Privacy‑preserving learning across sites, with differential privacy
- today · measured
- Each site learns from its own labels inside its boundary; residency is fail‑closed; Ryedore never sees a sensor value.
- next
- Secure aggregation of model updates with differential privacy and signed learning rounds; what one site learns about a failure is distilled into the shared model — a new site starts with what every other site has taught it, and no raw data moves.
- proof point
- Signed learning rounds in the verification bundle; measured warm‑start lift for a new site.

