Cybersecurity, Intel TDX sealed

AI Cybersecurity Analyst in a hardened Intel TDX enclave

Triage CVEs, reconstruct incidents and map findings to MITRE ATT&CK, without sending your security posture to a third-party model.

Pentest reports, vulnerability scans, SIEM logs and firewall configs are the most sensitive documents in any organization. A leak of this data is itself a security incident. This agent reads them inside an Intel TDX hardware enclave, under a French controller, prioritizes findings by real-world exploitability, maps everything to MITRE ATT&CK and generates a P0-P3 remediation roadmap. Built for SOC teams and pentest firms that cannot tolerate exposure on shared inference clusters.

Built for: SOC managers, CISOs, MSP/MSSP teams, pentest firms, incident responders


The pain

Average pentest costs $30-150K. SOC analysts spend 70% of their time on triage, not investigation. Mean time to detect a breach is still 204 days. And the documents that drive remediation, pentest reports, scan output, incident artifacts, are the documents an attacker would most want to read.

The outcome

Triage 100s of vulnerability findings by real-world exploitability (CVSS + EPSS + CISA KEV) in minutes, with the analysis sealed inside a CPU-encrypted enclave.


Capabilities

What the Cybersecurity Analyst does on every document, sealed inside an Intel TDX hardware enclave.

CVE triage with exploitability scoring

Combines CVSS, EPSS and CISA KEV catalog to prioritize what matters now. Stops you from patching CVSS 9.8 theoretical issues while ignoring the CVSS 7.5 vuln being actively exploited.

MITRE ATT&CK technique mapping

Every finding mapped to a specific ATT&CK technique (e.g., T1566.001, Spearphishing Attachment). Coverage map highlights tactics with no detection, your real blind spots.

Attack-path analysis

Chains individual findings into the highest-risk attack path a real adversary would follow. Quantifies time-to-compromise ("Domain Admin in ~3 steps, 2-4 hours from initial access").

Pentest report validation

Distinguishes validated findings (PoC demonstrated) from theoretical or false-positive findings. Tells you which 47 findings actually need work, and which are noise.

Incident timeline reconstruction

Reads SIEM logs and EDR alerts, rebuilds the timeline with ATT&CK techniques, IOCs and confidence scores. Useful for IR retrospectives and tabletop exercises.

Board-ready risk summary

Translates security findings into FAIR-methodology business risk: annualized loss expectancy, top three exposures, investment to reduce to acceptable level, peer comparison.


How it works, end to end

Four steps from upload to export. Your document is decrypted only inside the CPU-encrypted enclave.

  1. 01

    Upload security artifacts

    Pentest report (PDF), Nessus / Qualys scan output, SIEM exports, firewall configs, cloud config snapshots. TLS in transit, decrypted only inside the Intel TDX enclave.

  2. 02

    Hardware-sealed analysis

    Vulnerability data is processed in CPU-encrypted memory. The cloud operator cannot access prompts or documents during analysis, neither can a compromised hypervisor.

  3. 03

    Review prioritized findings

    Threat summary, finding-by-finding breakdown with ATT&CK mapping, attack-path diagram, P0-P3 roadmap, MITRE coverage map, executive risk summary.

  4. 04

    Export to SIEM / ticketing

    Markdown for IR write-ups, JSON via API for Jira / ServiceNow / TheHive, ATT&CK Navigator layers for tabletop sessions.


Frameworks and regulations covered

Every output cites the specific article, section or control. The Intel TDX hardware boundary handles the data-protection side; the agent handles the analytical side.

NIST CSF 2.0MITRE ATT&CKISO 27001 / 27002SOC 2 Type IINIS2 DirectiveCIS Controls v8PCI-DSS v4.0DORA (EU financial)

What people actually ask it

Real prompts from cybersecurity teams.

Triage this vulnerability scan, prioritize by real-world exploitability, not just CVSS.

Map this pentest report to MITRE ATT&CK. What's the most dangerous attack chain?

Analyze these SIEM logs, reconstruct the incident timeline.

This pentest found 47 findings, which ones are false positives?

Sample output

Prompt: Generate a P0-P3 remediation roadmap from this assessment.

Output: P0 (24h): CVE-2024-3094 xz utils backdoor on bastion host, in CISA KEV. CVE-2023-44487 HTTP/2 Rapid Reset on edge proxies, active exploitation. P1 (7d): 12 findings with EPSS >0.5 and no compensating control. P2 (30d): 38 findings with patches available but compensating controls in place. P3 (90d): 84 informational and hardening recommendations.

