Use frontier models on our servers without exposing your data. Cryptography keeps your prompts and answers unreadable to us, our hosts, and our infrastructure partners.
01 No training on your data02 We can’t read your content03 Privacy you can verify
01 / BUILT FOR WHAT’S YOURS
The work that matters should stay your work.
Bring AI closer to your most sensitive work. Keep your intellectual property out of everyone else’s hands.
01 / ENGINEERING
Ship the code. Keep the secrets.
Give your coding assistant the context it needs, without giving a lab your codebase. Work with proprietary algorithms, internal systems, and sensitive data inside private inference.
Source codeAlgorithmsInternal documentation
YOUR COMPETITIVE ADVANTAGEfunction nextBreakthrough(yourIdeas) { return/* yours, and yours alone */ }
Your unreleased game is your advantage. Use private AI in workflows involving concepts, graphics, 3D renders, logos, lore, and production code without turning your next release into someone else’s dataset.
Review agreements, compare clauses, and reason through sensitive matters. Protect the contents of client documents during inference, including information you would never send to a public chatbot.
Bring email, calendar, and Drive context into private AI workflows. Plan, synthesize, and make decisions without letting an inference provider read your communications or company strategy.
EmailCalendarDrive & documents
CONTEXT WITHOUT EXPOSURE
Your next move. On a need-to-know basis.
Connector permissions and data handling must preserve the protected path. Discuss your integration requirements with us.
Use cyber-capable models to pentest and red-team infrastructure you own or are authorized to test. Take security into your own hands without waiting for admission to a lab’s restricted security program.
Explore hypotheses, analyze results, and develop new proofs without handing over unpublished work. Your research should advance your team, not become training material for someone else’s model.
Serence and our infrastructure partners cannot read your prompts or answers. Cryptographic protection keeps them private, even while the model is working.
01 — VERIFY
Proof before a prompt.
Your client verifies cryptographic proof of the protected environment before sending your prompt. Privacy is checked before your data leaves your team.
02 — PROTECT
Intelligence inside the boundary.
The model works on your request inside a protected environment. Neither Serence nor the hosting provider can read what you send.
03 — RETURN
The answer belongs to you.
Your answer comes back encrypted, for your client to read. Your prompts and answers never become training data for us or a model lab.
03 / RETHINK THE TRUST CHAIN
One prompt. How many people to trust?
Your prompt can pass through a routing service and a model provider, running on someone else’s cloud and data center. You’re trusting more than one company.
If you use an intermediary such as OpenRouter, that’s another part of the chain. Each party brings its own access controls, policies, and security.
CONVENTIONAL CLOUD AITrust the operators
Your teamSends a prompt
→
Routing serviceIf you use one
→
Model providerProcesses your prompt
INFRASTRUCTURE BEHIND THE MODEL
Cloud host+Data center
Your prompt is readable where it’s processed. You rely on the provider—and any routing or infrastructure partners—to keep it private.
PRIVATE INFERENCE WITH SERENCEPrivacy by proof
Your team
ENCRYPTED
Private inferenceOnly the model can process it
The model can work with your prompt. Serence, our hosts, and our infrastructure partners cannot read it—or the answer.
Bugs, exposed databases, and third-party data practices have real consequences. These documented incidents and reported practices show why the processing path matters.
Provider disclosure
A chat history that wasn’t yours.
OpenAI disclosed a bug that let some ChatGPT users see other users’ conversation titles and possibly the first message of a new conversation. Limited billing details were also potentially exposed for some active Plus users.
Wiz found an exposed DeepSeek database with more than one million log entries, including plaintext chat history and API secrets. DeepSeek secured it after disclosure. Exposure was verified; malicious theft was not established.
Anthropic reported that some proxy services recorded Claude conversations and sold them to AI labs. Its report describes SenseTime purchasing transcripts harvested through third-party apps and routing services.
OpenAI initially said it was unlikely, but could not rule out usage-derived data helping improve its models. It later reported ruling out influence from Buckmaster’s Codex prompts in the preceding two months, including through training.
This is not evidence of copied research. It raises a bigger question: why should unpublished work enter a provider’s data pipeline at all?
Sources reviewed September 17, 2026. Confirmed exposures, vendor-reported findings, and disputed claims are distinguished above. The intermediary example in the trust diagram is not an allegation of misconduct by OpenRouter.
Inference is a model turning your request into an answer. Serence keeps that work inside a protected environment, with your content encrypted on the way in and out. We run the service without being able to read your content. How it works ↗
How is this different from “we don’t train on your data”?+
A no-training policy is a promise about data a provider may still be able to read. Serence adds cryptographic protection: we cannot read your prompts or answers inside the verified inference environment, or use them to train models.
What does “provable” actually mean?+
Your client checks cryptographic evidence of the environment before sending data. That evidence identifies what is running; review of the software establishes how it handles your information. How it works ↗
Do I still need to trust the hosting provider?+
You do not rely on the host to keep your prompt content secret inside the verified environment. The host can still affect availability and see some operational metadata. Protection depends on verified software, secure hardware, and your client. How it works ↗
Does this protect everything an AI agent can access?+
Private inference protects the model’s processing of your data. Your devices, accounts, and external tools need their own protections. Email, calendar, and Drive integrations must preserve the private path. Hardware and software vulnerabilities remain part of the threat model. How it works ↗
Which models and workflows can I use?+
Ask us about GLM-5.3, Kimi, and private workflows for coding, research, document review, and authorized security testing. Available models, versions, and modalities depend on your deployment.
YOUR NEXT IDEA DESERVES A PRIVATE SPACE.
Keep your advantage. Keep it yours.
Frontier intelligence for work that can’t be public.