Zero-trust advertising infrastructure
Advertising that is private, secure, and accurately measured at the same time — interest data that never leaves the device, blind auctions, and zero-knowledge attribution.
Who we want to build it with
Privacy engineers and publishers frustrated with the current model
Logged 28 June 2026
Digital advertising conflates three problems that do not actually require each other: privacy violation, security vulnerability, and attribution fraud. Effective, accurately measured advertising can be simultaneously private, secure, and fraud-resistant — the current model just was never designed with any of those goals in mind.
The architecture we keep sketching
- An on-device interest vault — encrypted, user-owned, never visible to advertisers. Philosophically different from proposals where the browser still reports your interests outward.
- Blind auctions — advertisers submit sealed bids against contexts, and the device itself evaluates matches locally. The server learns an ad was shown; it never learns to whom.
- Zero-knowledge attribution — advertisers get cryptographically verified conversion counts without learning anything about the individuals converting. More reliable than cookie-based attribution, not less.
- Isolated ad rendering — creative that can display pixels and handle a click, and do nothing else. Malvertising stops being a risk to manage and becomes architecturally impossible.
The cryptographic primitives — homomorphic evaluation, secure multi-party computation, trusted execution — are mature enough for production. What is missing is infrastructure designed around them from the start.
This is early thinking, shared openly on purpose. If you work in privacy engineering or run a publication that hates what advertising currently requires of it, we want to hear from you.