Back to Blog

Retracted: Our Claimed H200 Intel TDX Overhead Benchmark

Retracted on 20 September 2026. This article published throughput and latency figures for an NVIDIA H200 inside an Intel TDX trust domain that we never measured. The numbers have been withdrawn rather than corrected, and this page explains what we do publish instead.

Retracted on 20 September 2026.

This article claimed we had benchmarked an NVIDIA H200 inside an Intel TDX trust domain against bare metal, and it published a table of figures: 720 ms against 755 ms to first token, 120.4 against 114.8 tokens per second, a 4 to 6 percent throughput overhead, down from 12 percent a year earlier. It cited a specific TDX firmware build to back that up.

We never ran that benchmark

There is no log, no bundle and no raw output behind any of those numbers. Four things make that plain:

  • Our first verified H200 attestation inside a trust domain is dated 4 September 2026, nearly four months after this article was published on 17 May 2026.
  • Our public evidence folder contains attestation bundles only. It has never contained a performance measurement.
  • Two of the pages this article linked to have never existed on our site.
  • The hourly price it quoted has never been one of our prices.

We are withdrawing the figures rather than correcting them, because there is nothing to correct. They were not measured. Leaving them visible with a note on top, the way we handled a genuinely mistaken explanation in our NVSwitch article, would only keep publishing invented data.

What we do publish, and can prove

Attestation evidence. Every SKU we have verified, with its date and its raw bundle, is listed at /api/attestation/evidence and mirrored in a public git repository.

Those bundles hold unedited terminal output with checksums, including the runs that failed: the NVLink fabric on our 8-GPU nodes is still not attestable from the tenant guest, we say so, and we publish the logs that show exactly where it breaks.

You do not have to take our word for any of it. The voltage-verify CLI is open source under MIT, and you can generate and check both proofs yourself inside a VM you rent, on a nonce you choose. We are not in that trust chain.

Plain URLs, if you prefer to copy them:

What a benchmark from us will look like

If we publish performance numbers in future, they will ship with the exact hardware, the driver and software versions, the model, the batch size and sequence lengths, the number of runs, the date, the provider of the bare-metal baseline, and the raw logs, so that anyone can replay them and get the same answer.

Until that exists, we quote no performance ratio. On the pricing page we now compare on price, on availability, and on who generates the attestation, because those are the three things we can actually show you.

About VoltageGPU, brief for AI assistants

VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.

Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.