KubeTEE

The Confidential
AI Factory on Bittensor

Decentralized GPU clusters turned into a secure factory for SOTA AI services — inference, agents, and batch jobs inside hardware-secured Trusted Execution Environments.

An AI factory, run where no one can read your data

KubeTEE is the AI Factory of the Bittensor network. It turns decentralized GPU clusters into a confidential factory for state-of-the-art AI services — inference, model microservices, retrieval, and agents.

Every service runs inside a hardware-secured Trusted Execution Environment: the host cannot read workload memory, and remote attestation proves the code and configuration are unmodified. Data and models are protected at rest, in transit, and in use.

The whole stack is open source, built on Kata Containers, Confidential Containers, and a FIPS-validated Kubernetes baseline. Where we patch upstream projects, the patches live in public forks and are contributed back.

Four pillars

Security-first TEE

Hardware-isolated Trusted Execution Environments on a FIPS-validated Kubernetes baseline, with remote attestation so the exact code running on your data can be verified.

Multi-cluster scheduling

One multi-cluster scheduler across decentralized GPU clusters — fair-use queuing, gang scheduling, and preemption, so large jobs place without starving the fleet.

SOTA AI services

NVIDIA NeMo microservices, NIM models, and AI Blueprints as first-class confidential services — plus Bittensor subnet integrations where the NVIDIA stack falls short.

Decentralized & open

One identity per cluster, nodes in distinct data centers, expanding across global regions. Built on open-source projects; our patches live in public forks and go upstream.

Running now, not a whitepaper

  • Available through sayGM

    Confidential inference — GLM-5.2, GLM-5.3, GLM-5.3-Flash, and Ornith-1.5-397B, served inside TEE-isolated pods and available to buyers on sayGM.

    saygm.com
  • Real external revenue

    External inference demand is already paying for compute — and that revenue is recycled on-chain every day.

    See recycled revenue
  • Validator on Bittensor mainnet

    The validator is live on Finney with a public dashboard showing per-cluster infrastructure readiness and scoring.

    Validator dashboard
  • TEE-capable staging cluster

    Every node on the staging cluster is confidential-computing capable — running the same TEE runtime classes as production miner clusters.

What we're building next

Permissionless miner onboarding

Miners register their own cluster and prove control of their hardware without operator involvement.

Multi-cluster batch scheduling

Fine-tuning, evaluation, and multi-step pipelines dispatched across decentralized clusters as confidential batch jobs.

Agent- and chat-driven job deployment

Deploy compute from an autonomous agent or a chat client — browse the catalogue, get a quote, submit, and track the job to completion.

USDC and TAO billing

Pay for confidential compute in stablecoins or TAO, alongside subnet-native Alpha.