CPU chain — AMD SEV-SNP
Memory encrypted and integrity-protected by the AMD Secure Processor. Keys fused into silicon, unreadable by any software. Signed virtual TPM, bootloader, and kernel produce verifiable boot measurements.
AI Cloud
From rapid prototyping to foundation training to scalable inference
Compute
GB300 NVL72
New1x tray to 2+ racks · NVLink v5
Hardware-attested inference and fine-tuning on NVIDIA GPUs. Cryptographic proof your data and model stay protected in memory, in transit, and at rest
Modern infrastructure encrypts data at rest and in transit. But the moment a GPU runs a model, data is decrypted in memory to be used. For most workloads, that's fine.
For regulated data, proprietary models, or products where privacy is part of the value proposition, "trust the provider" is no longer a defensible control. Auditors, regulators, and customers want cryptographic evidence, not contractual promises.
| Data state | Status on standard infrastructure |
|---|---|
| At rest (disk, storage) | ✓ Encrypted |
| In transit (network, API) | ✓ Encrypted |
| In use (memory, during computation) | — The gap |
One attestation confirms your entire stack — CPU and GPU — is untampered
AMD Secure Processor
Your Workload & Data
prompts, models, sensitive inputs
Protected Environment
AES Encrypted RAM
Verified boot (OS, kernel, bootloader)
isolated from host, hypervisor, operator
Keys Fused Into Silicon
AMD-SP (AMD SEV-SNP)
physically unreadable by any software
NVIDIA GPU Secure Element
Your Model Weights
running computation, KV-cache
Protected Environment
Encrypted GPU memory (VRAM)
Signed GPU firmware
weights decrypted only inside the GPU
On-Die Root of Trust
GPU Secure Element
unique device identity, fused at manufacture
Memory encrypted and integrity-protected by the AMD Secure Processor. Keys fused into silicon, unreadable by any software. Signed virtual TPM, bootloader, and kernel produce verifiable boot measurements.
Each GPU carries a unique cryptographic identity fused at manufacture. GPU memory is encrypted. Model weights and activations are decrypted only inside the GPU die. Firmware is signed and attested.
Before any workload runs, you receive a single signed report covering both chains. Verify against AMD and NVIDIA root certificates using standard tooling. We don't see the result — trust is cryptographic, not contractual.
Workloads that previously had to run on-prem for compliance reasons: sensitive inference, fine-tuning on regulated data, model serving with PII can now run on Verda with cryptographic controls.
Traditional controls tell your auditor Verda follows the right processes. Confidential computing gives them something different: cryptographic proof verifiable on every workload.
Build consumer and enterprise AI products where "your data stays private, cryptographically" is part of the product.
Deploy the model on attested Verda CC instances. Your security team verifies the attestation on every job. PII never exists in cleartext outside the GPU die.
DORA | GDPRRun inference on attested Verda GPUs. Expose the attestation as part of your product — a signed proof that no one at your company, or at Verda, can read what users send.
Attestation as a product featureProcess the data on attested Verda instances inside the EU. Patient data is decrypted only inside the GPU, under a chain of trust your compliance team can independently verify.
GDPR | EU Health data spaceNo. The encryption keys for memory and GPU state sit inside the AMD Secure Processor and the NVIDIA GPU secure element. No software — ours, yours, or an attacker's — can extract them.
Per-instance encryption keys live in silicon. Cold-boot attacks, RAM extraction, and bus probing recover ciphertext, not plaintext.
Yes. Attestation reports are signed by AMD and NVIDIA roots of trust and verifiable with standard libraries. Full methodology and expected measurements are in our docs.
Confidential computing is available today on NVIDIA RTX Pro 6000. Multi-GPU support on Blackwell (B200, B300) is coming soon.
Multi-node training under CC is on our roadmap. It's a hard problem that the industry is still solving, and we're investing to be among the first to deliver it in production.
Confidential computing strengthens your posture against technical and operational controls required by GDPR (Article 32), DORA (ICT third-party risk), the EU AI Act (high-risk system controls), and sector-specific regimes in finance, health research, and public administration.
Built in Europe, trusted globally
From rapid prototyping to foundation training and scalable inference — on a single full-stack AI cloud