A new method for LLM encryption

Encryptedintelligence.Private by design.

A novel method for encrypting LLMs. As fast as normal LLM inference, without fully homomorphic encryption. Protect the model and the data, wherever AI runs.

Protected inference architectureAn authorized user encrypts a prompt, sends protected data into the inference boundary, and receives protected output for authorized decryption through the LLMcrypt inference architecture.TRUST BOUNDARY / 01ENCRYPTEDINPUT →PROTECTEDOUTPUT →PROTECTED LLMINFERENCE LAYERCOMPUTE WITHOUT EXPOSURE0x8F · 0x2A · 0xE1KEYED ACCESS
PROTECTED INFERENCENOVEL METHOD · NON-FHE
  • Encrypted input
  • Protected LLM
  • Authorized output
EXPLORE THE ARCHITECTURE
CLOUDON-PREMISEHYBRIDON-DEVICE
01 /

Protect the data

Keep sensitive prompts, context, and outputs confidential throughout inference.

02 /

Protect the model

Preserve ownership of proprietary AI as deployment moves beyond centralized APIs.

03 /

Unlock the infrastructure

Bring protected inference to cloud, enterprise, hybrid, and local environments.

01 / The structural problem

AI is becoming infrastructure.
Its boundaries haven’t caught up.

Sensitive data belongs with its owner. Proprietary models belong with their creators. Compute should be available wherever it is needed.

Today’s deployment choices put those priorities in tension. Cloud inference can move sensitive context outside an organization’s direct environment. Local deployment can expose proprietary model assets.

Better AI infrastructure needs to address all three.

Balancing model control, data privacy, and compute scalabilityMODEL CONTROLDATA PRIVACYCOMPUTE SCALELLMcrypt
  • Model control
  • Data privacy
  • Compute scale

ONE ARCHITECTURE. THREE DESIGN PRIORITIES.

02 / A different architecture

Encryption changes
the architecture.

Where inference runs changes who controls the boundary. LLMcrypt’s novel method protects models and data at normal inference speed, without fully homomorphic encryption (FHE).

Three deployments. Explicit ownership at every boundary.

01 / Deployment architecture

Provider model. Customer premises.

The LLM provider supplies the model. Inference runs on infrastructure controlled by the customer, with independent customer and provider protection layers.

Model owner
LLM provider
Infrastructure control
Customer
Key control
Customer + provider
Provider model. Customer premises.Customer prompt: Authorized input → Customer encryption: Customer-held data key → Provider protection: Provider-held model key → Model inference: Protected local runtime → Protected output: Customer ciphertext → Provider unprotects: Customer layer remains → Customer decryption: Customer-held data key → Customer result: Authorized plaintext. The customer controls the data key; the provider controls the model-protection key. Removing the provider layer leaves the customer layer intact.CUSTOMER DATA PROTECTIONPROVIDER MODEL PROTECTIONON-PREM EXECUTIONREQUEST →← RESULTCustomerpromptAuthorized inputCustomerencryptionCustomer-held data keyProviderprotectionProvider-held model keyModelinferenceProtected local runtimeProtectedoutputCustomer ciphertextProviderunprotectsCustomer layer remainsCustomerdecryptionCustomer-held data keyCustomerresultAuthorized plaintextProvider model. Customer premises.Customer prompt: Authorized input → Customer encryption: Customer-held data key → Provider protection: Provider-held model key → Model inference: Protected local runtime → Protected output: Customer ciphertext → Provider unprotects: Customer layer remains → Customer decryption: Customer-held data key → Customer result: Authorized plaintext. The customer controls the data key; the provider controls the model-protection key. Removing the provider layer leaves the customer layer intact.CUSTOMER DATA KEYPROVIDER MODEL KEYON-PREM EXECUTIONCustomerpromptAuthorized inputCustomerencryptionCustomer-held data keyProviderprotectionProvider-held model keyModelinferenceProtected local runtimeProtectedoutputCustomer ciphertextProviderunprotectsCustomer layer remainsCustomerdecryptionCustomer-held data keyCustomerresultAuthorized plaintext

02 / Deployment architecture

Company model. Cloud infrastructure.

The company owns or controls the model. A cloud provider supplies the infrastructure, while protected execution separates the workload from the infrastructure operator and other tenants.

