Skip to main content
L

Lunal

Lunal offers a confidential computing platform that runs AI inference, training, and agent workloads inside hardware‑encrypted Trusted Execution Environments (TEEs) such as AMD SEV‑SNP, Intel TDX, and NVIDIA Confidential Computing. The stack provides cryptographic attestation for both code and data, a managed Confidential Cloud, and modular components for on‑prem deployment, enabling enterprises to protect proprietary models and data without code changes.

San Francisco, United StatesFounded 202225200+ followers
Updated 2 months ago

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Product

Problem

Enterprises running AI workloads face the risk that data, model weights, and proprietary code can be exposed to cloud operators or compromised during processing, especially when using standard hardware without hardware-enforced isolation. Verifying that code runs unchanged inside a trusted environment is also difficult, limiting confidence in confidentiality and integrity.

Solution

Lunal provides a confidential computing stack that runs AI inference, training, and agent workloads inside hardware-encrypted Trusted Execution Environments (TEEs) such as AMD SEV‑SNP, Intel TDX, and NVIDIA Confidential Computing. The platform offers both a managed Confidential Cloud and modular components for on‑prem deployment, enabling organizations to add privacy without code changes or deep TEE expertise. Each execution is accompanied by cryptographic attestation proofs that can be independently verified, ensuring data and code remain private and tamper‑evident. Lunal also supplies an attestable build service that compiles code inside a TEE and emits signed provenance linking the git commit to the final artifact, establishing a verifiable chain of custody. Additional services like attestation verification, certificate distribution, and networking components support end‑to‑end confidentiality across the entire AI pipeline.

Target Audience

Primary customers are enterprises and AI service providers that need to protect proprietary models, data, and code during cloud or on‑prem AI processing, including organizations in regulated industries and developers of confidential AI applications.

Features

  • Confidential Inference API with per‑token pricing, compatible with OpenAI‑style calls and delivering attestation‑verified responses
  • Confidential VMs offering GPU (RTX PRO 6000, H100, B200) and CPU instances backed by TEEs, with encrypted inter‑GPU communication options
  • Attestable Build service (Kettle) that runs builds inside a TEE and produces signed provenance achieving SLSA Build L3
  • Unified Attestation Service supporting AMD SEV‑SNP, Intel TDX, and NVIDIA formats, providing public verification APIs and CLI tools
  • Certificate Distribution Service that gates secret and certificate delivery on attestation, with optional CA and TEE registry functions
  • Modular component catalog allowing selective integration of hardened VM images, SDKs, networking, and control plane services on customer infrastructure
  • No code modifications required; workloads run unchanged within the confidential stack
This profile is AI-generated and may contain inaccuracies.