The thesis
Factories make tokens.OpenGrid moves them.
An AI factory converts energy into tokens. An AI grid places that work across geography. Every grid being built today still owns the factories inside it. OpenGrid is the transmission layer that owns no generation.
Today’s AI grids are one company end to end — their factories, their fabric, their control plane. Own the generation and you cannot route neutrally to a competitor. That is a utility wearing a grid’s name.
The capacity is already out there: modular sites energising this quarter, regional hubs with power and no demand channel, edge machines on desks. Individually subscale. Collectively larger than any single operator will build this decade. Each has silicon and no way to take production traffic from a buyer who has never heard of them.
Open weights made the models portable. What is missing is a layer that can place work on someone else’s factory — and return proof of which one answered.
Who owns what
The layers are identical. The ownership is not.
One company owns all four. Every place it can route is itself.
OpenGrid owns orchestration, the network path, and settlement — Apache 2.0. The capacity beneath is not ours and never becomes ours.
We own no generation and will not acquire any. The moment we operate capacity, the neutrality is gone.
What proven means
A buyer cannot check the reputation of an operator they have never heard of. This is what stands in for one.
Provider identity
Ed25519 mTLS, revocable at the edge. Every route lands on a named operator.
Artifact provenance
Bound to an artifact digest and an approved engine build, not to a model name.
Encrypted transport
Sealed end to end between our edge and the serving machine: direct QUIC where the network allows it, our own encrypted relay where it doesn’t.
Signed receipts
One per successful route, reconciled against streamed output at the edge.
Auditable settlement
Double-entry, with daily signed Merkle snapshots.
Silent-drift detection
Blind canaries ride ordinary assignments.
No payload retention
Off by default.
The limit
The serving provider sees prompts and outputs in plaintext. Transport is encrypted end to end and the coordinator is blind to content, but we do not hide a request from the operator running it. The answer is a visible operator boundary and a verified zero-retention policy, not a confidential-compute claim we cannot back.
Where this is
Pre-production, grouped by evidence rather than by date. A gate opens when the thing that would prove it exists.
Built
Implemented, exercised against deterministic simulators.
OpenAI-compatible gateway
Implemented and tested.
ImplementedStandalone node adapters
llama.cpp, CUDA, MLX. One daemon per host.
ImplementedDirect and relay routing
Sealed end to end, including across our own relay.
ImplementedDouble-entry ledger
Append-only, with daily signed Merkle roots.
Implemented
Open
Built. The evidence that would make it production is not in hand.
Physical-hardware matrix
Adapters ship. The packaged matrix does not.
Validation openProduction routing
Compose exercises the whole path. That is validation, not proof.
Validation openManaged-cluster connector
Enrollment implemented. Routing off pending review.
Validation open
Gated
Hard-disabled. Each opens on named evidence.
Standalone billing
Opens on a catalog-trusted tokenizer and template binding.
Fail-closedCluster scheduling and billing
Opens on validation against a real multi-node GPU cluster.
Fail-closedPrivate-tier claims
Verify against signed zero-retention attestations. Fail closed when stale.
Fail-closedPublic provider enrollment
Closed developer preview.
Fail-closed