Caution
Hosting platform for software you don't want to get hacked
About Caution
Caution is a hosting platform for software you can't afford to get hacked. It simplifies and extends confidential compute, and lets developers deploy workloads to secure enclaves in minutes and give customers, auditors, and counterparties cryptographic proof that production is running the exact reviewed source code, build, configuration, and runtime - not an opaque binary controlled by a cloud operator or internal admin. Confidential computing hardware exists, but the tooling is too fragmented and incomplete for most teams to use well. Today, attestation often proves only that a binary has a certain hash; it does not prove what source code produced that binary. Building the missing deployment, reproducibility, and verification layer requires specialized security engineering and often locks teams into one cloud or hardware stack. Caution turns that into a simple git-based workflow that builds reproducible enclave images, provisions infrastructure, and lets anyone independently verify what is running. We built Caution after years securing high-risk systems through Distrust, where we worked with hedge funds, custodians, blockchain teams, cloud platforms, and critical grid operators on systems responsible for more than $600B in assets. Again and again, the same problem showed up: teams running mission-critical infrastructure could not reliably prove what was executing in production. As AI, fintech, healthcare, and regulated data collaboration move into the cloud, "trust us" is no longer enough. Caution is a general-purpose platform: if it runs on a server, it can run verifiably on Caution. We're starting where trust failures cost the most, but we believe verifiable compute will become the default way software runs, the same way HTTPS became the default way it's served. Infrastructure you can verify, not trust.
Public traction evidence
Each signal links to the public source used for attribution.
- X
we’re part of the team behind https://t.co/7BMLEjwki3, so entropy is a thing we’ve thought about a lot.
we’re part of the team behind https://t.co/7BMLEjwki3, so entropy is a thing we’ve thought about a lot. it’s probably a good moment to share two tools some may find useful right now: * AirgapOS: a minimal (and audited) OS for offline secrets management used by several well known
- X
having audited tons of high risk orgs, and being on calls with companies daily, i always find it shocking at the level of security maintained internally vs the level of security companies communicate externally.
having audited tons of high risk orgs, and being on calls with companies daily, i always find it shocking at the level of security maintained internally vs the level of security companies communicate externally. most companies still run their security programs in a negligent
- X
survivorship bias is hell of a drug.
story of my life. survivorship bias is hell of a drug.
- X
that’s not how distillation works.
that’s not how distillation works. distillation is an approximation of a model’s behavior, not a proof of equivalence. it learns from a finite set of examples and generalizes from them. because of that, it can’t prove the absence of backdoors. if a backdoor trigger is
- X
Mid-June we packed up and flew to San Francisco.
Mid-June we packed up and flew to San Francisco. Today, Caution launches publicly with Y Combinator. We're building the platform that removes blind trust from infrastructure: proof, not promises, about what's actually running in production. Proud of this team beyond words 🧡
- X
Our confidential compute platform is live in closed beta 🎉 We're working hands-on with the first customers, helping teams migrate existing TEE workloads or stand up confidential compute for the first time.
Our confidential compute platform is live in closed beta 🎉 We're working hands-on with the first customers, helping teams migrate existing TEE workloads or stand up confidential compute for the first time. https://t.co/VW6MbOUycO
- LinkedIn
Early Caution customers are choosing bring-your-own-compute.
Early Caution customers are choosing bring-your-own-compute. The pattern is showing up in inbound too: teams want verifiable compute to run where their infrastructure already lives. With BYOC: → Caution runs inside the customer’s AWS account → Teams keep control of enclave...
- X
"TEEs got hacked" is the wrong takeaway from the Taiko bridge exploit.
"TEEs got hacked" is the wrong takeaway from the Taiko bridge exploit. The hardware did its job. A leaked signing key did the damage. The real problem was trusting the key, not the code actually running. We wrote up what that means for anyone running TEEs: https://t.co/WAbkvy4pYJ