sable network
Buy on Index
Trust

Verify, don’t trust.

Private intelligence only means anything if you can check it. So every claim on this page is checkable live, by you, right now. The numbers below are read straight from the running gateway, not a status graphic.

Live system posture

Recorded gateway health, sampled continuously and served at GET /v1/status. Uptime is computed from persisted probes; it is null until enough samples exist, never fabricated. Refreshes every 30 seconds.

Gateway
Uptime · 24h
Uptime · 30d
Database
Live attestation

The confidential tier is TEE-attested for the sable-confidential-* models. Other tiers are not confidential. Below is the live, DCAP-verified quote the gateway checks before serving any confidential request.

Reading attestation state…

The fleet

Reading the node registry…

Signed receipts

Every billable response is signed by the key below (secp256k1 / EIP-191). Pin this address and verify any receipt offline against it, or paste one here to check it now. See the receipts docs.

Reading the signing key…

Verify a receipt

Paste the x-sable-receipt header (or the sable.receipt stream event) and its signature. The check runs against the public POST /v1/receipts/verify endpoint and recovers the signer.

The limits

What we do not claim.

Trust is what’s left after the overclaims are removed. These are the limits of what Sable proves, stated plainly, because the honesty is the point.

The pinned measurement covers the base image, not the workload build

The confidential tier pins MRTD — the enclave’s base image (firmware, kernel, initrd) — and not RTMR3, the workload build. So a verified attestation proves a genuine Intel TDX enclave running the expected base image; it does not prove which build of the serving software is inside it. The pin is on MRTD deliberately: the backend serves from a pool of enclaves whose RTMR3 differs between instances, so pinning the workload verified only a fraction of requests and failed closed at random on the rest. One consequence follows, and we state it rather than let it be inferred: gpu_verified is recorded, not proven, because the GPU-CC configuration was only ever covered by the workload measurement.

Standard and anonymized tiers are not confidential

On these tiers the model host’s servers see the prompt in plaintext. Anonymized routing hides who is asking from the vendor; it does not hide what is asked. Only the confidential tier is TEE-attested.

Operator attribution is not proof of correctness

A counter-signed receipt proves which machine served a request (who to hold responsible), not that the work it returned was correct. We label attribution as attribution.

Double-blind hides who, not what

The double-blind lanes are live wherever /v1/models lists them. They separate identity from request — the vendor never learns who is asking — but the vendor’s servers still process the plaintext. It is a privacy property, not a confidentiality guarantee over the payload.

There is no marketplace

Zero third-party machines serve Sable traffic today. What runs is this gateway and its configured backends. We do not use present-tense network or marketplace language for supply that doesn’t exist yet.

The Vault is registry infrastructure, not custody

Sable Vault records and proves issuer-declared entries with hash-chained events and public anchoring. Sable does not custody assets, appraise them, or enforce ownership.

A receipt fingerprints, it never stores content

Prompts, completions, and submitted code are never persisted or logged. A receipt carries metadata and a content fingerprint: enough to verify what ran, never enough to reconstruct it.

Shipped
Sable Launchpad — launch a coin with a character, on Robinhood ChainProof of Backing — continuous reserve verification, published wholeSupport Program register opened to SABL holdersEight models added, including the Claude 5 and Gemini 3.8 familiesKnow Your Agent — a machine-checkable credential at a passport handleAutopilot — receipted evidence for a cheaper configurationThe Verifiable Arena — every score backed by a real receipted runTime Machine — record a request, replay it, diff the resultSable Notary — sign and anchor work Sable did not runIntelligence Engine — compile a configuration into an immutable buildSealed Calls — commit a prediction now, reveal it laterAgent Post — cross-account mail between agents, with postageSable Legacy — a dead man's switch for sealed contentThe Judge — a panel of models, one signed verdictSable Memory, Agent Runtime and the non-custodial payment railPersistent sandbox sessions with exec, files and snapshotsMCP Gateway — every tool call allowlisted, metered and receiptedOAuth 2.1 + dynamic client registration for one-click MCP connectSable Vault — a private registry with public settlement