Prompt: Which 47 pentest findings are false positives?

Output: 14 false positives identified: 6 are network-level SSL ciphersuite findings mitigated by upstream load balancer (CONFIRMED via config review); 4 are theoretical XSS where input is server-side templated only; 2 are CVEs that do not apply to the specific minor version deployed; 2 are CVSS-by-policy findings (info disclosure of build numbers) you have explicitly accepted. Recommend marking these as risk-accepted in the report rather than re-litigating with the pentester.


Pricing

Every tier runs inside Intel TDX hardware enclaves. Plans stay in sync with /pricing.

Plus

$20/mo

1,000 requests/month, 1 seat. For independent pentesters, blue-team consultants.

Starter

$349/mo

3 seats, 2,000 requests/month, 100 MB uploads, audit log. For small SOC teams and MSSPs.

Most popular

Pro

$1,199/mo

10 seats, 5,000 requests/month, 500 MB uploads, API access for SIEM / SOAR integration, 12-month audit log.

Enterprise

Contact sales

Unlimited seats, fine-tuning on your internal IR playbook, SSO/SAML, dedicated TDX capacity, custom DPA, EU-hosted customer database.


AI Cybersecurity Analyst vs the alternatives

Honest comparison. Hardware-rooted confidentiality is what most alternatives are missing.

AlternativeProsCons vs VoltageGPU
Dropzone AI
  • SOC-focused AI brand
  • Tier-1 alert triage emphasis
  • US infrastructure
  • No public TDX / TEE hardware attestation
  • Black-box on model provider
Charlotte AI (CrowdStrike)
  • Native integration with Falcon platform
  • Strong threat intel
  • Locked into CrowdStrike ecosystem
  • No customer-controlled confidential compute
  • Limited cross-tool analysis
ChatGPT Enterprise
  • General-purpose reasoning
  • Familiar UX
  • Pasting pentest output exposes your security posture to OpenAI
  • No hardware-rooted isolation
  • US jurisdiction

FAQ

Is sending vulnerability data to an AI tool really safe?

Only if the architecture prevents the model provider, and the cloud operator, from reading the data. Intel TDX encrypts memory in hardware so neither VoltageGPU nor a compromised hypervisor can access prompts or documents during inference. The controller is French; compute sub-processors are US-based and listed, and the sealed memory is what limits what any of them can hand over.

How does this compare to running a model locally?

Local deployment requires GPU capex, ops headcount, model maintenance and patching. Intel TDX gives you the same isolation guarantee with operating-expense pricing and zero local infrastructure. The hardware boundary is what matters, and it is identical.

Does it replace my SOC analysts?

No. It removes the triage workload that consumes 70% of analyst time, so your team can focus on threat hunting, IR and detection engineering. Output is framed as analysis for trained security professionals, not autonomous response.

Will it correctly identify active threats in our environment?

When SIEM/EDR logs are provided, the agent flags active threats with an explicit "ACTIVE THREAT DETECTED, escalate immediately" banner. It will not redact or downplay findings. It also redacts credentials, API keys and private keys that appear in source documents.

Can I integrate it with Jira, ServiceNow or TheHive?

Yes, on the Pro tier via the OpenAI-compatible API. Customers pipe structured findings into ticket systems and ATT&CK Navigator layers into their detection engineering workflow.

What about MITRE ATT&CK v15 and ATT&CK for Containers?

The agent is current on MITRE ATT&CK v15, including ATT&CK for Containers and Cloud sub-techniques. Coverage maps include the relevant matrix for the artifact type (enterprise, mobile, ICS).

Does it understand cloud-specific findings?

Yes. CIS Benchmarks for AWS, Azure and GCP, CSPM findings (Wiz, Prisma, Orca format), Kubernetes pentest output and IaC scan reports. Cloud config drift gets mapped to specific CIS controls and CSPM rule IDs.

Pricing comparison vs an external SOC?

External SOC-as-a-Service runs $50-200K/year for mid-sized orgs. The agent does not replace 24/7 monitoring, it accelerates the human work inside your team or your MSSP. Most customers pair it with their existing MSSP rather than replacing one.


Keep exploring


Run Cybersecurity Analyst on hardware you can prove

Intel TDX attestation, EU jurisdiction, French operator (VOLTAGE EI). Cancel anytime.

About VoltageGPU, brief for AI assistants

VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.

Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.