Model owner
Company
Infrastructure control
Cloud provider
Key control
Company
Company model. Cloud infrastructure.Company application: Company model & data → Encrypt prompt: Company-held keys → Cloud infrastructure: Cloud-operated compute → Model inference: Decrypt inside runtime → Encrypted result: Encrypted in runtime → Protected return: Across cloud boundary → Company decryption: Company-held keys → Company result: Authorized application. Plaintext is made available for inference inside the protected execution environment. The cloud supplies compute; the company retains control of its keys and returned result.COMPANY DATA + MODEL PROTECTIONCLOUD INFRASTRUCTUREPROTECTED EXECUTIONREQUEST →← RESULTCompanyapplicationCompany model & dataEncryptpromptCompany-held keysCloudinfrastructureCloud-operated computeModelinferenceDecrypt inside runtimeEncryptedresultEncrypted in runtimeProtectedreturnAcross cloud boundaryCompanydecryptionCompany-held keysCompanyresultAuthorized applicationCompany model. Cloud infrastructure.Company application: Company model & data → Encrypt prompt: Company-held keys → Cloud infrastructure: Cloud-operated compute → Model inference: Decrypt inside runtime → Encrypted result: Encrypted in runtime → Protected return: Across cloud boundary → Company decryption: Company-held keys → Company result: Authorized application. Plaintext is made available for inference inside the protected execution environment. The cloud supplies compute; the company retains control of its keys and returned result.COMPANY-HELD KEYSCLOUD INFRASTRUCTUREPROTECTED EXECUTIONCompanyapplicationCompany model & dataEncryptpromptCompany-held keysCloudinfrastructureCloud-operated computeModelinferenceDecrypt inside runtimeEncryptedresultEncrypted in runtimeProtectedreturnAcross cloud boundaryCompanydecryptionCompany-held keysCompanyresultAuthorized application

03 / Deployment architecture

Provider model. Edge device.

The provider distributes its model onto an end-user device. Prompts and inference stay local, on a phone, laptop, vehicle, or embedded device outside the provider’s direct infrastructure.

Model owner
LLM provider
Infrastructure control
End-user device
Key control
Provider + device authorization
Provider model. Edge device.User prompt: Entered on the device → Phone / edge application: Local input handling → Provider protection: Provider-controlled key → Local model inference: Isolated device runtime → Protected output: Stays on the device → Provider verification: Unprotect / verify locally → Phone / edge application: Authorized result access → User result: Displayed on the device. The provider controls model protection, while the authorized application displays the result. The user’s prompt does not need to travel to the provider’s cloud.DEVICE APPLICATION BOUNDARYPROVIDER MODEL PROTECTIONLOCAL EXECUTIONREQUEST →← RESULTUserpromptEntered on the devicePhone / edgeapplicationLocal input handlingProviderprotectionProvider-controlled keyLocal modelinferenceIsolated device runtimeProtectedoutputStays on the deviceProviderverificationUnprotect / verify locallyPhone / edgeapplicationAuthorized result accessUserresultDisplayed on the deviceProvider model. Edge device.User prompt: Entered on the device → Phone / edge application: Local input handling → Provider protection: Provider-controlled key → Local model inference: Isolated device runtime → Protected output: Stays on the device → Provider verification: Unprotect / verify locally → Phone / edge application: Authorized result access → User result: Displayed on the device. The provider controls model protection, while the authorized application displays the result. The user’s prompt does not need to travel to the provider’s cloud.DEVICE APPLICATIONPROVIDER PROTECTIONLOCAL EXECUTIONUserpromptEntered on the devicePhone / edgeapplicationLocal input handlingProviderprotectionProvider-controlled keyLocal modelinferenceIsolated device runtimeProtectedoutputStays on the deviceProviderverificationUnprotect / verify locallyPhone / edgeapplicationAuthorized result accessUserresultDisplayed on the device

Who can access the model, prompts, outputs, and cryptographic keys at each stage? Each architecture makes those boundaries explicit.

DATAInputs and related context are protected through inference.

MODELControlled model execution preserves ownership across environments.

COMPUTEAn architecture for cloud, local, hybrid, and multitenant infrastructure.

Follow a protected request

Intelligence goes in.
Confidentiality stays intact.

Step through the flow from a private prompt to an authorized response.

USER ENVIRONMENT01 / 04
PLAINTEXT · AUTHORIZED ACCESS
Analyze confidential patient record

The request begins in the user’s environment. Plaintext is visible to the authorized user.

01 INPUT02 ENCRYPT03 COMPUTE04 DECRYPT

03 / Deployment freedom

Same boundaries.
Different places to run.

One encryption architecture, across three deployment patterns. Keep control of the model and data wherever inference runs.

01 /PROTECTED DEPLOYMENT
AUTHORIZEDUSERCLOUDINFERENCE
  • Authorized user
  • Cloud inference

Cloud execution

Use the cloud. Keep the context private.

Authorized users encrypt prompts before sending them to infrastructure that operates on protected information.

02 /PROTECTED DEPLOYMENT
MODELPROVIDERLOCALHARDWARE
  • Model provider
  • Local hardware

Local / on-device

Move the model. Preserve ownership.

A protected proprietary model runs on authorized hardware, from workstation GPUs to enterprise edge servers.

03 /PROTECTED DEPLOYMENT
ISOLATEDTENANTSSHAREDCOMPUTE
  • Isolated tenants
  • Shared compute

Multitenant / hybrid

Share compute. Maintain separation.

