Skip to main content

HEIR: Homomorphic Encryption Intermediate Representation

GitHub Workflow Status (with event) GitHub Contributors GitHub Discussions GitHub License OpenSSF Scorecard

An MLIR-based toolchain for homomorphic encryption compilers. Read the docs at the HEIR website.

For more information on MLIR, see the MLIR homepage.

Quickstart

There are currently three ways to use HEIR:

  • Use bazel and rules_heir with either the OpenFHE or Lattigo backends.
  • Install OpenFHE and use the heir_py Python package.
  • Install HEIR from source and invoke the heir-opt and heir-translate binaries directly, extracting the generated backend code and integrating it into your project manually.

See Getting Started for more details.

Building from source

This project uses bazel for its build system. Install bazelisk to manage the bazel version automatically. Then, with bazel on your path (pointing to bazelisk), run the following to build the main pass-running tool.

bazel build //tools:heir-opt

Or run an end-to-end test like

bazel test //tests/Examples/openfhe/ckks/halevi_shoup_matvec:all

HEIR depends on LLVM (from source) so a clean build may take 30 minutes depending on your machine. For faster builds, use BuildBuddy. Sign up for an account, create an API key, and add the following to .bazelrc.user in the root of the HEIR workspace:

common --remote_header=x-buildbuddy-api-key=<YOUR_API_KEY>
common --config=remote

This should reduce a clean build time to about 5 minutes.

See the bazel tips page for more example commands and tips on using bazel.

Supported backends and schemes

Backend Library BGV BFV CKKS CGGI
OpenFHE ✅ ✅ ✅ ❌
Lattigo ✅ ✅ ✅ ❌
tfhe-rs ❌ ❌ ❌ ✅
Jaxite ❌ ❌ ❌ ✅

Note some backends do not support all schemes.

Contributing

There are many ways to contribute to HEIR:

Citations

The HEIR project can be cited in academic work through the following entry:

@misc{ali2025heir,
      title={HEIR: A Universal Compiler for Homomorphic Encryption},
      author={Asra Ali and Jaeho Choi and Bryant Gipson and Shruthi Gorantala
              and Jeremy Kun and Wouter Legiest and Lawrence Lim and Alexander
              Viand and Meron Zerihun Demissie and Hongren Zheng},
      year={2025},
      eprint={2508.11095},
      archivePrefix={arXiv},
      primaryClass={cs.CR},
      url={https://arxiv.org/abs/2508.11095},
}

Support disclaimer

This is not an officially supported Google product.

Metadata

Release files for heir-py 2026.10.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for heir-py 2026.10.1
File Size Uploaded
heir_py-2026.10.1.tar.gz 15.9 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for heir-py 2026.10.1
File Interpreter ABI Platform
heir_py-2026.10.1-cp310-abi3-manylinux_2_28_x86_64.whl CPython 3.10 abi3 Linux glibc 2.28+ x86-64 Details
heir_py-2026.10.1-cp310-abi3-manylinux_2_28_aarch64.whl CPython 3.10 abi3 Linux glibc 2.28+ ARM64 Details
heir_py-2026.10.1-cp310-abi3-macosx_11_0_arm64.whl CPython 3.10 abi3 macOS 11.0+ ARM64 Details

Total release size: 120.8 MB

Release files / heir_py-2026.10.1.tar.gz

Download URL heir_py-2026.10.1.tar.gz
Size 15.9 MB
Tags Source
SHA-256 checksum
How to use checksums
4a2a068eb413d0a12c21ed5f8ebb45821581445f71507cfd72c190d6e91de123
BLAKE2b-256 checksum
How to use checksums
b3b096aa88fcc74d8c7376fc2afe17856eaa48de195d7e69974948fd6c195fc0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / heir_py-2026.10.1-cp310-abi3-manylinux_2_28_x86_64.whl

Download URL heir_py-2026.10.1-cp310-abi3-manylinux_2_28_x86_64.whl
Size 34.5 MB
Tags CPython 3.10 Linux glibc 2.28+ x86-64 abi3
SHA-256 checksum
How to use checksums
b8a56222ac248aa7d73796a4c5e1001b0398b955d46b313e6e8954d084ec9d0b
BLAKE2b-256 checksum
How to use checksums
05862fc6d76a4c23f27a0f2476d83a3a587f4b92045a45d534ccc409c8f67c1c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / heir_py-2026.10.1-cp310-abi3-manylinux_2_28_aarch64.whl

Download URL heir_py-2026.10.1-cp310-abi3-manylinux_2_28_aarch64.whl
Size 32.5 MB
Tags CPython 3.10 Linux glibc 2.28+ ARM64 abi3
SHA-256 checksum
How to use checksums
a0e077d4dee7e07e53711c4a0ee4a11b52ee44880dbd53d6e7d6f6ca80726327
BLAKE2b-256 checksum
How to use checksums
977aafc601fde2a5337057bcbd2e4d533712bc68eb7ee953336699f8e315209a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / heir_py-2026.10.1-cp310-abi3-macosx_11_0_arm64.whl

Download URL heir_py-2026.10.1-cp310-abi3-macosx_11_0_arm64.whl
Size 37.9 MB
Tags CPython 3.10 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
8cfd7ec171f07de041ea1804b1cbad6ada1f11177349b4e94b63196629504b82
BLAKE2b-256 checksum
How to use checksums
93c79d26f7b2fc08f5d7a0cd180ce1c8cc27d7ff49f4dc9f7122e87d1c578383
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page