Build, verify, and operate apps on Witbitz.
Witbitz is a trusted runtime for collaborative AI apps built around Spaces — backendless, content-blind, and verifiable. These docs run in three acts: build a tenant app, check the trust claims yourself, and run it hosted or in a boundary you control.
Build a tenant app, end to end.
Register a coupon-free tenant, build by embedding the reference Spaces, deploy on your own origin, then verify the trust claims yourself. Understand the model first, then follow the path.
Overview
What a Space is, how static apps use Witbitz, and where the deeper docs fit.
ArchitecturePlatform
The three layers, runtime services, topologies, and the live-call engine.
The modelAsync Spaces
The agent-as-a-function architecture and the content-blind poll model.
Privacy you can check, not just claims.
Neither the operator nor the app's own owner can read the users' data — and it's a property you verify from the code, not a promise you take. Each doc is precise about what is Production, Implemented, or Design; the full reality map is Status, and the checks run in your own terminal on Verify it yourself.
Trust model
The two guarantees — the double blind and delegated authority — what is protected, and what is not hidden.
ConfigurationPrivacy tiers
The maximal configuration, the orthogonal axes, and how named modes trade down.
Admission & lifecycleIdentity and admission
Key possession, signed entries, gated Spaces, OIDC, the owner rule, removal, and recovery.
The clientThe verified client
Verification and key confinement, the native attested client, and the verifier extension.
Unobservable in useAttested server tier
Run a Space's turns inside measured Nitro hardware, the key sealed to the image.
Run it wherever you need.
The same reproducible runtime, hosted or in a boundary you control. What is live, preview, built, and designed is tracked in Status.
Deployment options
Hosted private beta, enterprise VPC/on-prem, and air-gap in one map.
Reality mapStatus
Live, private beta, built-not-production, and designed work in one table.
Hosted private beta
Access, tenant keys, the public OpenAPI, and the checkable hosted evidence.
Customer boundaryEnterprise & on-prem
Run the runtime with your own model, storage, records, secrets, and IdP.
Zero egressAir-gap mode
What AIRGAP=1 changes, what still works, and what needs a local replacement.