Skip to content

Latest commit

 

History

194 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Encompute

Encompute lets you compute on data that stays encrypted, and lets several organizations work together without showing each other their data.

You write ordinary Python and mark which values are secret. Encompute encrypts them, runs the program on a machine that never holds the key, and checks the answer against plain Python.

Who it is for

  • Developers who need to compute on data they must not see.
  • Security and compliance leads who need to know what is protected, against whom, and what evidence is left.
  • Institutions that want several parties to train or analyze together under rules each party can check.

What it guarantees, and what it does not

It guarantees, for the supported features (support matrix):

  • The machine that does the computing never gets the secret key. It sees encrypted values, not your data.
  • Unsafe programs are refused when they are compiled: branching on a secret, printing it, or a number that could overflow.
  • Encrypted results are checked against plain Python, within a precision you declare.
  • Between organizations, rules about who may learn what are checked by the compiler. Keys can be released only to a workload that proves what it is (experimental on Google Confidential Space).

It does not:

  • Hide the program. The computing machine sees the operations, public constants, shapes, declared ranges, timing and data sizes.
  • Prove that the computing machine did the work honestly. A receipt is a signed claim. Proofs exist only in a research build.
  • Protect data after you decrypt it and share it.
  • Come with a proof of security for the whole system. The known limitations list the rest. Read them before you use real data.
  • Run fast. Encrypted computation costs far more than plain computation (performance).

Terms used here. FHE (fully homomorphic encryption): computing on encrypted data. CKKS: an FHE scheme for real numbers, correct to a declared precision. SecAgg (secure aggregation): parties add their private vectors so that only the sum is revealed. DP (differential privacy): added noise that limits what published results reveal about any one person. TEE (trusted execution environment): hardware that can prove what software it runs.

Try it in five minutes

You need Python 3.11 or later. This installs the released package (macOS on Apple silicon shown; the release has a wheel for Linux x86_64 too) and runs the starter, example 00:

git clone https://github.com/BAder82t/Encompute && cd Encompute
python3 -m venv .hello && . .hello/bin/activate
gh release download v0.3.0 -R BAder82t/Encompute -p 'encompute-0.3.0-cp311-abi3-macosx_11_0_arm64.whl'
pip install ./encompute-0.3.0-cp311-abi3-macosx_11_0_arm64.whl
examples/00_hello_encrypted/run.sh

Real output from that wheel (sizes and timings vary from run to run; the last step, three refusals of unsafe actions, is left out here):

== Score four private test results without revealing them ==
Step 1. The clinic's private data (the evaluator never sees this)
  panel = [0.62, 0.18, 0.91, 0.4]

Step 2. What the risk service is told: the program, not the data
  scheme    CKKS (approximate), 128-bit classical
  the evaluator can see:
    - program structure (operations and their order)
    - public constants (weights, coefficients)
    - input and output shapes
    - declared input ranges
  evaluator receives the secret key: no

Step 3. Encrypt, compute while encrypted, decrypt
  (the sizes below come from a second encrypted run with fresh keys)
  the clinic made a secret key and public keys, and encrypted the panel
  the evaluator received 1,574,609 bytes of ciphertext
    and 18,882,955 bytes of evaluation keys (no secret key)
  the evaluator computed sigmoid(weights . panel + bias) on ciphertext
  it returned 526,087 bytes: one ciphertext only the clinic can open
  the clinic decrypted it (timings in ms: keygen 460, encrypt 21, evaluate 94, decrypt 11)

Step 4. Check the answer against plain Python
  plain result      0.77171
  encrypted result  0.77161
  difference        0.00010  (allowed: 0.00100)

A clinic's four private numbers were encrypted, scored by a service that never saw them in the clear, and decrypted. The scoring side held no secret key. The example's README explains each step and what it does not show.

Pick your path

You are Read Then run
Developer Developer path 01, 02
Security or compliance lead Security and compliance path 06, 13
Institution deploying it Institution path 11, 12

Every capability has a runnable example; examples/ has a table by goal. All topics are in the guide: confidentiality policies, secure aggregation, differential privacy, planner, confidential fine-tuning, trust graph, attested key release, verification, remote evaluation and building from source.

Status and support

Release 0.3.0. What is supported, what is a subset, and what is experimental, research only or unsupported is in the support matrix, with a short summary. Also: known limitations, release notes, changelog, threat model, security findings, repository layout and roadmap.

An independent review of 0.3.0-rc.3 reported findings that are fixed in 0.3.0, some only partly. The reviewers have not reviewed the fixes. Security reports: SECURITY.md.

License

AGPL-3.0-only, with commercial licenses available: see LICENSING.md. Encompute statically links OpenFHE (BSD 2-Clause); research builds with the research-tfhe-rs feature also link TFHE-rs (BSD-3-Clause-Clear, plus Zama's patent terms); see THIRD_PARTY_NOTICES.md.

About

Build AI across organizations without exposing private data, models, gradients, or derived artifacts. Encompute compiles trust policies into confidential, verifiable execution.

Topics

Resources

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages