BKAI Official Logo Registered (3)
⌘K
Home About Solution
Get In Touch
Home
aAbout
sSolution
mMedia Center
pPress Releases
tThe HiveCast
mMedia Mentions
Blog
gGet In Touch
Back

EscrowAI Granted “Awardable” Status in the IARPA Solutions Marketplace

Blog Posts
Michael Blum·Sep 25, 2026· 7 minutes

BeeKeeperAI® is proud to announce that EscrowAI®, our confidential and verifiable AI execution platform, has been deemed Awardable through the IARPA Solutions Marketplace.

The IARPA Solutions Marketplace, launched in 2026 and run by the Applied Research Institute, gives Intelligence Community (IC) customers a faster way to find vetted commercial technology. Awardable status is granted through a competitive evaluation of each solution's alignment with shared IC problems, its technical merit, and its potential to meet IC mission needs.

For our team, the evaluation validated the problem we've worked on since BeeKeeperAI was founded in 2022: sensitive data and proprietary AI must be able to compute together while each remains fully protected and, in the era of agentic AI, while the AI acts only within its approved scope.

The problem: three things to protect

AI is only as good as the data it can compute on. For the IC, the data that matters most includes classified holdings, sovereign data of allied partners, and datasets held across agencies under different authorities. At the same time, AI and agentic AI are carefully guarded intellectual property. And in the era of agentic AI, protecting against agent behaviors adds a third security dimension. 

Bringing these together safely means protecting all three at once:

  • The data. Data must stay within its secure boundary to meet sovereignty and security rules, and in its raw form, with no masking, de-identification, or synthetic substitutes, to generate the most accurate outputs possible.
  • The model. Proprietary AI must be protected at rest, in transit, and during compute within the secure environment of the data holder(s). 
  • The mission. Autonomous agents must be kept within strict limits, so they can't leak data, be manipulated, or take actions no one intended.

The IC must also anticipate and address other risks: data exfiltration, models and agents memorizing sensitive inputs, and adversaries tampering with AI and data. As a result, AI solutions that could accelerate intelligence often stall or never get started because agencies, allies, and partners deem the risk too high.

Agentic AI raises the stakes

The next wave of AI, including agentic AI, can plan, make decisions, and take actions on their own. It can also query databases, call tools and APIs, chain many steps together, and work across systems at machine speed, often with little to no human oversight.

For the IC, agentic AI could greatly accelerate intelligence. But agents also add new risks:

  • Broader access. To be useful, agentic AI often needs access to several data sources and systems at once. Each added permission means more that could be exposed.
  • Prompt injection and manipulation. An adversary can hide instructions in a document, web page, or data feed the agentic AI reads, and trick it into leaking data or taking actions it shouldn't.
  • New leak paths. Sensitive data can leave through tool calls, API requests, generated content, or messages to other agents.
  • Retained memory. Agentic AI that maintains context or memory between tasks can hold on to sensitive information.
  • Hard-to-trace decisions. When agentic AI takes dozens of steps on its own, it's hard to reconstruct what it saw, what it did, and why, and that record is what oversight and accountability depend on.
  • Tampering. An adversary who alters the model, tools, or code an agent relies on can change what it does. Without monitoring and verification, no one may notice until the damage is done.

Every one of these risks calls for confidential and verifiable AI execution. When AI acts on its own, trust can't depend only on contractual requirements, policy, or good intentions. It must be enforced during execution and proven with tamper-proof records.

Why existing approaches fall short

Current practices address portions of the problem:

  • Data sharing agreements and manual reviews set the rules on paper, but they don’t technically enforce the contractual requirements or policies. 
  • Federated learning keeps data where it is, but it usually requires sending AI to each data holder for computing in their environment, which exposes its intellectual property to theft or attack during compute. 
  • Data sanitization and downgrading, such as masking, de-identification, and synthetic data, make data easier to share but can strip away the detail that makes it valuable, thereby reducing the precision of the outputs. They also leave the data at risk of re-identification. 
  • Cross-domain solutions move data between security levels in a controlled way, but they're built for transferring data, not for computing on it securely, and every transfer adds review time and risk. 
  • Advanced cryptographic methods, such as homomorphic encryption and secure multiparty computation, allow computing on encrypted data, but they can be slow and complex for large-scale AI work.

