Solutions

Confidential compute for sensitive AI workloads

Hardware-attested inference and fine-tuning on NVIDIA GPUs. Cryptographic proof your data and model stay protected in memory, in transit, and at rest

Why confidential computing?

Modern infrastructure encrypts data at rest and in transit. But the moment a GPU runs a model, data is decrypted in memory to be used. For most workloads, that's fine.

For regulated data, proprietary models, or products where privacy is part of the value proposition, "trust the provider" is no longer a defensible control. Auditors, regulators, and customers want cryptographic evidence, not contractual promises.

Data state Status on standard infrastructure
At rest (disk, storage) ✓ Encrypted
In transit (network, API) ✓ Encrypted
In use (memory, during computation) — The gap
Verified end-to-end

One attestation confirms your entire stack — CPU and GPU — is untampered

Trusted Boundary (TEE)
CPU Chain

AMD Secure Processor

Hardware Root of Trust

Your Workload & Data

prompts, models, sensitive inputs

Protects

Protected Environment

AES Encrypted RAM

Verified boot (OS, kernel, bootloader)

isolated from host, hypervisor, operator

Signs

Keys Fused Into Silicon

AMD-SP (AMD SEV-SNP)

physically unreadable by any software

GPU Chain

NVIDIA GPU Secure Element

Hardware Root of Trust

Your Model Weights

running computation, KV-cache

Protects

Protected Environment

Encrypted GPU memory (VRAM)

Signed GPU firmware

weights decrypted only inside the GPU

Signs

On-Die Root of Trust

GPU Secure Element

unique device identity, fused at manufacture

Untrusted
KVM QEMU hypervisor Host OS Other VMs Cloud provider infrastructure Management software

Confidential computing closes the last row — and does it on a verified boot chain, so you can trust the protection is real.

CPU chain — AMD SEV-SNP

Memory encrypted and integrity-protected by the AMD Secure Processor. Keys fused into silicon, unreadable by any software. Signed virtual TPM, bootloader, and kernel produce verifiable boot measurements.

GPU chain — NVIDIA confidential computing

Each GPU carries a unique cryptographic identity fused at manufacture. GPU memory is encrypted. Model weights and activations are decrypted only inside the GPU die. Firmware is signed and attested.

One converged attestation

Before any workload runs, you receive a single signed report covering both chains. Verify against AMD and NVIDIA root certificates using standard tooling. We don't see the result — trust is cryptographic, not contractual.

What this unlocks

Move regulated workloads off on-prem hardware

Workloads that previously had to run on-prem for compliance reasons: sensitive inference, fine-tuning on regulated data, model serving with PII can now run on Verda with cryptographic controls.

From "we trust our vendor" to "we don't have to"

Traditional controls tell your auditor Verda follows the right processes. Confidential computing gives them something different: cryptographic proof verifiable on every workload.

Ship privacy-first AI products

Build consumer and enterprise AI products where "your data stays private, cryptographically" is part of the product.

Built for use cases where security isn't optional

Finance

Fraud, risk, and KYC models on regulated PII

Deploy the model on attested Verda CC instances. Your security team verifies the attestation on every job. PII never exists in cleartext outside the GPU die.

DORA | GDPR
Consumer facing AI

From "we trust our vendor" to "we don't have to"

Run inference on attested Verda GPUs. Expose the attestation as part of your product — a signed proof that no one at your company, or at Verda, can read what users send.

Attestation as a product feature
Health research

Medical imaging and clinical AI on data that can't leave a protected boundary

Process the data on attested Verda instances inside the EU. Patient data is decrypted only inside the GPU, under a chain of trust your compliance team can independently verify.

GDPR | EU Health data space

FAQs

Can Verda staff read our data or model weights?

No. The encryption keys for memory and GPU state sit inside the AMD Secure Processor and the NVIDIA GPU secure element. No software — ours, yours, or an attacker's — can extract them.

What if a server is physically extracted from the rack?

Per-instance encryption keys live in silicon. Cold-boot attacks, RAM extraction, and bus probing recover ciphertext, not plaintext.

Can we verify the attestation with our own tools?

Yes. Attestation reports are signed by AMD and NVIDIA roots of trust and verifiable with standard libraries. Full methodology and expected measurements are in our docs.

What GPUs are supported today, and what's coming?

Confidential computing is available today on NVIDIA RTX Pro 6000. Multi-GPU support on Blackwell (B200, B300) is coming soon.

What about multi-node training under CC?

Multi-node training under CC is on our roadmap. It's a hard problem that the industry is still solving, and we're investing to be among the first to deliver it in production.

What compliance frameworks does this help with?

Confidential computing strengthens your posture against technical and operational controls required by GDPR (Article 32), DORA (ICT third-party risk), the EU AI Act (high-risk system controls), and sector-specific regimes in finance, health research, and public administration.

Built in Europe, trusted globally

One platform, the full AI lifecycle

From rapid prototyping to foundation training and scalable inference — on a single full-stack AI cloud