The thesis
Factories make tokens.OpenGrid is the transmission layer.
An AI grid places work across factories, regional hubs and edge sites as one platform. Every grid being built today still owns the machines it routes to. OpenGrid is the transmission layer between buyer and operator — open to anyone who contributes capacity, with a signed receipt for every call, and no generation of our own.
The category is real. Move intelligence closer to the data. Treat distributed endpoints as one platform. Route each request where it should run — not merely to the nearest box. That demand is being sold at industrial scale.
Every published grid still closes the loop the same way: the company that runs the control plane also runs the machines underneath it. The orchestrator knows its nodes because they are its nodes. Own the generation and you cannot route neutrally to a competitor. That is a utility wearing a grid’s name.
The capacity is already out there — modular sites, regional hubs, edge machines — with silicon and no way onto a closed grid. Open weights made the models portable. What is missing is a transmission layer that can accept a stranger’s machine, place production work on it, and prove which one answered.
Who owns what
The layers are identical. The ownership is not.
One company owns the factories and the control plane that routes to them. Every place it can send work is itself.
OpenGrid is the transmission layer — path, orchestration, identity and settlement, Apache 2.0. The machines underneath belong to whoever enrolled them.
We do not operate capacity and will not acquire any. The moment we run our own factories, the layer stops being neutral — and stops being open.
What proven means
A transmission layer open to strangers cannot rely on knowing the operator. This is what stands in for knowing them.
Provider identity
Ed25519 mTLS, revocable at the edge. Every route lands on a named operator.
Artifact provenance
Bound to an artifact digest and an approved engine build, not to a model name.
Encrypted transport
Sealed end to end between our edge and the serving machine: direct QUIC where the network allows it, our own encrypted relay where it doesn’t.
Signed receipts
One per successful route, reconciled against streamed output at the edge.
Auditable settlement
Double-entry, with daily signed Merkle snapshots.
Silent-drift detection
Blind canaries ride ordinary assignments.
No payload retention
Off by default.
The limit
The serving provider sees prompts and outputs in plaintext. Transport is encrypted end to end and the coordinator is blind to content, but we do not hide a request from the operator running it. The answer is a visible operator boundary and a verified zero-retention policy, not a confidential-compute claim we cannot back.