Private intelligence only means anything if you can check it. So every claim on this page is checkable live, by you, right now. The numbers below are read straight from the running gateway, not a status graphic.
Live system posture
Recorded gateway health, sampled continuously and served at GET /v1/status. Uptime is computed from persisted probes; it is null until enough samples exist, never fabricated. Refreshes every 30 seconds.
Gateway
Uptime · 24h
Uptime · 30d
Database
Live attestation
The confidential tier is TEE-attested for the sable-confidential-* models. Other tiers are not confidential. Below is the live, DCAP-verified quote the gateway checks before serving any confidential request.
Reading attestation state…
The fleet
Reading the node registry…
Signed receipts
Every billable response is signed by the key below (secp256k1 / EIP-191). Pin this address and verify any receipt offline against it, or paste one here to check it now. See the receipts docs.
Reading the signing key…
Verify a receipt
Paste the x-sable-receipt header (or the sable.receipt stream event) and its signature. The check runs against the public POST /v1/receipts/verify endpoint and recovers the signer.
The limits
What we do not claim.
Trust is what’s left after the overclaims are removed. These are the limits of what Sable proves, stated plainly, because the honesty is the point.
The pinned measurement covers the base image, not the workload build
The confidential tier pins MRTD — the enclave’s base image (firmware, kernel, initrd) — and not RTMR3, the workload build. So a verified attestation proves a genuine Intel TDX enclave running the expected base image; it does not prove which build of the serving software is inside it. The pin is on MRTD deliberately: the backend serves from a pool of enclaves whose RTMR3 differs between instances, so pinning the workload verified only a fraction of requests and failed closed at random on the rest. One consequence follows, and we state it rather than let it be inferred: gpu_verified is recorded, not proven, because the GPU-CC configuration was only ever covered by the workload measurement.
Standard and anonymized tiers are not confidential
On these tiers the model host’s servers see the prompt in plaintext. Anonymized routing hides who is asking from the vendor; it does not hide what is asked. Only the confidential tier is TEE-attested.
Operator attribution is not proof of correctness
A counter-signed receipt proves which machine served a request (who to hold responsible), not that the work it returned was correct. We label attribution as attribution.
Double-blind hides who, not what
The double-blind lanes are live wherever /v1/models lists them. They separate identity from request — the vendor never learns who is asking — but the vendor’s servers still process the plaintext. It is a privacy property, not a confidentiality guarantee over the payload.
There is no marketplace
Zero third-party machines serve Sable traffic today. What runs is this gateway and its configured backends. We do not use present-tense network or marketplace language for supply that doesn’t exist yet.
The Vault is registry infrastructure, not custody
Sable Vault records and proves issuer-declared entries with hash-chained events and public anchoring. Sable does not custody assets, appraise them, or enforce ownership.
A receipt fingerprints, it never stores content
Prompts, completions, and submitted code are never persisted or logged. A receipt carries metadata and a content fingerprint: enough to verify what ran, never enough to reconstruct it.
Shipped
/Sable Launchpad — launch a coin with a character, on Robinhood Chain/Proof of Backing — continuous reserve verification, published whole/Support Program register opened to SABL holders/Eight models added, including the Claude 5 and Gemini 3.8 families/Know Your Agent — a machine-checkable credential at a passport handle/Autopilot — receipted evidence for a cheaper configuration/The Verifiable Arena — every score backed by a real receipted run/Time Machine — record a request, replay it, diff the result/Sable Notary — sign and anchor work Sable did not run/Intelligence Engine — compile a configuration into an immutable build/Sealed Calls — commit a prediction now, reveal it later/Agent Post — cross-account mail between agents, with postage/Sable Legacy — a dead man's switch for sealed content/The Judge — a panel of models, one signed verdict/Sable Memory, Agent Runtime and the non-custodial payment rail/Persistent sandbox sessions with exec, files and snapshots/MCP Gateway — every tool call allowlisted, metered and receipted/OAuth 2.1 + dynamic client registration for one-click MCP connect/Sable Vault — a private registry with public settlement
/Sable Launchpad — launch a coin with a character, on Robinhood Chain/Proof of Backing — continuous reserve verification, published whole/Support Program register opened to SABL holders/Eight models added, including the Claude 5 and Gemini 3.8 families/Know Your Agent — a machine-checkable credential at a passport handle/Autopilot — receipted evidence for a cheaper configuration/The Verifiable Arena — every score backed by a real receipted run/Time Machine — record a request, replay it, diff the result/Sable Notary — sign and anchor work Sable did not run/Intelligence Engine — compile a configuration into an immutable build/Sealed Calls — commit a prediction now, reveal it later/Agent Post — cross-account mail between agents, with postage/Sable Legacy — a dead man's switch for sealed content/The Judge — a panel of models, one signed verdict/Sable Memory, Agent Runtime and the non-custodial payment rail/Persistent sandbox sessions with exec, files and snapshots/MCP Gateway — every tool call allowlisted, metered and receipted/OAuth 2.1 + dynamic client registration for one-click MCP connect/Sable Vault — a private registry with public settlement