HomeCompaniesCaution
Caution

Hosting platform for software you can't afford to have hacked

Caution is a hosting platform for software you can't afford to get hacked. It simplifies and extends confidential compute, and lets developers deploy workloads to secure enclaves in minutes and give customers, auditors, and counterparties cryptographic proof that production is running the exact reviewed source code, build, configuration, and runtime - not an opaque binary controlled by a cloud operator or internal admin. Confidential computing hardware exists, but the tooling is too fragmented and incomplete for most teams to use well. Today, attestation often proves only that a binary has a certain hash; it does not prove what source code produced that binary. Building the missing deployment, reproducibility, and verification layer requires specialized security engineering and often locks teams into one cloud or hardware stack. Caution turns that into a simple git-based workflow that builds reproducible enclave images, provisions infrastructure, and lets anyone independently verify what is running. We built Caution after years securing high-risk systems through Distrust, where we worked with hedge funds, custodians, blockchain teams, cloud platforms, and critical grid operators on systems responsible for more than $600B in assets. Again and again, the same problem showed up: teams running mission-critical infrastructure could not reliably prove what was executing in production. As AI, fintech, healthcare, and regulated data collaboration move into the cloud, "trust us" is no longer enough. Caution is a general-purpose platform: if it runs on a server, it can run verifiably on Caution. We're starting where trust failures cost the most, but we believe verifiable compute will become the default way software runs, the same way HTTPS became the default way it's served. Infrastructure you can verify, not trust.
Active Founders
Anton Livaja
Anton Livaja
Founder/CEO
Co-founder/CEO of Caution (YC S26). We give teams a hosting platform to run sensitive workloads in secure enclaves and cryptographically prove what code is running in prod. Previously co-founded Distrust, securing systems for hedge funds, custodians, and critical infra responsible for $600B+ in assets. Deep in confidential computing, supply chain security, and applied cryptography. Mission: improve the freedom, security, and privacy of as many people as possible.
Ksenia Lesko
Ksenia Lesko
Founder
Co-founder at Caution, where we help teams run sensitive workloads in secure enclaves and cryptographically prove what code is running in production. I lead the business and product side; previously ran strategy and ops at Distrust (distrust.co) and led customer education and activation at Ada (ada.cx).
Lance Vick
Lance Vick
Founder/CTO
Technology sovereignty maximalist. Lead security architect at Caution. Former security lead at Turnkey, BitGo, Unit 410, Pebble. Founded Stagex Linux distribution, and #! decentralized hackerspace. Experienced in Linux hardening, privacy, software engineering, security auditing, cryptographic key management, tamper evidence, HSMs, and supply chain security. Frequently internet infamous for exposing security negligence. Prolific mechanical puzzle collector, lockpicker, and hardware hacker.
Company Launches
Caution: Hosting platform for software you can't afford to have hacked
See original launch post

Hey everyone! We're Anton Livaja, Lance Vick, and Ksenia Lesko from Caution.

TL;DR: Caution is a hosting platform for software you can't afford to have hacked. Your software and data Istay protected even if your CI/CD pipeline, host infrastructure, or a developer laptop gets compromised. You go from source to a verifiable deployment in three commands. 

Built for: payment processors, PHI processors, AI agents, policy and fraud engines, secrets management, and other sensitive workloads.

https://drive.google.com/file/d/1u-l2TSBQO2t5dbhBsatCkZf5earCTyDD

Why we built this

On February 21, 2025, attackers stole $1.5 billion worth of Ethereum from Bybit, the largest digital heist in history. They never breached Bybit's own infrastructure: North Korea's Lazarus Group compromised a single developer machine at Safe{Wallet}, Bybit's multisig provider, and injected malicious JavaScript into the signing interface. Bybit's team approved what looked like a routine transfer and handed over a cold wallet to the attackers. The code everyone trusted was not the code that was running.

