Alpha Compute — Confidential Compute
Not even we can read this.
Alpha Compute runs frontier AI inside hardware enclaves attested down to the silicon. Your prompts, your weights, your outputs — encrypted in memory, invisible to the host, the hypervisor, and to us. Privacy by proof, not by policy.
Sealed session · 0 bytes logged · nothing leaves the boundary
0
Plaintext bytes visible to anyone but you
Always on
Silicon-enforced memory encryption
100%
Of sessions proved before the first byte
496+
NVIDIA B200 GPUs · live now
01 — Overview
Your most valuable data is the data you are not allowed to use.
Material non-public information. Patient records. Classified material. Privileged filings. The workloads with the highest value are exactly the ones every compliance team has blocked from touching a shared model.
Alpha Enclave removes the reason for the block. The hardware — not a contract, not a policy — makes the data unreadable to everyone except you, for the length of the session and not one moment longer.
Host OS
Sees ciphertext
Hypervisor
Sees ciphertext
Cloud operator
Sees ciphertext
Alpha Compute
Sees ciphertext
02 — How it works
Attest. Seal. Forget.
Three steps, enforced by hardware rather than policy, on every single request.
01
Attest
Before your session begins, the hardware signs a measurement of exactly what's running — firmware, kernel, model. You verify that signature against the silicon vendor's roots before sending a single byte.
02
Seal
Your prompt, the model weights, and every intermediate value stay encrypted in memory for the life of the session. The keys live inside the chip and never leave it — not to the host OS, not to us.
03
Forget
When the session ends, the enclave is torn down and the keys are destroyed with it. There is no plaintext left anywhere to hand over, subpoena, or leak.
03 — Attestation
The machine proves itself before you say a word.
The enclave signs a report of exactly what runs inside it. You check it against Intel and NVIDIA roots of trust. Fail one check and your key never leaves your device.
Report signature valid
Signed by the chip's own key, chained to the vendor root of trust
Launch measurement present
Identifies exactly what workload is running inside
GPU confidential mode active
NVIDIA CC-On confirmed for the attached accelerator
TLS bound to this session
Certificate pinned to the enclave's own keyset, not a shared cert
One changed bit anywhere in the measured image and the proof fails. The session never starts.
04 — Who it serves
Built for work that cannot leak.
Financial services
Diligence, research, and client analysis on material non-public information — none of it leaving your control.
Healthcare & life sciences
Patient and trial data at full fidelity, with a signed record behind every request.
Government & defense
Sensitive workloads run with data and keys sealed in hardware we operate, never exposed to an operator.
Legal & professional
Privileged material reviewed at speed, with privilege intact.
05 — The platform
Silicon to session. Nothing to trust.
No custom cryptography, no proprietary black box. Every layer below is a published standard from Intel, AMD, or NVIDIA — you can verify each one against the vendor's own attestation roots.
CPU enclave — Intel TDX
Per-VM keys in silicon
GPU enclave — NVIDIA Confidential Computing
Blackwell B200 × 496+
Attestation — verified against vendor roots of trust
Before keys are released
Session keys — ephemeral, held only inside the enclave
Destroyed at teardown
Reports are signed by the CPU and GPU themselves and checked against vendor roots of trust. Traffic between CPU and GPU enclaves is encrypted in transit. The boundary holds across the whole path.
06 — Control
Total control. Your data, your models, your borders.
Your data
Encrypted on your device to a key only the enclave holds. Never readable by us. Never retained. Never used to train anything.
Your models
Open-weight models run inside the enclave, and your fine-tuned weights are protected exactly as your data is. Nothing about the model leaves the boundary.
Your jurisdiction
Protection comes from the silicon, not the postcode. Enclave-01 runs in our facilities, and the same guarantees hold for data-residency requirements inside your jurisdiction.
07 — Get in touch
The rest happens under NDA.
Bring the workload you cannot send anywhere else. We will bring the attestation report.