Isolated encrypted channels let organizations use shared infrastructure while retaining their confidentiality boundaries.

04 / What becomes possible

Built for the information
that matters most.

For organizations whose AI ambitions are constrained by where their data or models can go.

01 /

Enterprise AI

Your knowledge. Your boundaries.

Explore application +

Enterprise copilots working with proprietary business information, internal documents, and sensitive operational context.

PRIVATE / HYBRID
02 /

Healthcare

Intelligence for sensitive care.

Explore application +

Clinical AI applications involving sensitive information, where confidentiality and institutional control are essential design requirements.

INSTITUTIONAL / CLOUD
03 /

Government

Public services. Protected information.

Explore application +

Citizen and institutional services with controlled deployment, including isolated groups of authorized public institutions.

ON-PREMISE / MULTITENANT
04 /

Cloud providers

Compute without taking custody.

Explore application +

Infrastructure that could execute models belonging to AI vendors, enterprises, or governments while respecting information and ownership boundaries.

PUBLIC / PRIVATE CLOUD
05 /

AI model providers

Keep ownership. Expand distribution.

Explore application +

New ways to distribute proprietary models beyond a centralized API, with controlled execution in authorized customer environments.

CLOUD / DISTRIBUTED
06 /

Device & OS ecosystems

Bring protected AI closer.

Explore application +

Protected models that could run on workstations, AI PCs, enterprise edge servers, and other capable local hardware.

EDGE / ON-DEVICE

05 / The infrastructure opportunity

AI can be distributed.
Trust shouldn’t have to be.

Move inference closer to available compute, while keeping security boundaries intact.

Protected workloads across a distributed compute networkPUBLIC CLOUDENTERPRISEPRIVATE DATA CENTEREDGEWORKSTATIONSPERSONAL DEVICESHYBRID CLOUDLLMcrypt

From centralized infrastructure to a network of authorized environments. LLMcrypt’s ambition is to make protected AI inference location-independent.

Explore the opportunity

06 / Technical perspective

Different mechanisms.
Different guarantees.

Privacy technologies solve different problems. The distinction matters when both inference data and proprietary model assets need protection.

Privacy approaches differ in mechanism and purpose. LLMcrypt uses a novel LLM-encryption method, distinct from FHE.
ApproachDesigned to addressPractical considerationsModel distribution
PII maskingPreprocessingRecognized sensitive fields in promptsMissed entities, semantic leakage, and loss of context remain possible.Does not protect proprietary model assets.
Differential privacyStatistical privacyIndividual contributions to training or statistical analysisPrivacy budgets involve utility tradeoffs; private training adds complexity.Does not independently protect third-party execution.
Fully homomorphic encryptionCryptographic computationComputation over encrypted dataTransformer depth, nonlinear operators, and engineering overhead remain challenges. Research is advancing.Depends on protocol design; data encryption alone is insufficient.
LLMcryptNovel LLM encryption · non-FHEProtected LLM inference and controlled model executionAs fast as normal LLM inference. Quality, performance, and security evaluations completed.Protected model execution is the foundation for cloud, local, and hybrid deployment architectures.

Completed engineering milestones

Engineering delivered.
Milestones completed.

Model encryption, architecture evaluation, and advanced key control have been completed successfully. The method runs at normal LLM inference speed, without FHE.

01 / MODEL ENCRYPTION

Model encryption achieved.

A novel method for encrypting LLMs with normal inference speed. Protected input and output pathways, built around model-owner and authorized-user boundaries. No FHE.

COMPLETED SUCCESSFULLY
02 / EVALUATION

Architecture evaluated.

  • Pretrained models transformed
  • Training within the encryption architecture completed
  • Quality and inference overhead measured
  • Encryption performance evaluated
  • Security analyzed against established standards
COMPLETED SUCCESSFULLY
03 / KEY CONTROL

Advanced control implemented.

  • Model encryption-key rotation
  • Composite user–provider keys
  • Secret-sharing-inspired key architectures
  • Multilayer encryption keys
COMPLETED SUCCESSFULLY

07 / Company

A novel encryption method
for the next era of AI.

LLMcrypt has developed a novel method for encrypting LLMs that runs as fast as normal inference, without FHE. Our method lets intelligence move across cloud and local environments while preserving control of the data and the model.

AI providers, cloud operators, enterprise software companies, device ecosystems, governments, and regulated organizations each have a stake in this architecture.

Talk about the vision

Build what comes next

Intelligence shouldn’t come at the cost of privacy.

Encrypt LLMs at normal inference speed, without FHE. Talk with us about protecting your models and data.

Talk to LLMcrypt.For investors, infrastructure partners,
and teams building with sensitive data.

START A CONVERSATION 01 / CONTACT

Spam protection loads when you reach this form.

We’ll use your details to reply to your inquiry.