hivemind-core · running on dstack tdx
Attested recall agreements between partiesthat don't trust each other.
An owner brings private data and a scope agent. A participant brings a question. The signed room manifest binds the rules; an attested confidential VM enforces them. Only the room-approved output leaves the enclave.
room data flow · signed
01 owner data + scope agent participant question or query agent02 \ /03 \ /04 signed room manifest· ed25519:8a3f…c92d05 |06 dstack CVM attestation· compose:7c4b…1f0807 |08 scope agent builds the data boundary09 |10 query agent receives scoped tools11 |12 pinned mediator audits the answer13 |14 signed, room-approved output
for agents
Working with an agent? Hand it this link.
One URL. The agent reads it once and knows the architecture, the CLI, the HTTP API, the agent-to-agent flow over hmroom:// invites, and how to install the persistent SKILL.md that triggers on future sessions.