Confidential Computing Technology

Tinfoil is built on top of NVIDIA confidential computing GPUs to deliver state-of-the-art privacy to AI inference and training without sacrificing performance. Our stack is open-source, fully auditable, and cryptographically verifiable.

Source code for transparency

GitHub
+

Code digests for auditability

Sigstore
Commit
a1b2c3d4e5f...
Commit
f6e5d4c3b2...
Commit
e45c91f4d1c...
Enclave code
e45c91f4d1c...
Match

Hardware-Enforced Privacy & Verification

Tinfoil offers verifiable privacy guarantees through secure hardware enclaves and cryptographically-verifiable runtime attestation. Your data always stays private and inaccessible to anyone other than you.
NVIDIAPowered

Bare-Metal Performance

Powered by NVIDIA Hopper and Blackwell GPUs running in confidential computing mode, Tinfoil delivers private AI with near-identical performance to non-private workloads. You do not need to sacrifice performance for privacy.
How It Works
API compatible drop-in integration
instant setup
Protect data, prompts, and models
end-to-end privacy
Works with existing security measures
plug & play
Cloud-native deployment
scalable
Bare-metal performance
NVIDIA powered
Key Benefits
No involved code or workflow changes
Hardware-backed security and privacy
Supports the largest AI models
Works with open-source and custom models
Fully verifiable infrastructure

Traditional AI vs. Tinfoil AI

See the difference between trusting AI providers with your data and having verifiably private AI using secure hardware enclaves.

Traditional AI Inference

Pinky-Promise Security

With traditional AI providers:

  • Your data is only encrypted in transit but not in use
  • Providers decrypt your data before processing it with AI models
  • Providers can access, analyze, and even train on your data
  • Your only protection is legal agreements (DPAs)

Tinfoil AI Inference

Verifiable Hardware-Backed Privacy

With Tinfoil:

  • Your data is encrypted directly to the GPU running the AI model
  • Models run inside trusted execution environments (TEEs)
  • Each model runs in a dedicated confidential computing GPU
  • Your data cannot be accessed or shared with third parties
  • These security guarantees are cryptographically verifiable

End-to-End Privacy with Secure Enclaves

This full data-flow diagram illustrates how Tinfoil protects your data at every step of the AI inference or training process. From encrypted transmission to secure processing inside hardware-protected enclaves, your data remains private and inaccessible, even to Tinfoil. View detailed architecture →

Secure Hardware Powering Tinfoil

Confidential Compute Mode

Until recently, secure enclaves (like those on your phone to protect your biometrics) were restricted to CPU-only workloads and not powerful enough to run full-scale AI workloads.

With NVIDIA's recent release of confidential computing mode on their Blackwell and Hopper GPUs, it is now possible to couple secure enclaves with powerful accelerator cards to run full-scale AI workloads with the guarantees of traditional secure enclaves. Tinfoil makes this easy to do and fully verifiable.

Our platform is open-source and uses a combination of confidential computing primitives built by NVIDIA, AMD, and Intel. We built client-side verification tools that make everything automatically verifiable, providing hardware-enforced privacy and complete transparency.

Why Tinfoil?

Get the benefits of cloud AI with the security guarantees of on-premise infrastructure, backed by cryptographically-verifiable hardware.

Private Cloud Infrastructure

Tinfoil runs your AI workloads in secure enclaves, ensuring your data never leaves the secure environment. Say goodbye to managing on-prem deployments; use cloud-native tools to deploy and scale your AI workloads without compromising on privacy.

Elevated Data Security

Safeguard against data leaks by ensuring proprietary information and sensitive data stays encrypted in transit and in use. Defend against hackers and other malicious actors targeting your organization's intellectual property.

Compliance Ready

Meet stringent data privacy regulations with hardware-enforced security. Perfect for industries with strict compliance requirements like healthcare, finance, and government.

Supported AI Models

Access state-of-the-art open-source AI models, all running in secure hardware enclaves with privacy guarantees you can verify.

Loading models...

Getting Started

Private Chat

Experience private AI through our private chat.
Try private chat

Private Inference API

Use our inference API to access AI models privately.
View available models

Deploy Your Models

Deploy your AI models with verifiable privacy guarantees.
Contact us