
Work Here?
Opaque Systems provides a platform for secure data analytics using Data Clean Rooms powered by Confidential Computing. It enables multiple data teams to share and analyze encrypted data across organizations while preserving each party’s access only to their own data and insights. Data remains encrypted at rest, in transit, and during processing, with analytics and AI computations performed inside confidential environments so no data is exposed during computation. This differentiates Opaque from competitors by offering end-to-end protection, easy migration to Confidential Computing clouds, and built-in support for regulatory compliance. The company's goal is to let organizations securely analyze sensitive information and collaborate on data projects without compromising privacy or security.
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
51-200
Company Stage
Series B
Total Funding
$55.5M
Headquarters
San Francisco, California
Founded
2020
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$55.5M
Meets
Industry Average
Funded Over
3 Rounds
Industry standards
Competitive compensation
Health insurance
Flexible work options
Unlimited PTO
401k
Home office reimbursement
Commute reimbursement
Meals on us
OPAQUE, a Confidential AI company, has introduced Weight Custody Manifest (WCM), an open standard that enables AI model builders to control where their model weights are unlocked when deployed on customer-controlled infrastructure. WCM keeps model weights encrypted until the deployment environment proves it meets conditions approved by the builder. The system addresses trust issues as models increasingly move beyond their creators' infrastructure into enterprise, sovereign, and on-premises environments. A jointly signed manifest defines the model's identity, licence, permitted uses, jurisdiction, and custody requirements before weights are unlocked. WCM also tracks fine-tuned derivatives and supports revocation capabilities. OPAQUE has validated WCM on NVIDIA H100 in confidential mode, as well as AMD and Intel confidential servers on Azure and Google Cloud. The open standard is released as an Apache-licensed developer preview with published specification, reference library, and 91 public test cases.
OPAQUE introduces an open standard that unlocks frontier models for sovereign and on-premises deployment. 2026-09-09 2 minutes Read Weight Custody Manifest ends the standoff that keeps the best models out of customer-controlled environments: builders get verifiable control over where their weights are unlocked, and customers keep control of their own machines SAN FRANCISCO - September 9, 2026 - OPAQUE, the Confidential AI company, today introduced Weight Custody Manifest (WCM), an open standard and developer-preview SDK that gives AI builders verifiable control over when and where their model weights can be unlocked when deployed on customer-controlled infrastructure. WCM extends OPAQUE's Confidential AI infrastructure to protect the actual models running on sensitive data, not just the data itself. AI models are increasingly moving beyond the infrastructure of the companies that built them. Enterprises are fine-tuning open models on proprietary data, while AI labs and software companies are being asked to deploy increasingly valuable models directly into customer, sovereign and on-premises environments. This shift creates a new trust problem for model builders. As model weights are deployed on someone else's machines, builders lack the technical controls required for effective protection. For a growing number of sovereign and on-premises deals, deploying into the customer's environment is now a precondition of the deal rather than an option. WCM directly addresses this challenge by keeping model weights encrypted until the new infrastructure proves it meets the conditions approved by the model builder. Even after the key is released, if those conditions change or the required proof is not consistently met, access can be revoked at any time. "Today's Confidential AI protects the customer from the model. WCM protects the model from the customer," said Imran Siddique, Chief Platform Officer at OPAQUE. "The terms of a written contract have limited reach as AI models increasingly move onto infrastructure their builders don't control. Builders need proof that their intellectual property will only be unlocked in an environment that meets agreed-upon conditions. WCM gives all parties verifiable proof instead of asking either side to simply trust the other." Unlike existing key brokers, WCM connects key release to the model itself and the terms governing its use. A jointly signed manifest can define the model's identity, license, permitted uses, jurisdiction, approved software and custody requirements before its weights are unlocked. WCM also tracks fine-tuned derivatives back to their parent models and supports revocation down the chain. The manifest is co-signed by the model builder and the custodian, OPAQUE by default or self-hosted by a sovereign customer. Either side can trigger an emergency revocation, and sovereign deployments can require a quorum so no single party can switch the model off on its own. Manifests can be recorded to a public, append-only log, which sovereign deployments require. It complements OpenSSF Model Signing where signing proves the model is genuine, while WCM determines whether it can be unlocked. WCM is being released as an open, Apache-licensed developer preview with a published specification, defined data format, working reference library and 91 public test cases. The specification, threat model and tests are public so model builders, customers and infrastructure providers can independently evaluate and implement the protocol. As a developer preview, the specification and interfaces may change based on implementer feedback ahead of a stable release. OPAQUE has validated WCM end-to-end on real hardware. The build is reproducible, with two back-to-back builds producing byte-identical results across 5,948 files, verified automatically. WCM has been validated using a NVIDIA H100 in confidential mode, as well as AMD and Intel confidential servers on Azure and Google Cloud. In its most recent validation, a CPU and GPU proved themselves together against the same fresh, one-time challenge before the model key was released as sealed ciphertext. Attempts to substitute either proof were refused, and the full test suite passed. Developers can access the WCM specification, reference implementation and test suite at https://agentrust-io.com/wcm. About OPAQUE OPAQUE is the Confidential AI company. Born from UC Berkeley's RISELab (now the Sky Compute Lab), OPAQUE lets organizations run AI models, agents, and workflows on their most sensitive data with hardware-rooted isolation and verifiable evidence that approved governance policies were actually enforced. Founded by Dr. Ion Stoica (co-founder of Databricks; co-director, UC Berkeley Sky Compute Lab), Dr. Raluca Ada Popa (ACM Grace Hopper Award winner; Senior Staff Research Scientist at Google DeepMind, where she leads AGI security research), and Rishabh Poddar (CTO); Imran Siddique, creator of the open-source Agent Governance Toolkit (AGT), is Chief Platform Officer. OPAQUE created the Confidential Computing Summit.
