prinet
Private SI inference · live

Ask anything.
Reveal nothing.

PRINET runs open models on GPUs that people contribute, and splits your prompt into secret shares so no single machine can read it. Uncensored, decentralized, and private by a number you can check.

  • No content filter
  • No datacenter
  • No prompt history

Send the same prompt through

How a private run works

Three steps between your words and the answer.

01 / Split

Your words never travel whole.

The model's activations are cut into two secret shares. Each node computes on its own share and never holds the real tensor. One share on its own is noise.

Share A

alone: noise

Share B

alone: noise

both shares together - the only way back to the prompt

02 / Route

Run by people, not a cloud.

Contributed GPUs are pooled into swarms that serve open models - no datacenter, and no content-policy layer in between.

03 / Measure

Privacy with a number on it.

0.21%

We score one node's view for how much of the prompt comes back. A run only counts as private if that number sits at chance.

One PRINET share0.21%
Chance0.20%
Undefended100%

Why this exists

Splitting a model isn't hiding a prompt.

The leak

The model is public. On a sharded network, your prompt can be too.

promptoutputEntrylayers 0-15exposedNode 2layers 16-31Node 3layers 32-47Exitlayers 48-63exposed

Spreading layers across strangers' GPUs solved the size problem. But every node still handles real activations, and with the weights public, those can be traced back to your words. Entry and exit see the most. PRINET was built to measure that exposure, and close it.

The evidence

What one node can recover.

Five ways to run a model, one question: given a single node's view, how much of the prompt comes back? Each is scored against live model shares, not estimated.

Anything that doesn't split the data leaks almost all of it. Privacy has a price, and we print it: 2.42 MiB of extra traffic per token.

See the method
PRINET · recovery by setup
Hosted API100%

Your prompt arrives as plain text, and can be logged.

Open weights, local100%

Raw activations at every layer.

Open-weight obfuscation100%

Any transform you apply, an attacker with the weights can undo.

Sharded, multi-node94–100%

Every hop handles real activation tensors.

PRINET, one 2PC share0.21%

At chance: no better than guessing.

Chance baseline0.20%

Get involved

Use it, build on it, or power it.

Recommended

Native Worker

Lend your GPU in the background through Ollama or vLLM. Serve the largest models and earn the top rate.

Top rate / token

npx @nuroaixyz/worker --token YOUR_TOKEN
Get the install command
Zero install

Browser Worker

Contribute straight from a browser tab with WebGPU. Nothing to install, no terminal.

Entry rate / token

Check your browser
User side

OpenAI-compatible API

Change one base URL and keep your code. Chat completions with no logging, billed per token.

Per token

POST /v1/chat/completions
Open the playground

Payments

$PRINET meters the network.

Every run is billed in tokens, not tracked in a profile. The chain records how much compute was used - never what was asked.

$PRINET CAExplorer ↗Dex ↗
01

Pay for compute, not with your data

Tokens are the billing unit. There is no prompt history and no profile behind them.

02

Usage funds the proof

30% of every settlement underwrites the research that keeps the privacy bound honest.

03

Nothing for failed jobs

If a run fails, it isn't charged.

Questions

Before you trust us with a prompt.

A network for private SI inference. Open models run on GPUs that people contribute, and your prompt is split into secret shares so no single node can read it. How well that works is measured and published in the Paper.

Not from its own view. A single share recovers 0.21% of a prompt - the same as guessing, which sits at 0.2%. The entry and exit nodes see the most, and the Paper says so plainly.

There is no per-request receipt yet. Today the guarantee is a measured gate: a run that doesn't meet the bound doesn't count as private.

A hosted API receives your prompt as plain text and can log it. Obfuscating open weights or simply sharding the model doesn't fix that - in our measurements they leak 94–100% of the prompt.

Any open model the network serves, with no content-policy layer in the way.

About 2.42 MiB of extra traffic per token to keep activations secret-shared. That's the price of the bound, and we publish it rather than hide it.

No. Bring a GPU - native or in a browser tab - and get paid per token you serve. Users pay for inference; workers don't front anything.

Inference is metered in $PRINET. 30% of every settlement funds the privacy research, and failed jobs aren't charged.

Only the one shown on this site. Any other address claiming to be $PRINET isn't ours.

Open Chat for a private run, Earn to attach a GPU, or the Paper for the full measurement. Questions go to PRINET on X.

Start here

Your words. Your business.

Talk to uncensored open models without handing your prompt to anyone. Or put an idle GPU to work and get paid for every token it serves.

Share latticeGame of Life