Lucid Labs
We build the technology that lets the world trust the AI it buys and sells. Each idea travels from a first-principles sketch to deployed, open, secure infrastructure, and what we learn shipping it feeds the next one.
A verification idea enters unproven and comes back proven, deployed, and standardized in the open. Four stations, one loop.
A multi-silicon research cluster with open, bare-metal access.
with VCF Explore the cluster →Structured red-teaming with independent government teams.
Government red teams See the architecture →What we learn in deployment becomes open standards the industry can adopt.
IETF · CCC · OCP Learn more ↓Each idea moves through four stations: experiment, validate, deploy, standardize. What breaks under red-teaming feeds the next round of experiments, and what we learn running production clusters is what we propose as standards.
01 · Experimentation
Hardware verification, side-channel analysis, TEE research, network inspection. This work needs physical, bare-metal access to datacenter-grade GPUs that no cloud provider offers. So we built it, and opened it to the community in partnership with the Verifiable Compute Foundation.
Multi-silicon by design. A dedicated bare-metal cluster spanning NVIDIA H100, H200, and B300 (Blackwell) and AMD Instinct MI355X, because real verification can't assume one vendor's chip.
Root of the machine. BIOS/UEFI-level access, IPMI/BMC management, custom firmware, and NVIDIA Confidential Computing enabled: the access researchers need and clouds never grant.
Physical access, supervised. Qualified researchers run real experiments on real silicon; Lucid runs the physical experimentation to spec.
Silicon in the cluster
Verifiable Compute Foundation: operates the community research cluster with Lucid.
02 · Validation
An architecture is only as good as the attacks it withstands. Before a government will adopt verifiable compute, its own agencies have to try to break it. So we run structured red-teaming programs with national security agencies and government research institutes, on a Builder-vs-Breaker model where the people trying to break it are never the people who built it.
Red-teamed for government adoption. We run structured adversarial programs with national security agencies and government research institutes: the buyers who need the strongest possible proof before they trust verifiable compute.
Builder vs Breaker. The teams trying to break the architecture are never the teams who built it. Independent red teams keep full technical authority over their own methodology and reporting.
Four capabilities under fire: data residency, compute integrity, confidentiality, and AI Passports. Each one attacked, not asserted.
The output is public. Fully documented, open-source, state-backed reference architectures, built to be demonstrated to policymakers and submitted to standards bodies.
An 18-month validation program with a nation state actor, deploying our verification platform on real GPU infrastructure. The actor's cybersecurity group runs the adversarial testing and delivers formal vulnerability and penetration-test reports, retaining full technical authority over its own methodology.
Builder
Lucid deploys the verification platform on real GPU infrastructure.
Breaker
A nation state actor's red teams attack it independently and report what breaks.
◉ Nation-state red-team cluster
03 · Deployment
The mechanisms that survive experimentation and validation don't stay in the lab. We ship them as part of our NeoCloud offering for government and enterprise clients (verifiable AI compute as a service), and we publish the reference architectures as open hardware so anyone can build, inspect, and certify their own.
04 · Standards
Verifiable AI compute comes down to four questions that today are asserted but never proven. We turn each into evidence a regulator, a sovereign customer, or an auditor can independently verify, as open standards, so the whole industry can adopt them.
Where, physically, is the chip running this workload? Proven by ping-based location attestation: a bound derived from the speed of light, which no VPN can fake.
View the standard at sovcert.org →Who (and which agent) is using this chip, and did it stay in scope? Human identity-proofing, sanctions screening, and signed agent delegation chains.
What can the deployed model actually do? Independent, cryptographically signed evaluations bound to a specific model checkpoint.
How much compute, of what class, by whom? Hardware-rooted FLOP counting the operator can't reset.
Standards bodies & communities we engage with








Get in touch
Bring us your security and confidentiality specs. We'll show you what verifiable compute can prove, end to end.
© 2026 Lucid Computing · Research