Deploy to secure enclaves in minutes, isolate sensitive workloads, cryptographically prove what code is running.
Hey everyone! We're Anton Livaja, Lance Vick, and Ksenia Lesko from Caution.
TL;DR: Caution is a hosting platform for software you can't afford to have hacked. Your software and data Istay protected even if your CI/CD pipeline, host infrastructure, or a developer laptop gets compromised. You go from source to a verifiable deployment in three commands.
Built for: payment processors, PHI processors, AI agents, policy and fraud engines, secrets management, and other sensitive workloads.
https://drive.google.com/file/d/1u-l2TSBQO2t5dbhBsatCkZf5earCTyDD
On February 21, 2025, attackers stole $1.5 billion worth of Ethereum from Bybit, the largest digital heist in history. They never breached Bybit's own infrastructure: North Korea's Lazarus Group compromised a single developer machine at Safe{Wallet}, Bybit's multisig provider, and injected malicious JavaScript into the signing interface. Bybit's team approved what looked like a routine transfer and handed over a cold wallet to the attackers. The code everyone trusted was not the code that was running.
This keeps happening because nearly all software runs on blind trust:
If any part of that chain is compromised, an attacker can read your secrets, tamper with your business logic, or quietly run code your team never reviewed. It's the same failure behind SolarWinds and Codecov: tampered code arriving through a trusted channel, passing every check. Caution exists to shrink that attack surface and make the most sensitive systems verifiable.
Cryptographically, and in real time. Deploying into secure enclaves normally takes a specialist team and months of integration. Caution automates the entire flow: source to verifiable deployment in minutes, with three commands:
🎥 Watch Anton walk through the platform
Under the hood, Caution is a verifiable confidential compute platform: hardware-backed cryptography isolates your workloads, preserves data privacy, and proves what software is running on a server in real time. The entire platform is open source, so verification never requires trusting us. In practice, this eliminates entire classes of attacks out of the box:
Caution guards against everything but first- or third-party code bugs: if the release you approve has a flaw, that's what runs. Nothing can be added, no fix can be stripped out, and every patch is provably live.
With advances in AI, attacks that used to require rare, expensive expertise are now cheap and scalable, and the gap between a vulnerability existing and being exploited is collapsing toward zero. Reactive patching was already losing. It can't win a race against automated attackers.
In the post-Mythos world, the security model has to flip. Infrastructure can no longer assume it won't be compromised. It has to be built to stay secure even when the host, the pipeline, or individuals with privileged access are compromised, and to prove, cryptographically, that it has. That's what Caution does.
Caution is a general-purpose platform: if it runs on CPU or GPU, it can run verifiably on Caution. We're starting where trust failures cost the most, but we believe verifiable compute will become the default way software runs, the same way HTTPS became the default way it's served.
Anton and Lance have spent their careers securing some of the most security-critical systems in the world: BitGo, Ledn, Turnkey, OpenZeppelin, and Unit 410 (later acquired by Coinbase). Across hundreds of engagements, from hedge funds to critical grid operators, the systems we've helped secure hold more than $600B in digital assets. Ksenia spent years helping enterprises adopt new technology, and now leads go-to-market, customer education, and operations at Caution, turning deep security engineering into a product companies can understand, buy, and use.
We've been the people companies call in when this class of attack hits. Teams needed stronger guarantees against supply chain and runtime attacks, but existing solutions were too hard, too bespoke, or too expensive. So we built the platform we kept wishing existed.
Caution is in production and onboarding customers spanning crypto infrastructure, blockchain labs, digital asset lending, consumer hardware, post-quantum security, and private AI inference.
We support AWS Nitro Enclaves today. Intel TDX, AMD SEV-SNP, TPM 2.0, NVIDIA Confidential Computing, and broader cloud support is in active development and coming soon.
If you're running software where sensitive data must stay private or business logic can't be tampered with, we'd love to help you level up your security. Book 20 minutes with us or email us at founders@caution.co.
We'd especially love to hear from you if you're a:
You can also learn more on our blog, and follow us on LinkedIn and X for updates.