For developers and small infra teams running AI on data they can't expose: rent an H100, H200 or RTX PRO 6000 inside an Intel TDX trust domain, then check the Intel and NVIDIA attestation yourself, on your own nonce.
Both are produced inside your VM, on a challenge you choose, and signed by Intel and NVIDIA. You check them on your own machine. We are not in the trust path.
Run from inside the VM, on a random nonce, and passed. "Both proofs" means the Intel TDX quote was checked in the same published run; the quote is available to the tenant on every Confidential VM. Nothing is listed on assumption.
Not attested, and never claimed: the NVSwitch fabric on 8-GPU nodes, 8× H200 nodes, B200 and B300 (never available), and the container tier, which has no tenant attestation. Machine-readable list
02What you can run
Three products, clearly labelled.
Confidential is what we are built for. The standard tier exists so you don't pay for an enclave you don't need, and it is never sold as confidential.
Confidential VMsIntel TDX + NVIDIA attestationStart here
A whole VM inside a trust domain, attested by you.
Root over SSH, your own stack, billed per second. Generate the TDX quote and the GPU attestation yourself, whenever you want.
On a VoltageGPU Confidential VM the tenant produces both proofs, inside the VM, on a challenge they choose. voltage-verify writes a manifest with a fresh random challenge; the Intel TDX quote carries the SHA-512 of that manifest and is verified up to the pinned Intel SGX Root CA; NVIDIA's attestation service signs its SHA-256 into the GPU tokens. With the wrong challenge the verifier answers NOT VERIFIED. Who you trust: Intel, NVIDIA and yourself. VoltageGPU is not in the trust path.
Hardware actually verified: NVIDIA GPU attestation verified from inside the VM on: single-GPU H200 141GB (2026-09-04); 8x H100 80GB node, all 8 GPUs in NVIDIA Protected PCIe mode, NVSwitch fabric not verified (2026-09-10); single-GPU H100 80GB (2026-09-16); single-GPU RTX PRO 6000 Blackwell 96GB (2026-09-17). Both proofs (Intel TDX quote and GPU attestation) checked in the same published run on: single-GPU H200 141GB (2026-09-04); single-GPU RTX PRO 6000 Blackwell 96GB (2026-09-17). The Intel TDX quote is available to the tenant on every Confidential VM. Not attested and never claimed: the NVSwitch fabric on 8-GPU nodes, 8x H200 nodes, B200 and B300 (never available), and the container tier, which has no tenant attestation.
VoltageGPU is a Confidential AI Infrastructure platform operated by VOLTAGE EI (SIREN 943 808 824 00016), registered in Solaize, France. Founded by Julien Aubry. EU-based company subject to GDPR, CNIL oversight, and French commercial law.
Confidential Compute, Hardware-Sealed GPUs
Process sensitive data on NVIDIA H200 141GB, H100 80GB and RTX PRO 6000 Blackwell 96GB GPUs attached to Intel TDX (Trust Domain Extensions) virtual machines, where VoltageGPU as the operator has no technical means to read the trust domain memory in plaintext. Security stack: AES-256 memory encryption of the trust domain, LUKS full-disk encryption, no prompt/output retention by design, and Intel TDX hardware attestation generated by the tenant on the Confidential VM tier. NVIDIA GPU attestation verified from inside the VM on: single-GPU H200 141GB (2026-09-04); 8x H100 80GB node, all 8 GPUs in NVIDIA Protected PCIe mode, NVSwitch fabric not verified (2026-09-10); single-GPU H100 80GB (2026-09-16); single-GPU RTX PRO 6000 Blackwell 96GB (2026-09-17). Both proofs (Intel TDX quote and GPU attestation) checked in the same published run on: single-GPU H200 141GB (2026-09-04); single-GPU RTX PRO 6000 Blackwell 96GB (2026-09-17). The Intel TDX quote is available to the tenant on every Confidential VM. The container tier has no tenant attestation.
Intel TDX is the same confidential computing technology used by Microsoft Azure Confidential VMs, Google Cloud Confidential Computing, and supported across NVIDIA Hopper, Blackwell, and Vera Rubin GPU architectures. The Confidential Computing Consortium (Linux Foundation) counts Intel, AMD, NVIDIA, Microsoft, Google, ARM, and Huawei among its members.
