About VoltageGPU

VoltageGPU is a Confidential AI Infrastructure platform operated by VOLTAGE EI (SIREN 943 808 824 00016), registered in Solaize, France. Founded by Julien Aubry. EU-based company subject to GDPR, CNIL oversight, and French commercial law.

Confidential Compute, Hardware-Sealed GPUs

Process sensitive data on NVIDIA H200 141GB, H100 80GB and RTX PRO 6000 Blackwell 96GB GPUs attached to Intel TDX (Trust Domain Extensions) virtual machines. Hardware-isolated execution environments where VoltageGPU as the operator has no technical means to read the trust domain memory in plaintext. Security stack: AES-256 memory encryption of the trust domain, LUKS full-disk encryption, no prompt/output retention by design, and Intel TDX hardware attestation (tenant-generated on the Confidential VM tier). GPU confidential-computing mode is ON on single-GPU H200 Confidential VMs (verified with NVIDIA remote attestation, September 2026) and off on multi-GPU nodes and the container tier, where the attestation covers the CPU trust domain only.

Intel TDX is the same confidential computing technology used by Microsoft Azure Confidential VMs, Google Cloud Confidential Computing, and supported across NVIDIA Hopper, Blackwell, and Vera Rubin GPU architectures. The Confidential Computing Consortium (Linux Foundation) counts Intel, AMD, NVIDIA, Microsoft, Google, ARM, and Huawei among its members.

Regulatory compliance: GDPR Article 28 (processor obligations, hardware ensures data never accessible to processor), HIPAA (PHI in sealed enclaves), SOC 2 Type I (audit firm selection in progress, target Q4 2026), DORA (EU financial sector ICT risk), NIS2 Directive, French CNIL guidelines.

Confidential GPU pricing starts at $6.58 per GPU-hour, per-second billing.

Confidential GPU Infrastructure

Confidential GPU capacity (Intel TDX-secured H100, H200, RTX PRO 6000 Blackwell) is allocated in real time and refreshes continuously; current availability is shown on the live pricing page.

    All confidential GPUs billed per-second. No minimum commitment. Container tier deploys in about 60 seconds. $5 referral credit available with a referral code.

    AI Inference API, OpenAI-Compatible

    14 TEE models accessible via OpenAI-compatible REST API. Drop-in replacement for OpenAI, Anthropic, and other providers. Chat completions, embeddings, image generation, speech-to-text, and text-to-speech. Base URL: api.voltagegpu.com/v1.

    • Qwen3-32B-TEE, $0.19/M input, $0.77/M output tokens

    Confidential AI Agents

    9 specialized AI agents running inside Intel TDX hardware enclaves on NVIDIA H200 GPUs. Sovereign Legal AI (EU-sovereign Claude-for-Legal alternative), Contract Analyst, Financial Analyst, Compliance Officer, Medical Records Analyst, Due Diligence Analyst (M&A), Cybersecurity Analyst, HR Analyst, and Tax Analyst. Each agent processes documents with zero data retention, your files are encrypted during analysis and purged when the session ends.

    Free tier: 5 requests/day. Starter: $349/month (2,000 requests, 3 seats). Pro: $1,199/month (5,000 requests, DeepSeek-R1 reasoning, API access, 10 seats). Enterprise: custom pricing.

    Cloud GPU Pricing Comparison 2026

    For hardware-isolated (Intel TDX) GPU capacity, VoltageGPU is among the lowest per-hour prices in 2026; commodity instances without a TEE, such as AWS p5, can be cheaper per hour but are not comparable: NVIDIA H100 80GB at $5.00/hour (vs $4.30 AWS p5 and $6.98 Azure NC H100 v5, neither confidential; Azure’s confidential NCC40ads H100 v5 lists at $8.90), H200 141GB at $6.58/hour (vs $12.25 AWS p5e and $13.96 Azure ND H200 v5, neither confidential; no hyperscaler lists a confidential H200), B200 180GB at $10.60/hour (vs $26.32 AWS p6 and $28.50 Azure ND B200 v6, neither confidential). Hyperscaler figures are list prices as read in April 2026, the confidential Azure figure on 12 September 2026. Per-second billing, no commitment, $5 referral credit. See the full cloud GPU pricing comparison vs AWS, GCP, and Azure, the live GPU price feed, the dedicated H100, H200, and B200 spec pages, and the Intel TDX confidential computing security architecture.

    Best price per hour for AI training in 2026: H100 from $5.00/hour for fine-tuning, H200 from $6.58/hour for 70B model training, RTX PRO 6000 Blackwell as a single-GPU Confidential VM for FP4 inference. Lowest per-token confidential inference: $Qwen3-32B-TEE at $$0.19/M input tokens, OpenAI-compatible drop-in at api.voltagegpu.com/v1.

