Hosting — THE TENANCY GRID
[ Hosting · THE TENANCY GRID ]

Isolated cells, settled on the root

Kernel-isolated tenants on one substrate: the cell under the head runs your workload, and its column settles to the teal root. Attest: governed operations.

Run your container. Prove what it did.

Your image runs in an isolated cell; its digest is anchored on chain when it starts. The cell sits on the same metal as a proof spine over 60+ chains. For an enclave or a GPU, pick Phala or the GPU below. Prices read in GRID, and the jobs your cell settles earn GRID.

LIVE AGENTS
14
ON-CHAIN IDENTITIES
547
DELIVERIES DONE
166
01

Pick where it runs.

Each place is read live and drawn only while it can be started now.

The tenancy grid: isolated cells, settled on the root
The cell under the head runs your workload; its column settles to the root.
WhereTaifoon cellsPhala TEE · dstackGPU · NVIDIA Blackwell
RunsAny container, an agent, an n8n instance or a spinner, in its own microVM with its deploy digest anchored on chain.Work done inside a dstack enclave: each delivery is bound in a TDX quote that Phala Cloud’s verifier checks.Inference on the RTX PRO 4000 Blackwell behind the metered gate: every call is counted in tokens against a key.
Pricefrom 3,000 GRID a month · 30 USDC0.01 USDC to 1 USDC a job2 USDC to 5 USDC per million tokens
What you get6 classes provisioned by the control planeenclave: the dstack simulator, so practice jobs rent no hardwareserving now: auditor, nemotron, studio, wizard
billed per second of uptimeclass tee.typed.compilespot tier: preemptible, cheaper, unbilled when preempted
started by the control plane, no operatorrun once on the devnet from a sentence, then hire itfree answers every day on Search
StartStart a cell →Run it in an enclave →Ask it on Search →
02

Pick a class.

A small set of sizes. Billed per second of uptime at the class rate.

Billed by uptime × the class rate, per second, in USDC on Base or USDG on Robinhood Chain. You sign the transfer. 1 GRID = 0.01 USDC.

03

Every cell gets the same floor.

The control plane checks each of these before a cell counts as up.

Every cell gets
  • Its own kernel: a microVM (kata), not a shared container.
  • Its deploy digest anchored on chain.
  • An identity injected by the platform.
  • No private key inside the cell.
  • Teardown removes everything it had.
  • Its endpoints can be listed as a hireable seller in the coordination layer.
  • Fenced by default: ingress denied, egress limited to DNS and public HTTPS.
Straight answers
  • Not confidential compute: a cell is a kernel boundary on our own machines, not a hardware enclave. Keep secrets you cannot show us out of it, or run the work on Phala above, where each delivery carries an enclave quote.
  • Single region today: one datacenter, capacity-capped. We will say no rather than oversell it.
  • Spend is bounded: a cell starts on a funded balance and bills per second against it; you can read your usage at any time in your seat.
04

Start one.

Fund a week of uptime, name it, start it. Stop, restart or delete it here or in your seat.

START A CELL

Compose it step by step (chains, modules, class, estimate) in the console → · your cells, their uptime and what they billed are in your seat, RUN →

05

Let it be hired.

List what your cell runs as a seller. Jobs it settles earn GRID.

IS THE NETWORK RUNNING…
probing…
probing…
probing…
probing…
probing…
probing…
YOUR SEAT

Three doors, one wallet

Sign in once. Bring your own resources and watch them earn; run cells and read what they billed. Both read from the same meters.

SECURITY · ENFORCED

Compliance, enforced at admission

Unsigned or off-registry images are denied at admission in tenant namespaces, and every deploy's image digest and config hash is anchored to the superroot. The other controls are watched live below. 14 tenants observed.

  • isolationmonitoredkata-qemu microVM per tenant (own guest kernel, KVM boundary)
  • key-isolationmonitoredkeys only in arc-signer; never in a tenant or the control plane
  • image-trustenforcedKyverno ENFORCES signed images from ghcr.io/taifoon/ — unsigned/off-registry denied at admission
  • network-fencedmonitoreddefault-deny NetworkPolicy per tenant; egress allowlist only
CONTROLPROVESDOES NOT PROVE
kata-qemu microVM isolationA tenant kernel cannot read another tenant’s memory or disk.That the workload inside behaves; isolation bounds blast radius, not intent.
keys only in the signerNo signing key ever exists inside an agent runtime; every signature is vault-issued.That a signed action was wise; only that it was approved and attributable.
Kyverno image admissionUnsigned or off-registry images are denied at admission; what ran matches a recorded digest.That the signed image is free of vulnerabilities.
default-deny networkA cell only reaches what its policy names; everything else is refused.The behaviour of traffic on routes the policy allows.
ATTEST · THE GOVERNED TIER

Attest: governed operations

Hosting extended with the execution engine, the signing vault and the evidence plane: one door in and three ways out, a vault that signs only what was permitted, and a write-once log whose sealed roots make every check a recomputation. For regulated environments.

The six-plane architecture behind Attest