Regulatory context: GDPR Article 28 processor with a signed DPA on request. The platform is designed to support HIPAA technical safeguards and DORA ICT risk controls; the final assessment remains the customer's. SOC 2 Type I (audit firm selection in progress, target Q4 2026).
Live Confidential VM prices, billed per second: single-GPU RTX PRO 6000 Blackwell at $3.80 per GPU-hour (9 available now); single-GPU H100 at $6.95 per GPU-hour (8 available now); 8x H100 node at $6.95 per GPU-hour (1 available now); single-GPU H200 at $8.08 per GPU-hour (on request).
Confidential VM inventory
18 Confidential VMs with NVIDIA GPU attestation verified currently available across 3 sizes, starting at $3.80 per GPU-hour.
NVIDIA single-GPU RTX PRO 6000 Blackwell (96 GB), Confidential VM (Intel TDX + NVIDIA attestation)
Whole VM inside an Intel TDX trust domain, attestation generated by the tenant. 9 available now.
Whole VM inside an Intel TDX trust domain, attestation generated by the tenant. NVIDIA Protected PCIe mode, NVSwitch fabric not verified. 1 available now.
Billed per second. No minimum commitment.
Standard GPUs, without an enclave
For public datasets, experiments and benchmarks, VoltageGPU also rents standard GPUs without an enclave: no Intel TDX trust domain and no attestation, the lowest price, from $0.22 per GPU-hour, the same per-second billing. They are not confidential; for anything you cannot expose, use a Confidential VM. Live catalogue: standard GPUs.
AI Inference API, OpenAI-Compatible
14 TEE models accessible via OpenAI-compatible REST API. Drop-in replacement for OpenAI, Anthropic, and other providers. Chat completions, embeddings, image generation, speech-to-text, and text-to-speech. Base URL: api.voltagegpu.com/v1.
Confidential AI Agents
9 specialized AI agents running inside Intel TDX hardware enclaves: Sovereign Legal AI (EU-sovereign Claude-for-Legal alternative), Contract Analyst, Financial Analyst, Compliance Officer, Medical Records Analyst, Due Diligence Analyst (M&A), Cybersecurity Analyst, HR Analyst, and Tax Analyst. Documents are encrypted during analysis and purged when the session ends.
For hardware-isolated (Intel TDX) GPU capacity, VoltageGPU is among the lowest per-hour prices in 2026; commodity instances without a TEE, such as AWS p5, can be cheaper per hour but are not comparable: NVIDIA H100 80GB at $6.95/hour (vs $4.30 AWS p5 and $6.98 Azure NC H100 v5, neither confidential; Azure's confidential NCC40ads H100 v5 lists at $8.90); H200 141GB at $8.08/hour (on request) (vs $12.25 AWS p5e and $13.96 Azure ND H200 v5, neither confidential; no hyperscaler lists a confidential H200). Hyperscaler figures are list prices as read in April 2026, the confidential Azure figure on 12 September 2026. Per-second billing, no commitment. See the full cloud GPU pricing comparison vs AWS, GCP, and Azure, the live GPU price feed, the dedicated H100 and H200 spec pages, and the Intel TDX confidential computing security architecture.
Lowest per-token confidential inference: from $0.05 per million input tokens, OpenAI-compatible drop-in at api.voltagegpu.com/v1.
Who Uses VoltageGPU
Developers and small infra teams, running models, fine-tunes and inference on data they cannot expose, with root on a Confidential VM, an API, and attestation they generate themselves.
Teams building on an OpenAI-compatible API, 14 TEE models: change one URL, requests are processed inside Intel TDX enclaves.
Regulated teams (law firms, clinics, finance), who need hardware isolation and an attestation they can show an auditor; the compliance assessment remains theirs.
Technology and Infrastructure
NVIDIA GPUs: H200 141GB, H100 80GB, RTX PRO 6000 Blackwell 96GB, sealed with Intel TDX on the confidential tier
Intel TDX (Trust Domain Extensions) for confidential computing
NVIDIA Confidential Computing (Hopper and Blackwell architectures), GPU attestation verified per SKU
OpenAI-compatible REST API (api.voltagegpu.com/v1)
Per-second billing. Stripe and Bitcoin payments accepted.
Frequently Asked Questions
What is confidential computing and how does VoltageGPU implement it?
