SEAL is fully shipped. $ANYR
Anyroute SEAL is private, verifiable infrastructure for open and uncensored models.
It is built around four parts:
S: Sidecar
The model runs behind an attested Sidecar. The hardware proves the environment, the model weights are measured, keys are created inside the enclave, and every response can be tied back to that record.
E: Encrypted transport
Your request is encrypted to the enclave. A relay separates your IP from the request path, so the operator handling the model does not need to know who sent it.
A: Anonymous credits
Payment and prompting are separated. Blind credits let a request be paid for without attaching the payerโs identity to the prompt or the receipt.
L: Ledger of receipts
Every response returns a signed receipt. It records the model, route, attestation, policy, and hashes of the request and response, not the content itself. Streams are hash-chained, so altered or cut output can be detected. Receipt records are anchored on-chain for verification.
SEAL also makes policy visible. If filtering is enabled, the policy is measured inside the enclave and named in the receipt. No hidden changes after the fact.
Builders can use it with OpenAI-compatible model servers, Claude Code, Codex, the OpenAI Agents SDK, Saved Routes, Batch Studio, and private RAG.
The point is not to ask users to trust a privacy policy.
The point is to show what ran, where the request went, what was retained, who could see what, and give the user a receipt they can verify themselves.
SDKs for every stack.
Anyroute now has official TypeScript, Python, and Go SDKs, alongside LangChain and LlamaIndex integrations.
Build with chat, batches, rerank, and presets. Every SDK can verify receipts offline.
Shipped: https://t.co/jiBs4KuvGZ
Uptime, by privacy lane.
Anyroute now has a public status page with SLOs for the public, attested, and unlinkable lanes.
Private lanes are measured only through privacy-preserving aggregates. Follow incidents through Atom or RSS.
Shipped: https://t.co/9Ggq4YYW6q
Teams should not need to hand over their identities to work together.
Anonymous orgs on Anyroute let members join with a passkey or wallet, no email required. A Safe can own the org.
Set roles for admins, devs, viewers, and agents. Every action lands in a hash-chained audit log you can verify offline.
Shipped: https://t.co/vql93Me0io
Sort by speed. Sort by cost.
Add `:nitro` to a model for the fastest available provider, or `:floor` for the lowest-cost option.
Anyroute also now supports a Cohere- and Jina-compatible rerank endpoint that returns grounded scores, not invented ones.
Shipped: https://t.co/uBrKe5bAok
Your traces, your collector.
Send OpenTelemetry GenAI spans to your own OTLP endpoint, Langfuse, or Helicone.
Prompt content is exported only when you opt in. Private-lane requests are never exported.
Shipped: https://t.co/wLDenCtM3N
The Anyroute Network is coming.
Private inference cannot depend on a small group of providers. More private capacity needs to be in more hands. $ANYR
Soon, operators with confidential GPUs and eligible TDX hosts will be able to run a SEAL host on Anyroute.
One command sets up the host.
Your hardware attests what it is running.
Private requests are routed to verified capacity.
Every response carries a signed receipt.
Hosts earn USDG for the tokens they serve.
The goal is simple: make private, verifiable inference available beyond a single provider or data centre.
The attested lane is already live with open models. The next step is opening supply.
Check whether your server qualifies:
https://t.co/oBkbbFfVYU
Build details:
https://t.co/IS37BUmaOo
Presets, with memory.
Presets keep a versioned configuration for your model, system prompt, and settings.
Use `@preset/name`, compare any two versions, roll back in one call, or pin an exact release with `@preset/name@3`.
Shipped: https://t.co/4Z1qvmfI4N
Your Ollama apps, every model.
Point `OLLAMA_HOST` to Anyroute, and tools like Open WebUI, Continue, and LangChain can access 376 models through the Ollama API.
Streaming stays native. Every call includes a signed receipt. The attested lane is available too.
Shipped: https://t.co/tQPdVpidH2
@RobinhoodApp Agents can now act. The next question is what rules sit between an agent and your money.
Budgets. Mandates. Simulation before signing. A real kill switch. Private payments and receipts.
That is the layer Anyroute is building next.
The Anyroute Network is coming.
Private inference cannot depend on a small group of providers. More private capacity needs to be in more hands. $ANYR
Soon, operators with confidential GPUs and eligible TDX hosts will be able to run a SEAL host on Anyroute.
One command sets up the host.
Your hardware attests what it is running.
Private requests are routed to verified capacity.
Every response carries a signed receipt.
Hosts earn USDG for the tokens they serve.
The goal is simple: make private, verifiable inference available beyond a single provider or data centre.
The attested lane is already live with open models. The next step is opening supply.
Check whether your server qualifies:
https://t.co/oBkbbFfVYU
Build details:
https://t.co/IS37BUmaOo
Weโre working on a big and new expansion. More details in a few hours.๐
Hired some new help to spread workload and get things done.
Bigger team at @TryAnyroute now.
Would to love get feedback or suggestions about where weโre at now from our $ANYR community.
We still have an extensive roadmap ahead although if anyone has bright ideas, weโre willing to listen to each and everyone on them on our tg: https://t.co/4gg6xdsWmH
Batch API is now available on Anyroute.
Submit a batch and receive 50% off every completed line. Each result includes its own signed receipt; failed lines are not charged.
Prompts are processed in memory and are not written to the Anyroute database.
https://t.co/XOhfs1tP8Y
Batch API is now available on Anyroute.
Submit a batch and receive 50% off every completed line. Each result includes its own signed receipt; failed lines are not charged.
Prompts are processed in memory and are not written to the Anyroute database.
https://t.co/XOhfs1thjq
To run a SEAL enclave:
โข Intel TDX for attested or unlinkable lanes
โข an OpenAI-compatible engine + digest-pinned Sidecar
โข read-only weights on the model allow-list
โข Docker Compose or Kubernetes
Confidential GPU claims also need Hopper or Blackwell in CC mode.