your infrastructureyour applicationclient + verification sdkpayload stays here
confidential execution boundary
verify before sendingyour request stays with you.
uk-hosted executionconfidential cpu + gpu
hardware
attested
workload
measured
tls key
bound
the evidence comes first.
your SDK checks fresh CPU and GPU evidence, the approved workload, and the endpoint’s identity. your sensitive request stays with you until verification passes.
tls terminates inside the boundary.
your request travels over a verified TLS connection. the network routes ciphertext; TLS terminates at the attested gateway, inside the confidential environment.
compute in protected memory.
the open-weight model works with plaintext in protected CPU and GPU memory. the hardware boundary is designed to prevent host administrators from reading that memory.
the request ends. its payload doesn’t stay.
the response returns to your application. prompt and response payloads are not retained after processing. only allowlisted operational metadata has a separate retention schedule.
less blind trust. more evidence.
trust.
hosted zero data retention
a retention policy is not execution evidence.
a ZDR policy promises that prompts and responses won't be retained. on its own, it doesn't let you verify which software handles them, whether logging is disabled, or who can access them during processing.
own.
on-premises inference
you manage the hardware and operations.
bring inference in-house and you also take on GPU procurement, installation, power, and capacity planning. security updates, maintenance, and idle capacity remain yours to manage.
verify.
confidential inference
verify, don’t trust.
use reserved capacity with a workload and endpoint you can verify. our lightweight, source-available SDK runs in your infrastructure, checks attestation, and forwards your OpenAI-compatible requests only when verification passes.
in memory. not in history.
prompts and responses are processed in protected memory, then cleared when the request is complete.
your model is cleared. we don’t have to be.
we’re seeking design partners for confidential inference.