Train locally
Each approved party trains on its own data, inside its own boundary. No raw records cross to anyone else.
→Share the model updates. Not the data. Train across sites and parties without records leaving the room they belong in — and see exactly what crosses the boundary on every round.
Each site trains in its own environment. Records never leave it.
Model weight updates travel. The data behind them stays put.
Who joined, what was aggregated, privacy budget left — on one record.
A competitor lost four terabytes — including who its workers were. Keep the records in the room. Train locally, share updates only, and aggregate the gain with the record included.
Each approved party trains on its own data, inside its own boundary. No raw records cross to anyone else.
→Model updates leave the site. The data does not. Secure aggregation and a privacy budget keep the spend-down visible.
→The round closes with a review record: who joined, what was aggregated, participant health, and the privacy budget left.
A round runs like any other release: approve the parties, aggregate the updates, gate the result, and keep the privacy budget with the record.
The data never moves. The proof does. Every round leaves a record the next one has to clear.
The weight updates each approved party submits — never the records behind them.
Differential privacy spend-down and remaining headroom, written down on every round.
Who joined, who dropped, what crossed the boundary, and the secure aggregation status.
An identity-verified record of the round and its verdict, attached to the release.
Test the run. Review the hard cases. Recruit the right specialist. Remember what each party can share. Approve what leaves review. Federation is the Remember stage — it learns across rooms while every record stays where it belongs.
Fine-tune with the rubric, the reviewers, and the data you already keep.
See the page →Deterministic environments for agents that need to be tested before they ship.
See the page →Access, audit, and retention written down without crossing the wall.
See the page →Bring the parties. Bring the boundaries. We handle the rounds, the privacy budget, and the proof.