Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

HEIR: Homomorphic Encryption Intermediate Representation

GitHub Workflow Status (with event) GitHub Contributors GitHub Discussions GitHub License OpenSSF Scorecard

An MLIR-based toolchain for homomorphic encryption compilers. Read the docs at the HEIR website.

For more information on MLIR, see the MLIR homepage.

Quickstart (Python)

Pip install the heir_py package

pip install heir_py

Then run an example:

from heir import compile
from heir.mlir import I64, Secret

@compile()  # defaults to scheme="bgv", OpenFHE backend, and debug=False
def func(x: Secret[I64], y: Secret[I64]):
    sum = x + y
    diff = x - y
    mul = x * y
    expression = sum * diff + mul
    deadcode = expression * mul
    return expression

func.setup()
enc_x = func.encrypt_x(7)
enc_y = func.encrypt_y(8)
result_enc = func.eval(enc_x, enc_y)
result = func.decrypt_result(result_enc)

print(
  f"Expected result for `func`: {func.original(7,8)}, FHE result:"
  f" {result}"
)

This will compile the function above using the BGV scheme to machine code via the OpenFHE backend. Then calling the function will encrypt the inputs, run the function, and return the decrypted result. The function call foo(7, 8) runs the entire encrypt-run-decrypt flow for ease of testing.

Building from source

This project uses bazel for its build system. Install bazelisk to manage the bazel version automatically. Then, with bazel on your path (pointing to bazelisk), run the following to build the main pass-running tool.

bazel build //tools:heir-opt

Or run an end-to-end test like

bazel test //tests/Examples/openfhe/ckks/halevi_shoup_matvec:all

HEIR depends on LLVM (from source) so a clean build may take 30 minutes depending on your machine. For faster builds, use BuildBuddy. Sign up for an account, create an API key, and add the following to .bazelrc.user in the root of the HEIR workspace:

common --remote_header=x-buildbuddy-api-key=<YOUR_API_KEY>
common --config=remote

This should reduce a clean build time to about 5 minutes.

See the bazel tips page for more example commands and tips on using bazel.

Supported backends and schemes

Backend Library BGV BFV CKKS CGGI
OpenFHE
Lattigo
tfhe-rs
Jaxite

Note some backends do not support all schemes.

Contributing

There are many ways to contribute to HEIR:

Citations

The HEIR project can be cited in academic work through the following entry:

@misc{ali2025heir,
      title={HEIR: A Universal Compiler for Homomorphic Encryption},
      author={Asra Ali and Jaeho Choi and Bryant Gipson and Shruthi Gorantala
              and Jeremy Kun and Wouter Legiest and Lawrence Lim and Alexander
              Viand and Meron Zerihun Demissie and Hongren Zheng},
      year={2025},
      eprint={2508.11095},
      archivePrefix={arXiv},
      primaryClass={cs.CR},
      url={https://arxiv.org/abs/2508.11095},
}

Support disclaimer

This is not an officially supported Google product.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

heir_py-2026.8.11.dev0.tar.gz (15.8 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

heir_py-2026.8.11.dev0-cp310-abi3-manylinux_2_28_x86_64.whl (34.5 MB view details)

Uploaded CPython 3.10+manylinux: glibc 2.28+ x86-64

heir_py-2026.8.11.dev0-cp310-abi3-manylinux_2_28_aarch64.whl (32.5 MB view details)

Uploaded CPython 3.10+manylinux: glibc 2.28+ ARM64

heir_py-2026.8.11.dev0-cp310-abi3-macosx_11_0_arm64.whl (35.0 MB view details)

Uploaded CPython 3.10+macOS 11.0+ ARM64

File details

Details for the file heir_py-2026.8.11.dev0.tar.gz.

File metadata

  • Download URL: heir_py-2026.8.11.dev0.tar.gz
  • Upload date:
  • Size: 15.8 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for heir_py-2026.8.11.dev0.tar.gz
Algorithm Hash digest
SHA256 e4bf3d3cc50e33a72a159d15b14174ae75d0e4dc5126267fb11cf723562e19bc
MD5 a2bb3e237df986179872fbd835c39cec
BLAKE2b-256 a7a628ace1bcb61ca2903f5810fdae36fdf7dc1bb44b13b28425fa4e82d039f8

See more details on using hashes here.

Provenance

The following attestation bundles were made for heir_py-2026.8.11.dev0.tar.gz:

Publisher: release.yml on google/heir

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file heir_py-2026.8.11.dev0-cp310-abi3-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for heir_py-2026.8.11.dev0-cp310-abi3-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 e878072663f7146d84cdf150ff6d61db0a98c189f95ea5322ca9e68b11f563e2
MD5 62853bc4636b79d7d65eacc791320eb4
BLAKE2b-256 6ca3556b9ff6bf09e9bca90505552ac289e2716918a5a0286a0381dc7d96ba9e

See more details on using hashes here.

Provenance

The following attestation bundles were made for heir_py-2026.8.11.dev0-cp310-abi3-manylinux_2_28_x86_64.whl:

Publisher: release.yml on google/heir

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file heir_py-2026.8.11.dev0-cp310-abi3-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for heir_py-2026.8.11.dev0-cp310-abi3-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 30c8d1067b456f10bd958b4965610e0cb12d125ab1a519caf500329daea8af3c
MD5 c09f38afb3cb5a0b17503f350632c788
BLAKE2b-256 64b7ba58bb73e9bd6e018f7650942153874702f0385a62f88877731b887983d7

See more details on using hashes here.

Provenance

The following attestation bundles were made for heir_py-2026.8.11.dev0-cp310-abi3-manylinux_2_28_aarch64.whl:

Publisher: release.yml on google/heir

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file heir_py-2026.8.11.dev0-cp310-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for heir_py-2026.8.11.dev0-cp310-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 f3007de8af2fd5afd40f0be4d41838d9c9ef87cf60316ff65e557b4282a34bb2
MD5 1691f181767276e84bf80d69e1a96b3c
BLAKE2b-256 46bfe1cad39818d8c76240f32f64dc71185acb458633c2cc97d25f06b100919c

See more details on using hashes here.

Provenance

The following attestation bundles were made for heir_py-2026.8.11.dev0-cp310-abi3-macosx_11_0_arm64.whl:

Publisher: release.yml on google/heir

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page