Targon (SN4) shipped TargonOS live to production, officially making it the first permissionless compute network offering VM rentals rather than containers.

The upgrade lets customers rent GPU and CPU virtual machines with root access from day one, hardware-attested isolation, and end-to-end encrypted workloads underneath. TargonOS now provides a dedicated VM (Virtual Machine) for each customer workload directly, rather than leaving miners to manage confidential VMs themselves as the previous TargonVM setup required.
This gives a compute experience closer to what cloud users already understand, with verifiable confidentiality backed by industry leaders like Intel underneath the interface.
What TargonOS Delivers
The launch build covers the core features that separate a real cloud experience from a confidential compute demo.
1. Rentable GPU and CPU VMs: Both compute classes available on demand, priced per usage.
2. Root access from day one: Customers get full control of the machine they rent, not a sandboxed slice of it.
3. Hardware-attested isolation: The confidentiality guarantee is verifiable at the chip level rather than trusted on the operator’s word.
4. End-to-end encrypted workloads: Data stays encrypted from the customer’s session through the compute layer.
The combination gives developers and enterprises the same kind of environment they get from a major cloud provider, with the difference that the isolation and encryption are cryptographically provable.
What Changed From the Old Setup
TargonVM previously required miners to host confidential VMs, with customer workloads deployed inside those miner-managed environments. TargonOS restructures that flow:

1. Dedicated VM per customer workload. Every workload gets its own provisioned machine rather than sharing space inside a miner-managed VM.
2. Provisioning happens through TargonOS directly. The middleman layer between customer and confidential machine is gone.
3. Cloud-like experience with verifiable confidentiality. Users get the interface they already understand, with hardware-attested isolation attached rather than assumed.
4. Backed by industry infrastructure. Intel and other partners provide the confidentiality primitives underneath the network.
The shift matters because it lowers the operational complexity for both customers and miners. Customers no longer share provisioning space with other workloads. Miners no longer have to manage the confidential VM layer themselves.
A Cloud You Can Verify
TargonOS represents one of the sharper positioning moves the Bittensor ecosystem has produced this year. A permissionless network renting real VMs with verifiable confidentiality attaches every advantage of the traditional cloud experience to the trust guarantees only a decentralized network can offer.
For developers, the interface is familiar. For enterprises with confidentiality or compliance requirements, the isolation is provable.
For the ecosystem, the launch redefines what a Bittensor compute subnet can actually ship. TargonOS is live for anyone ready to move workloads onto verifiable, dedicated infrastructure.
Enjoyed this article? Join our newsletter
Get the latest TAO & Bittensor news straight to your inbox.
We respect your privacy. Unsubscribe anytime.
Enjoyed this article?
Join our newsletter
Get the latest TAO & Bittensor news straight to your inbox — every morning before markets open.





Be the first to comment