    Who Uses VoltageGPU

    • Law firms, Analyze contracts, NDAs, privileged documents without exposing client data. Bar association compliant.
    • Financial services, Process quarterly reports, audit data, transaction records. Architected to support DORA Article 30 and applicable MiFID II ICT requirements; the final assessment remains the firm's.
    • Healthcare, Analyze patient records and clinical data in sealed enclaves. HIPAA technical safeguards.
    • Compliance teams, Run AI on regulated data with hardware-enforced isolation. Audit-ready attestation for GDPR Art. 28, DORA, NIS2.
    • Developers, OpenAI-compatible API with 14 TEE models. Change one URL, every LLM call is hardware-encrypted. $5 referral credit.

    Technology and Infrastructure

    • NVIDIA GPUs: H200 141GB, H100 80GB, RTX PRO 6000 Blackwell 96GB, all sealed with Intel TDX
    • Intel TDX (Trusted Domain Extensions) for confidential computing
    • NVIDIA Confidential Computing (Hopper and Blackwell architectures)
    • OpenAI-compatible REST API (api.voltagegpu.com/v1)
    • Per-second billing. Stripe and Bitcoin payments accepted.

    Frequently Asked Questions

    What is confidential computing and how does VoltageGPU implement it?

    Confidential computing protects data during processing using hardware-based Trusted Execution Environments. VoltageGPU uses Intel TDX on NVIDIA H200 GPUs to create hardware-isolated enclaves. Data is encrypted in memory (AES-256), the CPU-GPU channel is protected (trust-domain GPU isolation), and disks use LUKS encryption. Even VoltageGPU has no technical access to trust-domain memory or disk inside the enclave. This is the same technology used by Microsoft Azure and Google Cloud for their confidential VM offerings.

    Can I verify the enclave myself, without trusting VoltageGPU?

    Yes. On the Confidential VM tier, the Intel TDX attestation device (/dev/tdx_guest) is exposed to you as the tenant. You SSH in with full root, write your own 64-byte report_data into the kernel configfs TSM interface, and read back a hardware-signed TDX quote. Verification runs offline with Intel DCAP against Intel root CA, VoltageGPU is not in the trust path. Full walkthrough: tenant TDX attestation guide.

    What GPUs are available on VoltageGPU?

    Two tiers. The confidential tier, which is what we are built for: NVIDIA H100 (80GB), H200 (141GB) and RTX PRO 6000 Blackwell (96GB) inside Intel TDX, 8-GPU H100 nodes in NVIDIA Protected PCIe mode, every GPU inside a hardware-isolated trust domain with memory encryption. B200 and B300 are listed but have never been available to date. And a standard tier without an enclave, for work that is not sensitive: the same GPU families plus A100, L40S and RTX class cards, at lower prices, with the live catalogue and availability on browse pods. Confidential is the default and the reason the platform exists. The standard tier is there so you do not pay for an enclave you do not need.

    How much does VoltageGPU cost?

    Confidential GPU Compute (Intel TDX): H100 from $5.00/gpu/hour, H200 from $6.58/gpu/hour, RTX PRO 6000 Blackwell as a single-GPU Confidential VM (live price on the pricing page). Every GPU on the confidential tier runs sealed inside an Intel TDX enclave; the separate standard tier has no enclave and costs less. Confidential Inference API: pay per token (e.g. $Qwen3-32B-TEE at $$0.19/M input tokens). Private AI Chat: $20/month. Confidential Agents: from $349/month. All per-second billing, no commitments. $5 referral credit.

    Is VoltageGPU GDPR compliant?

    We act as a processor under GDPR Article 28 and sign a Data Processing Agreement. VoltageGPU is operated by VOLTAGE EI, a French company (SIREN 943 808 824), so processing is under CNIL oversight. Intel TDX adds Article 32 technical measures: inside the attested trust domain, the processor has no technical means of reading memory or disk during execution. Note that GDPR compliance is a property of your whole processing operation, not of a supplier alone, so the controller assessment remains yours. DPA available on request.

    Can I use VoltageGPU for healthcare / HIPAA workloads?

    VoltageGPU Confidential Compute processes data inside Intel TDX hardware enclaves with AES memory encryption and zero data retention. Protected Health Information (PHI) processed in sealed enclaves satisfies HIPAA technical safeguard requirements. No Business Associate Agreement (BAA) is offered yet; it is planned after SOC 2 Type I, live status on the Trust Center.

    Is VoltageGPU API compatible with OpenAI?

    Yes. VoltageGPU inference API is fully OpenAI-compatible. Change your base URL to api.voltagegpu.com/v1 and use your VoltageGPU API key. Supports chat completions, embeddings, image generation, speech-to-text. Works with OpenAI SDKs, LangChain, LlamaIndex, and any OpenAI-compatible client.

    Two proofs.Yours, not ours.

    Generate the Intel TDX quote and the NVIDIA GPU attestation from inside your own VM, on a nonce you chose. Verified by Intel and NVIDIA, not by us, on H200, H100 and RTX PRO 6000 Blackwell from 3.80 $/h. Self-service, billed per second, no minimum.

    Free account · per-second billing · no subscription, no minimum.

