The SDK that ships substrate-locality, compute-economics, and cryptographic entropy as a single integration. Build AI features into your product without inheriting the privacy-attack surface that comes with model-provider APIs. Operator-blind data handling, verified compute accounting, and AI-derived entropy primitives — composable, portable, and underwritten by a family of U.S. provisional patent applications at Elo AI Co.
Four architectural properties, not aspirational ones: Data Sovereignty — user data never leaves the trust boundary unencrypted. Proof, not promises — verifiable via the EloProof framework, not vendor claims. Operator-Blind — the substrate operator (including us) cannot read user data by design. Breachless — a breach of operator infrastructure yields ciphertext only.
For solo developers, indie teams, side projects. The substrate-locality covenant + Family A core primitives. Per-call metering, BYOM-ready, MIT-style integration.
Best for: First substrate-locality integration. Prototype to production.
For growing companies and product teams shipping AI features at scale. Full Family A + Family B compute economics (ZK-verified inference, post-quantum settlement ledger, model-agnostic compute units). Per-customer scope enforcement. Hash-chained audit trail.
Best for: Privacy-first AI features in production. SOC 2 / HIPAA / GDPR machine-checkable.
For Fortune-500, regulated industries, sovereign-data deployments. Full Family A + B + C, plus BYOM (Bring Your Own Model), per-tenant key isolation, dedicated audit-trail anchoring, SLAs, custom HKDF info-string namespaces.
Best for: Healthcare, financial services, defense, government, sovereign-data workloads.
Enterprise customers run their own model providers (OpenAI direct, Anthropic direct, Azure OpenAI, on-prem). The Elo SDK is provider-agnostic at the gateway.
Provider API keys are stored masked. Per-customer scope is enforced at the integration boundary. Failover to platform default is automatic if your provider is unavailable. The hash-chained audit trail anchors every call.
Backed by EloProof — seven verifiability layers operationalizing operator-blind. Read the framework →
Per-tenant, per-subsystem, per-context. Cross-subsystem decryption structurally impossible.
3-path peer rendezvous with DTLS certificate-to-fingerprint binding + hybrid post-quantum handshake extension.
Compile-time enforcement of scalar-only cross-context composition. Cross-kit data leakage is a compile error, not a runtime check.
Every inference call carries a signed, hash-chained record of consumption — provider-agnostic, machine-auditable. (Zero-knowledge proofs reserved for Elocoin Groth16 + the EloZKP roadmap; see EloProof.)
Tamper-evident, future-proof against quantum attacks. Universal Compute Units (UCU) standard.
Neural-network inference as cryptographic-grade entropy source via authenticated API with quality attestation. TLS / SSH / VPN / E2E integration.
Every integration call SHA-256-anchored in a signed, append-only log. Claim 7.7 runtime invariant.
Your shipped artifact contains zero extractable key material by design. Subpoena-proof, breach-proof, insider-proof.
If a strategic acquirer evaluates your company, the substrate-locality covenant is a feature, not a risk. Your AI architecture doesn't introduce a privacy-attack surface they'd have to absorb. You ship operator-blind by design; they inherit it operator-blind. Proof, not promises.
SDK access opens alongside the Cognielo launch on July 17, 2026, with general availability in Q3 2026. Leave your email and tier below and we'll prioritize you — no newsletter, no drip campaign, just your access notice when your tier opens.
Prefer to talk directly — especially for Enterprise or BYOM evaluations spanning healthcare, financial services, defense, or sovereign-data deployments? Reach the SDK team at justin@eloai.co or through the secure channel at eloai.co/contact.
SDK customers inherit the cognielo.com subprocessor disclosure — see cognielo.com/subprocessors for the full processor list (Cloudflare and BAA scope).