Confidential offers a modular confidential computing stack that runs AI inference, training, and build workloads inside hardware‑encrypted Trusted Execution Environments (TEEs). The platform provides both a managed Confidential Cloud and on‑premise components, delivering cryptographic attestation proofs that verify data and code remain private and untampered without requiring TEE expertise. It integrates APIs, VM images, and SDKs to protect proprietary models and sensitive data for enterprises and AI service providers.
Funding
Funding not disclosed
Founders
Product
Problem
Enterprises running AI workloads face the risk that sensitive data and proprietary model code can be exposed or tampered with during processing, especially when using shared cloud infrastructure or third‑party build pipelines. Existing solutions often require deep expertise in Trusted Execution Environments (TEEs) and lack end‑to‑end cryptographic proof of integrity and privacy.
Solution
Confidential provides a modular confidential computing stack that enables AI inference, training, and build processes to run inside hardware‑encrypted TEEs. The platform offers both a managed Confidential Cloud and on‑premise components, allowing organizations to add privacy and integrity guarantees without modifying their code or acquiring TEE expertise. Each workload is accompanied by attestation proofs that can be independently verified, ensuring that the code and data remain confidential and untampered. The stack includes an attestation service, certificate distribution, attestable build pipelines, and SDKs, creating a verifiable chain of custody from source code to execution. By integrating these components, customers achieve hardware‑enforced data protection and cryptographic verification while maintaining compatibility with existing AI frameworks and APIs.
Target Audience
Primary customers are enterprises and AI service providers that need to protect proprietary models and sensitive data during inference, training, or software build pipelines, as well as organizations deploying confidential compute on their own data centers.
Features
- Confidential Inference API with per‑token pricing, compatible with OpenAI‑style calls and delivering attested responses from models running inside TEEs
- Confidential VMs (GPU and CPU) provisioned on the Confidential Cloud, supporting AMD SEV‑SNP, Intel TDX, and NVIDIA Confidential Computing for training, fine‑tuning, and inference
- Attestable Build service (Kettle) that runs builds inside a TEE and emits signed provenance linking git commits to final artifacts, achieving SLSA Build L3 without deterministic compilers
- Centralized Attestation Service that normalizes and verifies attestation reports across multiple hardware vendors, providing a public API and CLI for independent verification
- Certificate Distribution Service that gates secret and certificate delivery on successful attestation, optionally acting as a CA and maintaining a registry of authorized TEEs
- Modular component catalog (SDKs, hardened VM images, networking services, oblivious HTTP gateway) enabling selective adoption on customer‑owned infrastructure
- End‑to‑end cryptographic proof of hardware‑enforced integrity and privacy, allowing customers to verify claims without trusting the provider