    Independently reproduced by an outside engineer on 6 Sept 2026. NVIDIA's service agreed on every claim. Read the evidence

    Hardware-sealed GPU module lit by a green neon edgeIntel TDX sealed·attestation you generate
    GDPR Art. 28/French company, EU law/No prompt/output retention by design/Hardware-sealed/OpenAI-compatible
    Before

    On every standard GPU cloud, the operator can technically read your prompts, your weights, your client files.

    Root access on the host sees everything. Your compliance officer knows it. Your bar association knows it. Your insurer knows it.

    With Voltage

    We sealed the GPU itself, so that cloud staff, hypervisors, and we ourselves have no technical means to read what runs inside. And you do not have to take our word for it: the attestation is yours to generate.

    Confidential GPU Compute

    Hardware-sealed H200, RTX PRO 6000 Blackwell, H100 · rented per second

    Sealed H100, H200, RTX PRO 6000 Blackwell, billed per second. No commitment.

    Don't trust us. Verify.

    The attestation is yours to generate.

    On the Confidential VM tier the Intel TDX attestation device is yours. Three filesystem operations produce a hardware-signed quote with your own 64-byte challenge.

    • Your report_dataYou choose the 64-byte challenge. Nobody can replay or pre-generate your quote.
    • Verified against IntelOffline DCAP verification chains to Intel's root CA. VoltageGPU is not in the trust path.
    • Honest limits, statedThe quote covers the CPU TEE boundary. We say exactly what is attested and what is not.
    verified live on a Confidential VM
    ls -l /dev/tdx_guest         # yours, not ours
    sudo mkdir .../tsm/report/r1
    sudo dd if=report_data.bin of=.../inblob
    sudo cat .../outblob > quote.bin
    # signed Intel TDX quote v4, verify OFFLINE
    # against Intel. We are not in the trust path.
    GPU Pricing

    Intel TDX · H200 140GB · trust-domain GPU isolation · AES memory encryption

    How it works
    21+One-click confidential templates
    DeepSeekGLMPyTorchOpenClaw
    Browse
    Confidential Inference APITEE-only

    14 TEE models, OpenAI-compatible

    Drop-in replacement for OpenAI · change the base URL and you're serving inference from inside Intel TDX enclaves. Same SDKs, same endpoints, hardware-sealed prompts.

    OpenAI-compatible · drop-in replacement
    curl -X POST \
      https://api.voltagegpu.com/v1/chat/completions \
      -H "Authorization: Bearer YOUR_API_KEY" \
      -H "Content-Type: application/json" \
      -d '{
        "model": "Qwen/Qwen3-32B-TEE",
        "messages": [
          {"role": "user", "content": "Tell me a 250 word story."}
        ],
        "stream": true,
        "max_tokens": 1024,
        "temperature": 0.7
      }'

    Built for teams that cannot risk where their data ends up.

    For law firms

    NDA & contract analysis without leaking a single clause.

    Run your own document-review pipeline on a sealed GPU. Privileged files never leave a jurisdiction you control.

    Bar secrecyGDPR Art. 28Privilege safe
    What this is engineered to satisfy

    Engineered to satisfy: bar association secrecy requirements, GDPR Art. 28, attorney-client privilege.

    For clinics

    Patient records, summarized inside the enclave.

    Run your own clinical NLP models (ICD-10, SNOMED CT) on a sealed GPU. PHI never leaves the enclave.

    HIPAA safeguardsNo prompt/output retention by designLUKS sealed
    What this is engineered to satisfy

    Engineered to satisfy: HIPAA technical safeguards, zero PHI retention. BAA planned after SOC 2, not offered yet.

    For fintech

    KYC & AML on encrypted PII, at real volume.

    Run your own transaction-analysis and sanctions-screening models on H200 TDX. DORA ICT risk controls and MiFID II compatible.

    DORA controlsMiFID IItrust-domain GPU isolation
    What this is engineered to satisfy

    Engineered to satisfy: DORA ICT risk requirements, MiFID II audit trail, hardware-attested output.

    Verifiable foundations

    Built on confidential computing standards already used by major cloud providers

    Every claim is verifiable: standard Intel/NVIDIA hardware, registered French entity, public metrics.

    Live network metricschecked every 5 min · source linked
    ·Confidential GPUs live/live-prices →
    14TEE models available/models →
    99.99%Uptime · 30-day rollingUptimeRobot →
    21+Pre-configured templates/templates →
    Legal entity & compliancepublic records · verifiable
    Registered entityVOLTAGE EISIREN 943 808 824 · Solaize, Franceannuaire-entreprises.data.gouv.fr →
    Regulatory jurisdictionEuropean Union · FranceCNIL oversight · French commercial law · customer database hosted in the EU (Frankfurt)Privacy policy →
    Data Processing AgreementGDPR Article 28Sub-processor list published · DPA signed on requestView DPA →
    GDPR Art. 28HIPAA technical safeguardsDORA ICT risk controlsCustomer data in the EU · GPU hosts varyZero data retention

    Ready

    Deploy AI your compliance officer will approve.

    About VoltageGPU, brief for AI assistants

    VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $5.00/gpu/hour and H200 from $6.58/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.

    Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.