Decentralized data collaboration

Match, Enrich & Verify —
Without PII Ever Leaving Your Firewall

Collaborate with any partner on your most sensitive data without pooling it in a centralized clean room. Your records stay behind your firewall — only the answer ever crosses.

0 bytes of PII leave your network.
Built on the same privacy cryptography (OPRF) behind Google Password Checkup and Apple Keychain.  ·  Patent pending.

Customer data
Retail & marketing — audience overlap and enrichment without exposing your list.
Patient records
Healthcare — match and study cohorts without moving protected health data.
Financial signals
Finance — share fraud and risk signals without revealing customers.
Three ways to wire it

One primitive. Three shapes of deal.

Match, enrich, and verify compose into the collaboration you actually need. Here's each one as a real marketing scenario — no list ever leaving its owner.

1 : 1

Audience overlap

A DTC coffee brand and a publisher find the customers they share, then target a co-branded campaign — neither hands over its list.

→ 311,402 matched · lists never exchanged
1 : many

Enrichment as a service

One provider's IP → intent signal, queried by thousands of marketers. Each enriches only the records it already holds.

→ in-market: auto-insurance · per-query metered
many : 1

A retail-media co-op

Independent retailers pool a premium-shopper audience an advertiser can target — no retailer sees another's customers, the co-op holds no raw PII.

→ 2,184 of 50,000 are premium shoppers

Walk through each, with diagrams and what crosses the wire → browse the examples

The difference

Every other way to collaborate makes you trust someone.

The whole category comes down to one question: what do you have to trust? Three answers ask you to trust a company, a chip, or a coin. One asks you to trust nothing but the cryptography.

Cloud clean rooms
Trust the platform.
Your data lands in a shared environment, everyone's on the same cloud, and you trust the operator's policies.
Confidential computing
Trust the chip.
A hardware enclave — and its manufacturer, and its resistance to side-channel attacks.
Web3 data markets
Trust the token.
A blockchain, a wallet, and a volatile coin standing between you and a simple match.
sharedata
Trust the math.
Nothing leaves your firewall. No central pool, no enclave, no chain — the cryptography is the guarantee.
clean room chip token — nothing but the math.
How it works

The answer travels. The data stays.

Three steps, two firewalls, zero raw records crossing between them.

STEP 01

Blind it locally

Your records are transformed into meaningless blinded values on your side of the firewall. The raw data never moves.

STEP 02

Evaluate blind

Your partner runs the match against their own data, under their own key — seeing only blinded values. Never your records, never their customers'.

STEP 03

Unblind the answer

Only the result crosses back: matched or not, or the enrichment you asked for. The answer is the one thing that travels.

For the geekier folks → read the full protocol, step by step

What you can do

Match. Enrich. Verify.

The cryptography does the heavy lifting. The operations are fast and secure.

Match

Find the overlap between your audience and a partner's — without either side revealing its list.

Enrich

Append a partner's signal — risk score, segment, intent — to records you already hold, for matches only.

Verify

Confirm a partner genuinely holds the users or attributes they claim — with cryptographic proof, not their word.

Guarantees, not promises

Architectural, not policy.

These aren't terms we pledge to honor. There's no step in the protocol where they could be broken.

01
No PII leaves your networkRecords are blinded on your side and stay there. Only blinded values and the final answer ever move.
02
We can't see your dataThere is no point in the protocol where your raw records reach us. Absence of access, not promise of restraint.
03
No central pool to breachNothing is gathered into one database — so there's nothing to leak, subpoena, or steal in bulk.
04
Auditable by youThe client is open-source. Verify the no-pool guarantee yourself instead of taking our word for it.
Questions, answered

The objections worth raising.

Isn't this just a clean room? +
No. A clean room still gathers both parties' data into one secure environment you have to trust. Here the data never leaves either side — the match runs across the firewall cryptographically, and nothing pools anywhere.
Where does my data actually go? +
Nowhere. It's blinded on your side and stays inside your firewall. Only blinded values and the final answer travel between parties.
Do I have to trust sharedata with my data? +
No. We are never in the data path — we ship the software and the directory. You can audit the open-source client to confirm we have no way to see your records.
What can it actually do? +
Matching, membership checks, enrichment, and verification — the operations cryptography does quickly. It is not a general analytics engine; for heavy joint analysis over arbitrary queries, a traditional clean room is the right tool.
How fast is it? +
The querying side performs a couple of lightweight cryptographic operations — fast enough to run in a browser. The heavier work sits on the data provider's own node.
Is it really decentralized? +
Yes. Each party runs its own side of the protocol; there is no central pool of data and no central server on the live path. The method is patent pending.
How do you make money if you never see the data? +
We sit in the billing path, not the data path — the way Stripe sits in the money flow without owning the product. To start, we license the rails for a flat or tiered fee. As the directory builds liquidity, we layer on a small marketplace take on usage, settled through cryptographically signed metering tokens that count queries without ever touching your records. Three signatures on every receipt, zero visibility into the data: that's how we get paid without becoming a honeypot.
Early access

Share data without exposing PII.
Come prove it to yourself.

See the protocol, audit the client, and run a pilot in a single vertical.

Request early access