Back to directory
Enterprise infrastructure · Cybersecurity

Caution

Know what runs on a server

ceo, co-founder and security engineer @CautionHosting YC (S26) - the verifiable compute hosting platform | https://t.co/xcTercS7a8 maintainer
2.2K followers
TLVC Rating
Hook
Editing / Creativity
Copy
Sentiment of launch
Distribution strategy
Community Rating
No ratings yet
Your rating
Sign in to rate this launch.

About

Caution is a hosting platform aimed at teams running workloads they cannot afford to have tampered with or exfiltrated, such as AI inference, crypto custody, fintech ledgers, and healthcare systems. Developers deploy their software into secure enclaves and then hand customers, auditors, or counterparties a cryptographic proof that the exact release approved in the build pipeline is what is actually executing in production, rather than an opaque binary they have to take on faith. The company pairs reproducible builds, so an enclave image can be independently rebuilt from source and matched against what is deployed, with multi-hardware attestation, so proofs do not rest on a single vendor's root of trust like Intel TDX, AMD SEV, or AWS Nitro. The launch matters now because confidential compute has largely stayed in the "trust us" zone, where attestation confirms code has not changed at runtime but cannot confirm what the code originally was. Caution's argument is that attestation without reproducible builds is still a black box, since there is no way to prove the code in the enclave matches the published source. The company positions the platform as fully open source infrastructure that customers and outside reviewers can inspect, which is unusual for hosting products in this category. It is currently in private beta, with access gated through a conversation with their engineering team. Caution is part of Y Combinator's S26 batch and was founded by Anton Livaja, CEO, and Lance Vick, CTO, both longtime security engineers channeling prior work securing high-value systems into the product. For founders and operators evaluating where to put sensitive services, the launch is worth a look as an alternative to standard cloud hosting when the question "what is actually running on that server right now" has to be answerable with evidence rather than a status page.
Tags
<500KSeedProduct launchB2BGlobalAI-generatedUS
Comments (15)
Sign in to join the discussion.
Priya Raghavan8d ago

The pitch is tight but I need to know: is the demo hitting a real enclave or is that a very confident loading spinner?

Moussa Dembélé8d ago

Deploying to enclaves in minutes is a bold promise. What happens when a customer's compliance team asks for the attestation trail six months later?

Tomas Lindqvist8d ago

Attestation as a product feature is one of those things every security team asks for and then quietly forgets to implement. Curious how you handle key rotation without breaking the proof chain.

Lucia Sombra8d ago

Feels adjacent to what Fly and Turnkey are circling from different angles. The verifiable prod release angle is the sharpest wedge I've seen in the space.

Kwame O.8d ago

"software you can't afford to have hacked" is such a menacing tagline. Half your leads are going to arrive already sweating.

Reyna Alcázar8d ago

Every enclave demo I've ever seen works flawlessly on stage and then falls apart the moment a real workload with real dependencies shows up. Prove me wrong.

Mei Tanaka8d ago

Docs or it didn't ship. Where's the SDK repo and does the quickstart actually take minutes or is that marketing minutes?

Farida Nasser8d ago

S26 batch already flexing. The tweet copy reads like a founder who's had this exact argument with a CISO 40 times.

Chidi Okafor8d ago

How small is the team behind this? Enclave hosting is not a two-person weekend project so I'm genuinely curious about the shape of the crew.

Ravi J.8d ago

First 10 seconds of the launch video do their job but the cut to the dashboard is jarring. Someone tell the editor about cross-fades.

quietsage8d ago

You don't get to say your binary is trustworthy. The math does.

Jorge Villanueva8d ago

We tried to ship something like this internally around 2020 and it died in a security review meeting. Glad someone is doing it as an actual product.

Anya Volkova8d ago

The landing page buries the deploy flow under three paragraphs of trust language. Show the terminal in the hero, not the manifesto.

Hana K.8d ago

Been three weeks out from launching my own security thing for about eight months. This tweet just made me close my laptop and rethink my life.

Ilya Bergman8d ago

Building in the runtime security space and honestly this framing is cleaner than what most of us have been using. Slightly annoyed, mostly impressed.