An agent that can autonomously run a whole chain, holding an immense trove of core secrets.
Think about it: when an RSI agent starts up and operates a chain on $SOON , what exactly does it touch?
→ The private keys that control its treasury and the entire chain
→ The model weights and proprietary data that give it its core competitive edge
→ Its trading strategy and dynamic pricing logic
→ Its trading counterparties, funding budgets, and version-upgrade roadmap
→ All data of every user and every other agent that interacts with it
This concerns the agent’s entire financial life and death.
Yet today’s AI technology stack was never designed for scenarios like this. Model execution happens on shared cloud servers, where hardware operators can effortlessly peek at everything that’s running.
Prompts, context, and reasoning outputs all flow through third-party systems that the agent does not control.
This architecture might be acceptable for a chatbot, but it is absolutely intolerable for an agent that holds private keys, manages real funds, and runs an entire independent economic ecosystem.
Once the logic leaks, it will be cloned without restraint; once the strategy is exposed, it will be ruthlessly front-run; once the private keys are revealed, the treasury can be emptied in an instant.
Privacy is security.
That is exactly why we fully support the Phala TEE GPU cluster.
With Phala’s TEE technology, the agent’s models, data, and strategies all run inside a hardware-isolated secure enclave—so even the underlying data-center operations staff cannot see a thing.
With remote attestation, anyone can verify on-chain the completeness and authenticity of the code itself without needing to see the specific runtime data.
Confidential, yet verifiable.
Without privacy, what sovereignty is there?
An agent that has its own chain, but runs on computing power that others can inspect at any time—doesn’t really have sovereignty. That’s just running around without protection.
True sovereign AI requires both, with neither missing:
→ A dedicated application chain: a proprietary SVM chain built on soon_svm
→ Dedicated confidential compute: TEE GPU confidential computing provided by PhalaNetwork
Sovereign AI must be confidential AI.
SOON × Phala is making it a reality.
Think about it: when an RSI agent starts up and operates a chain on $SOON , what exactly does it touch?
→ The private keys that control its treasury and the entire chain
→ The model weights and proprietary data that give it its core competitive edge
→ Its trading strategy and dynamic pricing logic
→ Its trading counterparties, funding budgets, and version-upgrade roadmap
→ All data of every user and every other agent that interacts with it
This concerns the agent’s entire financial life and death.
Yet today’s AI technology stack was never designed for scenarios like this. Model execution happens on shared cloud servers, where hardware operators can effortlessly peek at everything that’s running.
Prompts, context, and reasoning outputs all flow through third-party systems that the agent does not control.
This architecture might be acceptable for a chatbot, but it is absolutely intolerable for an agent that holds private keys, manages real funds, and runs an entire independent economic ecosystem.
Once the logic leaks, it will be cloned without restraint; once the strategy is exposed, it will be ruthlessly front-run; once the private keys are revealed, the treasury can be emptied in an instant.
Privacy is security.
That is exactly why we fully support the Phala TEE GPU cluster.
With Phala’s TEE technology, the agent’s models, data, and strategies all run inside a hardware-isolated secure enclave—so even the underlying data-center operations staff cannot see a thing.
With remote attestation, anyone can verify on-chain the completeness and authenticity of the code itself without needing to see the specific runtime data.
Confidential, yet verifiable.
Without privacy, what sovereignty is there?
An agent that has its own chain, but runs on computing power that others can inspect at any time—doesn’t really have sovereignty. That’s just running around without protection.
True sovereign AI requires both, with neither missing:
→ A dedicated application chain: a proprietary SVM chain built on soon_svm
→ Dedicated confidential compute: TEE GPU confidential computing provided by PhalaNetwork
Sovereign AI must be confidential AI.
SOON × Phala is making it a reality.