EscrowAI takes a different approach. It utilizes Trusted Execution Environments (TEEs) with confidential computing within its privacy-enhancing workflow to protect data and AI at the hardware level during compute (in use). TEE solutions protect confidentiality in memory, block outside software from tampering with the protected memory or AI while it runs, and use attestation to prove the environment is genuine. 

EscrowAI builds on this with a hardened TEE environment that includes third-party FIPS compliant public key management, telemetry to monitor for non-compliant behaviors, an immutable ledger of key activities during the computing cycle, schema (policy) checks before outputs are released, and automated commissioning and decommissioning. 

How EscrowAI works

EscrowAI protects the data and the AI, and contains agent behavior during execution: 

  1. Encryption end to end. Data and AI are encrypted at rest, in transit, and during compute, ensuring that neither party ever sees the other's asset in the clear.
  2. Attested, hardware-protected execution. Computation runs inside TEEs on AMD SEV-SNP, NVIDIA H100, and Intel TDX (for on-premise deployments). Remote attestation confirms that only approved models, agents, and tools are running before anything is decrypted.
  3. Third-party key management. Decryption keys are released only to attested environments, so no party or agent can compute on data it wasn't authorized to use. Each owner retains control of the keys to its own data and AI. 
  4. TEE Telemetry. 
  5. Output policy enforcement. Everything leaving the TEE is checked against a mutually approved schema, which closes off a key path for data exfiltration.
  6. Immutable audit ledger. Every step is recorded in a tamper-proof log, providing the traceability of what occurred within the computing environment.
  7. Automatic TEE commissioning and decommissioning. When the data holder authorizes a compute cycle, the TEE is automatically commissioned and activated. When the computing cycle is complete, the TEE is decommissioned, so no agent memory or sensitive context lingers.

Together, these controls place verifiable limits on how data and AI collaborations are conducted.

Mission impact: making challenging collaborations possible

When data and AI both stay protected, collaborations that were once extremely difficult or off the table become possible:

  • Safer adoption of AI agents. Agencies can put autonomous AI to work to support sensitive missions inside a controlled, attested, and auditable environment, instead of trusting that an agent will behave. 
  • Allied and coalition partnerships. Partners can collaborate on shared problems while each retains sovereign control of its data and AI.
  • Cross-agency analysis. Datasets that could never be pooled can be securely computed upon within their sovereign boundary without exposing intellectual property or taking on the risks of agent behavior.
  • Commercial AI on sensitive data. Agencies can use leading commercial and open-source models on protected data within the hardened TEE.
  • Faster approvals. The hardened TEE and protections within the EscrowAI workflow can shorten the legal, privacy, and security reviews that often stall AI adoption.

EscrowAI supports IARPA's focus on Cyber and AI Security. It isn't meant to replace the tools the IC already relies on. It provides the confidential and verifiable execution layer that lets AI and agents compute on highly sensitive data.

What's next

Being Awardable is a starting point. We look forward to working with IC mission partners on pilots that show measurable results in security, performance at scale, and review time, and that unlock collaborations that are currently stalled or extremely difficult to contract.  

We're grateful to IARPA and the Applied Research Institute for building a faster path from innovation to mission, and to our customers and partners who helped make EscrowAI what it is today.

Government customers: watch our five-minute EscrowAI solution video (registration required) in the IARPA Solutions Marketplace. 

Want to learn more? Contact us to talk about how EscrowAI can support your mission.


Comments

Please log in or register to post a comment
BKAI Official Logo Registered (3)
TERMS & CONDITIONS
PRIVACY POLICY
INTELLECTUAL PROPERTY
COOKIE POLICY
Copyright © 2026 BeeKeeperAI, Inc.