This keeps happening because nearly all software runs on blind trust:

  • trust in the cloud host
  • trust in production admins
  • trust in CI/CD
  • trust that the code you reviewed is the code actually running

If any part of that chain is compromised, an attacker can read your secrets, tamper with your business logic, or quietly run code your team never reviewed. It's the same failure behind SolarWinds and Codecov: tampered code arriving through a trusted channel, passing every check. Caution exists to shrink that attack surface and make the most sensitive systems verifiable.

Caution proves exactly what's running on your server

Cryptographically, and in real time. Deploying into secure enclaves normally takes a specialist team and months of integration. Caution automates the entire flow: source to verifiable deployment in minutes, with three commands:

uploaded image

🎥 Watch Anton walk through the platform

Under the hood, Caution is a verifiable confidential compute platform: hardware-backed cryptography isolates your workloads, preserves data privacy, and proves what software is running on a server in real time. The entire platform is open source, so verification never requires trusting us. In practice, this eliminates entire classes of attacks out of the box:

  • Build & CI/CD tampering: reproducible, multi-party signed builds mean injected code can't pass as a legitimate release.
  • Infrastructure & insider compromise: a compromised cloud account, admin, or laptop can't silently swap what's running.
  • Runtime data theft: data is processed in hardware-isolated enclaves, unreadable even to the host, the cloud provider, or us.

Caution guards against everything but first- or third-party code bugs: if the release you approve has a flaw, that's what runs. Nothing can be added, no fix can be stripped out, and every patch is provably live.

Why now

With advances in AI, attacks that used to require rare, expensive expertise are now cheap and scalable, and the gap between a vulnerability existing and being exploited is collapsing toward zero. Reactive patching was already losing. It can't win a race against automated attackers.

In the post-Mythos world, the security model has to flip. Infrastructure can no longer assume it won't be compromised. It has to be built to stay secure even when the host, the pipeline, or individuals with privileged access are compromised, and to prove, cryptographically, that it has. That's what Caution does.

Caution is a general-purpose platform: if it runs on CPU or GPU, it can run verifiably on Caution. We're starting where trust failures cost the most, but we believe verifiable compute will become the default way software runs, the same way HTTPS became the default way it's served.

Why us

Anton and Lance have spent their careers securing some of the most security-critical systems in the world: BitGo, Ledn, Turnkey, OpenZeppelin, and Unit 410 (later acquired by Coinbase). Across hundreds of engagements, from hedge funds to critical grid operators, the systems we've helped secure hold more than $600B in digital assets. Ksenia spent years helping enterprises adopt new technology, and now leads go-to-market, customer education, and operations at Caution, turning deep security engineering into a product companies can understand, buy, and use.

We've been the people companies call in when this class of attack hits. Teams needed stronger guarantees against supply chain and runtime attacks, but existing solutions were too hard, too bespoke, or too expensive. So we built the platform we kept wishing existed.

Traction

Caution is in production and onboarding customers spanning crypto infrastructure, blockchain labs, digital asset lending, consumer hardware, post-quantum security, and private AI inference.

We support AWS Nitro Enclaves today. Intel TDX, AMD SEV-SNP, TPM 2.0, NVIDIA Confidential Computing, and broader cloud support is in active development and coming soon.

Our ask

If you're running software where sensitive data must stay private or business logic can't be tampered with, we'd love to help you level up your security. Book 20 minutes with us or email us at founders@caution.co.

We'd especially love to hear from you if you're a:

  • security team that wants proof, not promises, from your infrastructure
  • fintech running payments, policy, or fraud engines
  • crypto custodian, exchange, or wallet team that can't afford another Bybit
  • healthcare or AI company processing PHI or other regulated data
  • team giving AI agents production credentials and losing sleep over it
  • company using AI inference with sensitive data

You can also learn more on our blog, and follow us on LinkedIn and X for updates.

Caution
Founded:2025
Batch:Summer 2026
Team Size:5
Status:
Active
Location:George Town, Cayman Islands
Primary Partner:Brad Flora