Startup Bets on Transparent Code Verification to Win Trust in Sensitive Computing
A Y Combinator-backed startup called Caution has emerged from private beta with a platform that attempts to solve one of the thorniest problems in cloud security: proving that the code running in a supposedly secure environment actually matches what developers reviewed. The company targets enterprises handling AI models and financial infrastructure, workloads where a breach or manipulation could carry nine-figure consequences.
At the heart of Caution's pitch is cryptographic attestation tied to reproducible builds. Co-founder and CEO Anton Livaja argues that current attestation methods leave users effectively trusting a black box. "There's no way to prove that the code in the enclave matches your source," Livaja wrote when announcing the platform on December 1, 2025. His solution: let anyone rebuild the code locally and verify it matches what's running in production by comparing outputs against live attestation data.
The platform deploys workloads to secure enclaves within minutes, at least on AWS Nitro infrastructure where it operates today. Support for Intel TDX, AMD SEV-SNP, and TPM 2.0 sits on the roadmap, though the company has been somewhat vague about exact timelines beyond pointing to development work underway.
Building trust through open verification
Caution exposes what it calls platform configuration registers and source manifests at a public "/attestation" endpoint. The verification process comes in two flavors: a complete rebuild from source code, or a faster check against pre-established trusted values. The company positions this as an industry first, though competitors might quibble with that framing.
The technical architecture includes STEVE, an end-to-end encryption system developed by Distrust (Caution's predecessor entity) that ensures plaintext data exists only on the client side and inside the enclave itself. A separate component called Locksmith handles secret delivery through quorum-based shard holders, releasing keys only after verifying workload identity.
Customers can choose from three deployment models. The fully managed option lets Caution handle infrastructure. A bring-your-own-compute approach runs in the customer's AWS account with scoped permissions. Self-hosted deployments fall under either AGPLv3 or a commercial license. The verification mechanism works the same way regardless of who operates the servers, which matters for enterprises skittish about vendor lock-in.

From consulting to product
The team of five grew out of Distrust, a security consultancy that claims experience securing systems holding north of $100 billion in assets, though the company does not clarify the specific nature of that involvement. Livaja and co-founder Lance Vick, who serves as CTO, lead the technical direction. Vincent Kobel handles product, Ryan Heywood focuses on security engineering, and Ksenia Lesko manages strategy and operations.
Distrust open-sourced the underlying runtime, EnclaveOS, late last year. A live demonstration at chat.caution.dev shows verifiable AI inference with public attestation, though the demo's polish suggests it may have seen updates since the original launch.
The company maps its technical controls to frameworks including NIST CSF 2.0, ISO/IEC 27001, SOC 2, and NIS2. It clarifies these are evidence mappings rather than certifications, a distinction that matters in procurement conversations where compliance checkboxes often drive purchasing decisions.
When bridges collapse
In a blog post published on June 30, 2026, dissecting the Taiko bridge exploit, Livaja defended his architectural choices while acknowledging broader industry challenges. He called the incident "a trust-model failure, not a TEE failure," pushing back against critics who saw it as evidence that trusted execution environments remain fundamentally flawed. His takeaway centered on avoiding single points of failure in cryptographic trust models, advice that predates modern secure enclaves by decades.
The analysis revealed something about Caution's positioning. Rather than claiming secure enclaves solve all problems, the company argues they need to be deployed correctly with proper verification chains. It's a more modest pitch than some competitors offer, though perhaps more realistic.
Crowded field, different approaches
Caution enters a market where established players have years of customer deployments. Edgeless Systems built MarbleRun around SGX with Kubernetes integration. Fortanix sells enterprise attestation management across multiple cloud providers, available through AWS Marketplace. Anjuna offers its own multi-TEE platform, though details about recent developments are sparse in public materials.

The major cloud providers themselves have moved aggressively into verifiable computing. Google highlighted "verifiable, private AI" features in Confidential Space through blog posts and updated documentation. Microsoft brought Azure Confidential VMs with Intel TDX to general availability in February. NVIDIA published attestation documentation for its H100, H200, and Blackwell GPU lines.
Those moves from hyperscalers raise an obvious question: why would enterprises choose a startup's abstraction layer when AWS, Google, and Microsoft offer native capabilities? Caution's bet appears to be that multi-vendor verification and source-code-anchored attestation provide differentiation the platforms won't match, at least not quickly.
Hardware diversification as hedge
The company's roadmap emphasizes reducing dependence on any single silicon vendor's root of trust. Cross-verifying enclave measurements across Intel, AMD, and other hardware should theoretically make certain supply chain attacks harder to execute undetected. Whether customers will pay for that additional assurance depends partly on how they model threats.

Livaja has been candid about current limitations. "Caution runs on AWS Nitro Enclaves today," he wrote in the Taiko analysis, acknowledging that broader hardware support remains in development rather than production-ready. That timeline matters for prospects evaluating the platform now versus waiting for multi-vendor capabilities to ship.
The company maintains a live demo and public attestation endpoints, unusual transparency for enterprise security tooling. Whether that openness helps build trust or simply provides more surface area for scrutiny will likely determine how quickly Caution can convert pilot deployments into production contracts. For now, the startup is making a straightforward wager: that in high-stakes computing environments, being able to independently verify what's running matters enough to justify another platform layer.
