator or device-protection evidence.
Compute Zero Trust / Experimental MVP
Evaluate a local authorization path for scoped, expiring compute leases. Read the evidence before choosing a protection boundary.
Try the authorization walkthrough
MVP 1.0 is in progress. Linux/NVIDIA device-level protection remains unvalidated; Apple functional evidence does not satisfy that gate.
E1 / Pure & simulated
Fake-backend tests exercise policy, leases, local IPC and the ALLOW/DENY launch path. They provide no accelerator or device-protection evidence.
E2 / Physical Apple Silicon
Physical M3 Max evidence covers discovery, real Metal compute and managed application-level ALLOW/DENY flow. DeviceEnforce and DeviceRevoke remain unsupported or not evaluated.
E3 / Bare-metal Linux + NVIDIA
The required device-level enforcement evidence is still pending. E2 cannot replace it; an Apple-only PASS remains blocked on E3.
The evaluable path uses OS-observed caller identity, default-deny policy, a scoped lease and a supervised workload launch. Local audit records explain decisions; telemetry is not authorization authority. Cloud is absent from the per-compute hot path.
The quickstart uses a fake backend and harmless echo workload. It verifies authorization, not GPU enforcement. Launcher identity is distinct from workload executable identity; the current limitations are documented.
Read the supported security boundarySource builds and the authorization walkthrough support Linux and Apple Silicon macOS. There is no polished installer or hosted service. Windows, AMD/Intel, enterprise fleet governance and production-grade privileged-attacker resistance are outside this MVP.
Installation, policy, limitations & evidence · Evaluation questions · Report a vulnerability privately