Patent Pending — multiple U.S. provisional applications · 7 claim families

Operator-blind AI for your app.

The SDK that ships substrate-locality, compute-economics, and cryptographic entropy as a single integration. Build AI features into your product without inheriting the privacy-attack surface that comes with model-provider APIs. Operator-blind data handling, verified compute accounting, and AI-derived entropy primitives — composable, portable, and underwritten by a family of U.S. provisional patent applications at Elo AI Co.

Four architectural properties, not aspirational ones: Data Sovereignty — user data never leaves the trust boundary unencrypted. Proof, not promises — verifiable via the EloProof framework, not vendor claims. Operator-Blind — the substrate operator (including us) cannot read user data by design. Breachless — a breach of operator infrastructure yields ciphertext only.

Three tiers. One substrate.

Pick your tier.

Tier 1

Indie

For solo developers, indie teams, side projects. The substrate-locality covenant + Family A core primitives. Per-call metering, BYOM-ready, MIT-style integration.

Best for: First substrate-locality integration. Prototype to production.

Sign up →

Tier 2

Standard

For growing companies and product teams shipping AI features at scale. Full Family A + Family B compute economics (ZK-verified inference, post-quantum settlement ledger, model-agnostic compute units). Per-customer scope enforcement. Hash-chained audit trail.

Best for: Privacy-first AI features in production. SOC 2 / HIPAA / GDPR machine-checkable.

Contact sales →

Tier 3

Enterprise

For Fortune-500, regulated industries, sovereign-data deployments. Full Family A + B + C, plus BYOM (Bring Your Own Model), per-tenant key isolation, dedicated audit-trail anchoring, SLAs, custom HKDF info-string namespaces.

Best for: Healthcare, financial services, defense, government, sovereign-data workloads.

Contact sales →

Bring Your Own Model

Your model. Our substrate. Operator-blind end-to-end.

Enterprise customers run their own model providers (OpenAI direct, Anthropic direct, Azure OpenAI, on-prem). The Elo SDK is provider-agnostic at the gateway.

Provider API keys are stored masked. Per-customer scope is enforced at the integration boundary. Failover to platform default is automatic if your provider is unavailable. The hash-chained audit trail anchors every call.

Backed by EloProof — seven verifiability layers operationalizing operator-blind. Read the framework →

What the SDK delivers

The integration shipment.

Family A · Substrate-Locality

HKDF-derived key trees

Per-tenant, per-subsystem, per-context. Cross-subsystem decryption structurally impossible.

Family A · Substrate-Locality

WebRTC operator-blind P2P

3-path peer rendezvous with DTLS certificate-to-fingerprint binding + hybrid post-quantum handshake extension.

Family A · Substrate-Locality

Lane Guard type primitives

Compile-time enforcement of scalar-only cross-context composition. Cross-kit data leakage is a compile error, not a runtime check.

Family B · Compute Economics

Verified compute accounting

Every inference call carries a signed, hash-chained record of consumption — provider-agnostic, machine-auditable. (Zero-knowledge proofs reserved for Elocoin Groth16 + the EloZKP roadmap; see EloProof.)

Family B · Compute Economics

Post-quantum settlement ledger

Tamper-evident, future-proof against quantum attacks. Universal Compute Units (UCU) standard.

Family C · Entropy

AI-derived entropy provisioning

Neural-network inference as cryptographic-grade entropy source via authenticated API with quality attestation. TLS / SSH / VPN / E2E integration.

Audit

Hash-chained audit trail

Every integration call SHA-256-anchored in a signed, append-only log. Claim 7.7 runtime invariant.

Distribution

Hollow-binary posture

Your shipped artifact contains zero extractable key material by design. Subpoena-proof, breach-proof, insider-proof.

For your acquirer

Acquisition-clean by construction.

If a strategic acquirer evaluates your company, the substrate-locality covenant is a feature, not a risk. Your AI architecture doesn't introduce a privacy-attack surface they'd have to absorb. You ship operator-blind by design; they inherit it operator-blind. Proof, not promises.

Get started

Talk to us.

SDK access opens alongside the Cognielo launch on July 17, 2026, with general availability in Q3 2026. Leave your email and tier below and we'll prioritize you — no newsletter, no drip campaign, just your access notice when your tier opens.

Prefer to talk directly — especially for Enterprise or BYOM evaluations spanning healthcare, financial services, defense, or sovereign-data deployments? Reach the SDK team at justin@eloai.co or through the secure channel at eloai.co/contact.

SDK customers inherit the cognielo.com subprocessor disclosure — see cognielo.com/subprocessors for the full processor list (Cloudflare and BAA scope).