OPAQUE, AMD, Intel, TII, and other industry leaders collaborate on TRACE, an open standard to advance runtime verification for AI. Aug 25, 2026, 09:00 ET New vendor-neutral specification creates portable, hardware-backed evidence of what AI systems ran, which policies were enforced, and how sensitive data was governed across clouds and infrastructure SAN FRANCISCO, Aug. 25, 2026 /PRNewswire/ - OPAQUE, the Confidential AI company, today announced TRACE (Trust, Runtime Attestation, and Compliance Evidence), an open, portable, hardware-enforced governance record for AI agents and other confidential workloads. Developed in collaboration with leading hardware and AI infrastructure companies and contributed to the Linux Foundation, TRACE establishes a vendor-neutral format for proving what software ran, which policies governed execution, what data classifications were involved and which tools were invoked. Rather than creating another proprietary verification stack, TRACE composes existing standards into a common evidence layer designed to work across enterprise, cloud and sovereign AI infrastructure. Enterprise AI is rapidly moving from isolated model experiments to agents and workloads that operate across sensitive data, tools, clouds and infrastructure. That shift is making the need for independently verifiable runtime evidence more urgent. OpenAI recently disclosed that models undergoing a cybersecurity evaluation, with certain production safeguards intentionally reduced for testing, found an unexpected path beyond their constrained environment and compromised Hugging Face infrastructure. The incident underscored a fundamental challenge for autonomous AI: documented policies and sandbox configurations do not, by themselves, prove which controls remained in force or what a system actually did during execution. The same evidence gap applies to open-weight models. Possessing the weights and controlling the infrastructure provides greater deployment control, but it does not prove that an approved model ran unmodified or that required policies governed its use. That's where TRACE comes in. Vendors across the AI ecosystem are developing their own approaches to runtime attestation and evidence, but without an open standard, enterprises face a vendor-by-vendor patchwork of incompatible trust records that cannot be independently compared or verified. TRACE composes established standards for hardware attestation, workload identity, software provenance and transparency, including RATS, EAT, SLSA, SCITT, SPIFFE and EAR. The result is a single verifiable artifact that travels with AI workloads across cloud providers, confidential computing platforms and sovereign infrastructure while adding runtime evidence for policy enforcement, data classification and AI tool execution. "The models and agents we deploy five years from now will be far more powerful than the ones we're deploying today. We may not always be able to predict how they reason, but we can control what they're allowed to do and prove what they actually did," said Aaron Fulkerson, CEO of OPAQUE. "TRACE creates a tamper-evident record of what ran, which policies were enforced, what data was involved and which tools an agent invoked. That proof holds whether you're running an open-weight model today or a much more capable system tomorrow. The industry needs that evidence to be portable and independently verifiable before the market hardens around incompatible vendor trust systems." "As enterprises move AI into production on their most sensitive data, confidentiality cannot be an afterthought, it has to be a requirement," said Mahesh Wagh, senior fellow at AMD. "AMD SEV provides that built-in silicon foundation, keeping data and models protected in use, and TRACE turns that protection into portable, independently verifiable evidence. We're proud to be a founding collaborator on an open standard that gives organizations independent evidence of not just where their AI ran, but how it behaved once in production." "The industry must move to cryptographically-verifiable AI. As agents become more autonomous and increasingly interact with other agents, sensitive data, and critical business systems, organizations need cryptographic evidence of the agent's identity, what it is authorized to do, where it is running, and proof that governance policies were enforced. Hardware-based attestation and confidential computing make that possible at scale, creating a foundation for independently verifiable AI where enterprises can make informed decisions before agents access data, invoke tools, or delegate actions to one another. Intel is pleased to collaborate on this open industry effort that builds on established standards and gives enterprises greater confidence as they deploy AI with their