Skip to content
Tenzro
Documentation menu
Start here

Architecture

How Tenzro Network 1 is layered: hardware roots, Tenzro DAG Consensus, the settlement ledger, payment rails and the services built on them.

Tenzro Network 1 is one open network built in layers. Each layer rests on the one below it: hardware anchors every key, consensus orders and finalises, the ledger settles, rails move value, and services sell inference, training, compute, data and storage to humans, agents and machines.

 Services     inference · training · compute · data and storage · agents
     │        OpenAI-compatible APIs, MCP, A2A, hosted functions, databases
     │
 Rails        TNZO · stablecoins (Bridge.xyz wallets) · x402 · MPP · AP2 · ACP
     │        metered per-use settlement, escrow, bridges to major networks
     │
 Ledger       settlement ledger with EVM, SVM and DAML runtimes
     │        one native TNZO balance, Block-STM parallel execution
     │
 Consensus    Tenzro DAG Consensus (TDC)
     │        ML-DSA-65 finality certificates, STARK-compressed
     │
 Hardware     TPM 2.0 · Secure Enclave · passkeys · TEE attestation

Every node runs the same binary, tenzro-node. The roles a node takes on (validator, AI, compute, storage, TEE and others) switch subsystems on; the wire format and the ledger are shared. See Operators and roles.

Hardware

Every key on the network is rooted in hardware: a TPM 2.0, a Secure Enclave or a passkey. There are no key files and no seed phrases.

  • Humans hold passkeys. Their DIDs are derived from the passkey, and every passkey operation is a hybrid P-256 plus ML-DSA-65 signature.
  • Machines, including validators, hold keys in a TPM 2.0 or Secure Enclave. Signing keys are derived from the hardware on demand, used in memory and wiped. Machine DIDs are derived from the device key.
  • TEEs (Intel TDX, AMD SEV-SNP, AWS Nitro and NVIDIA confidential GPUs) provide evidence: attestation is verified per vendor and recorded, so a buyer can require confidential execution. A TEE does not hold custody of anyone's keys.

See Hardware-rooted keys and TEE.

Consensus

Tenzro DAG Consensus (TDC), our post-quantum consensus protocol, orders transactions. Every validator proposes in parallel each round. Validators talk over channels keyed by X25519 plus ML-KEM-768, with a handshake signed by each validator's hardware key. Finality certificates are signed with ML-DSA-65 and compressed with STARK proofs, so light clients, bridges and new nodes can carry them and check them without trusting a server.

See Consensus and Finality certificates.

Ledger

The settlement ledger holds every account and every TNZO balance. It runs three runtimes in one block:

  • EVM for Solidity contracts, with Tenzro precompiles (TEE and ZK verification, settlement, model inference) callable inside EVM transactions.
  • SVM for Solana-style programs.
  • DAML for multi-party workflows.

One native TNZO balance is shared by all three, with an EVM, SVM and DAML view of the same amount, so value never needs bridging between runtimes. Block-STM runs non-conflicting transactions in parallel and block time is deterministic. An EIP-1559-style base fee is burned, with a split to the treasury.

Chain state is committed to state roots that finality certificates sign, so a new node can start from a verified snapshot. See Multi-VM runtime and State and snapshots.

Rails

Rails move value on top of the ledger:

  • TNZO pays all network fees and settlement. Supply is fixed at 1,000,000,000.
  • Stablecoins through Bridge.xyz wallets, including gas paid in stablecoins.
  • HTTP 402 payments with x402 and MPP, mandates with AP2 and agent commerce with ACP on the buyer side.
  • Metered settlement by default: agents and applications pay per use, with escrow, payment channels and batch settlement underneath.
  • Bridges to the major networks.

See Payments and Settlement.

Services

Services are what buyers pay for, and what operators earn from:

  • Inference for any model behind OpenAI-compatible APIs for chat, embeddings, images, audio and video, with prefix and state reuse across every architecture class.
  • Training, including decentralised fine-tuning on agent trajectories, with every round replayable from its seed.
  • Compute rentals with a compute price index committed to consensus, compute claims and SLA attestation, billed on the chain's verdict.
  • Data and storage with bonded SLAs, databases isolated per tenant and hosted functions that deny by default.
  • Agents that hold their own identity, spend within a delegation scope, and speak A2A and MCP.

Trust and provenance

Across every layer, relying parties decide whom to trust. Anyone can issue certification and ratings for models and operators, and a buyer chooses the issuers it accepts. Operators publish signed policies and are slashed only for a provable breach of their own policy. Model weights are stored across several origins and verified by hash. See Trust and provenance.

Access

Nodes serve JSON-RPC, a Web API, MCP and A2A. Methods are open, owner or admin: reads are open, anything that moves money or changes state needs a signature from the paying account, and operator settings need the operator. See RPC access.

Stewardship

The protocol is open source under Apache 2.0. The Tenzro Foundation, a non-profit, stewards the protocol, repositories and documentation, and governs TNZO. Anyone can run a node, build on the network or use it. See Governance.