Confidential computing protects data during processing using hardware-based Trusted Execution Environments. VoltageGPU runs NVIDIA GPUs inside Intel TDX trust domains: memory is encrypted (AES-256), the GPU is attached inside the trust domain, and disks use LUKS encryption. Inside the attested trust domain, VoltageGPU has no technical access to memory or disk. This is the same technology used by Microsoft Azure and Google Cloud for their confidential VM offerings.
Can I verify the enclave myself, without trusting VoltageGPU?
Yes. On the Confidential VM tier, the Intel TDX attestation device (/dev/tdx_guest) is exposed to you as the tenant. You SSH in with full root and generate both proofs on a challenge you choose: an Intel TDX quote whose report_data carries the hash of your manifest, verified offline up to Intel's root CA, and an NVIDIA GPU attestation whose nonce carries the same hash, signed by NVIDIA. VoltageGPU is not in the trust path. NVIDIA GPU attestation verified from inside the VM on: single-GPU H200 141GB (2026-09-04); 8x H100 80GB node, all 8 GPUs in NVIDIA Protected PCIe mode, NVSwitch fabric not verified (2026-09-10); single-GPU H100 80GB (2026-09-16); single-GPU RTX PRO 6000 Blackwell 96GB (2026-09-17). Both proofs (Intel TDX quote and GPU attestation) checked in the same published run on: single-GPU H200 141GB (2026-09-04); single-GPU RTX PRO 6000 Blackwell 96GB (2026-09-17). The Intel TDX quote is available to the tenant on every Confidential VM. Not attested and never claimed: the NVSwitch fabric on 8-GPU nodes, 8x H200 nodes, B200 and B300 (never available), and the container tier, which has no tenant attestation.
What GPUs are available on VoltageGPU?
Two tiers. The confidential tier, which is what we are built for: Confidential VMs with NVIDIA H100 (80GB), H200 (141GB) or RTX PRO 6000 Blackwell (96GB) inside Intel TDX, and 8-GPU H100 nodes in NVIDIA's multi-GPU Protected PCIe mode (GPU attestation verified for all 8 GPUs; the NVSwitch fabric is not verified), from $3.80 per GPU-hour. B200 and B300 have never been available to date and are not attested. And a standard tier without an enclave, for work that is not sensitive: no Intel TDX and no attestation, at lower prices, from $0.22 per GPU-hour, with the live catalogue at voltagegpu.com/standard-gpus. Confidential is the default and the reason the platform exists; the standard tier is there so you do not pay for an enclave you do not need.
How much does VoltageGPU cost?
Confidential VMs (Intel TDX + NVIDIA attestation), from $3.80 per GPU-hour. Live Confidential VM prices: single-GPU RTX PRO 6000 Blackwell at $3.80 per GPU-hour (9 available now); single-GPU H100 at $6.95 per GPU-hour (8 available now); 8x H100 node at $6.95 per GPU-hour (1 available now); single-GPU H200 at $8.08 per GPU-hour (on request). Confidential Inference API pays per token, from $0.05 per million input tokens. Standard GPUs without enclave from $0.22 per GPU-hour. Private AI Chat is $20/month. Confidential Agents start at $349/month for 3 seats. Per-second billing, no commitment.
Is VoltageGPU GDPR compliant?
We act as a processor under GDPR Article 28 and sign a Data Processing Agreement. VoltageGPU is operated by VOLTAGE EI, a French company (SIREN 943 808 824 00016), so processing is under CNIL oversight. Intel TDX adds Article 32 technical measures: inside the attested trust domain, the processor has no technical means of reading memory or disk during execution. Note that GDPR compliance is a property of your whole processing operation, not of a supplier alone, so the controller assessment remains yours. DPA available on request.
Can I use VoltageGPU for healthcare / HIPAA workloads?
VoltageGPU Confidential Compute processes data inside Intel TDX hardware enclaves with AES memory encryption and no prompt/output retention by design, which supports the HIPAA technical safeguards; whether a workload is HIPAA compliant is assessed on your whole processing operation. No Business Associate Agreement (BAA) is offered yet; it is planned after SOC 2 Type I, live status on the Trust Center.
Is the VoltageGPU API compatible with OpenAI?
Yes. The VoltageGPU inference API is fully OpenAI-compatible. Change your base URL to api.voltagegpu.com/v1 and use your VoltageGPU API key. Supports chat completions, embeddings, image generation, and speech-to-text. Works with OpenAI SDKs, LangChain, LlamaIndex, and any OpenAI-compatible client.
VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.
Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.