most sensitive data," said Anand Pashupathy, Vice President and General Manager, Intel Product Assurance and Security. OPAQUE first introduced TRACE at the Confidential Computing Summit in June 2026. TRACE reference library passed 135,000 PyPI downloads in its first ten weeks, with technical engagement from major hardware and AI companies, and ongoing standards discussions across the Coalition for Secure AI (CoSAI) and the Linux Foundation ecosystem. TRACE will be governed through the Linux Foundation, providing a vendor-neutral home for the standard, while CoSAI hosts the technical workstream. Through the workstream, AI companies, cloud providers, silicon vendors, and enterprise users will collaborate to ensure TRACE remains interoperable across AI models, cloud platforms, confidential computing technologies and emerging AI governance frameworks. TRACE is led by OPAQUE Chief Platform Officer Imran Siddique, creator of the open-source Agent Governance Toolkit, working alongside OPAQUE CEO Aaron Fulkerson and CTO and Co-founder Rishabh Poddar. Founding collaborators include AMD, Intel, Microsoft, and the Technology Innovation Institute (TII), which joins the effort as TRACE's sovereign AI anchor. TRACE is available today as an open specification with reference implementations and documentation at trace.agentrust-io.com. OPAQUE welcomes technical review and contributions from AI developers, cloud providers, silicon manufacturers and standards organizations interested in advancing portable, independently verifiable runtime evidence for AI. About OPAQUE OPAQUE is the Confidential AI company. Born from UC Berkeley's RISELab (now the Sky Compute Lab), OPAQUE lets organizations run AI models, agents, and workflows on their most sensitive data with hardware-rooted isolation and verifiable evidence that approved governance policies were actually enforced. Founded by Dr. Ion Stoica (co-founder of Databricks; co-director, UC Berkeley Sky Compute Lab), Dr. Raluca Ada Popa (ACM Grace Hopper Award winner; Senior Staff Research Scientist at Google DeepMind, where she leads AGI security research), and Rishabh Poddar (CTO); Imran Siddique, creator of the open-source Agent Governance Toolkit (AGT), is Chief Platform Officer. OPAQUE created the Confidential Computing Summit, now co-hosted with the Linux Foundation. SOURCE OPAQUE
OPAQUE: secure AI for sensitive data - CEO Aaron Fulkerson. 6h ago · 0:00 listen · Source: Pulse 2.0 Summary. OPAQUE is developing Confidential AI infrastructure to help enterprises use sensitive data in AI. This technology enforces policies during execution and provides verifiable evidence of what occurred. OPAQUE CEO Aaron Fulkerson shared insights into his background and the company's mission. He noted that in his past roles, trust, not technology, was often the bottleneck. He believes AI is at a similar point today. Enterprises are hesitant to use sensitive data because they can't verify what happens during processing. Fulkerson explained that OPAQUE embeds security and compliance from the start, rather than adding it later. This approach helps overcome resistance and speeds up adoption. The system generates verifiable evidence of data processing, shifting the focus from speculation to proof. The founding team identified a key problem: while data is encrypted at rest and in transit, protections often disappear during active processing. OPAQUE aims to address this gap. This technology could allow companies to leverage AI with sensitive information more securely. This is an AI-generated audio summary. Always check the original source for complete reporting.
OPAQUE, the Confidential AI company, has joined the Linux Foundation's Appia Foundation and Agentic AI Foundation to advance open standards for verifiable AI systems. The company will contribute its work on AI identity, runtime governance, and cryptographic evidence to help organisations prove how AI systems are governed. OPAQUE's contributions are built on the open-source Agent Governance Toolkit, which has nearly 5,000 GitHub stars and over 100 contributors. The company plans to contribute several specifications to the foundations, including Agent Manifest for verifiable AI agent identity and TRACE for hardware-attested trust records. The Appia Foundation provides testing criteria and evaluation guidelines to verify trusted AI systems, whilst the Agentic AI Foundation ensures transparent development of autonomous AI. OPAQUE is already a member of the Confidential Computing Consortium and co-hosts the Confidential Computing Summit with the Linux Foundation.
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
51-200
Company Stage
Series B
Total Funding
$55.5M
Headquarters
San Francisco, California
Founded
2020
Find jobs on Simplify and start your career today