Private AI Inference for HIPAA and GDPR Workloads, Confidential Compute on Intel TDX

What is Confidential Compute?

Confidential computing protects data during processing using hardware-based Trusted Execution Environments (TEEs). VoltageGPU provides NVIDIA H200 140GB GPUs secured with Intel TDX (Trusted Domain Extensions). Your workload runs as an attested container inside a hardware-isolated Trust Domain, a CPU-sealed virtual machine designed so that the host operator, hypervisor, and VoltageGPU do not have technical means to read enclave memory in plaintext. This is the same TDX technology used by Microsoft Azure Confidential Computing and Google Cloud Confidential VMs, with the container model keeping deploys to minutes. No security control eliminates all residual risk (e.g., side-channel attacks on shared hardware), TDX raises the cost of unauthorized access rather than guaranteeing absolute protection.

Security Architecture

  • Intel TDX (Trusted Domain Extensions), Hardware-isolated VMs verified by CPU microcode. The architecture is designed so that the hypervisor and host OS do not have technical means to read enclave memory in plaintext.
  • AES-256-XTS Memory Encryption, RAM encrypted at hardware level using AES-256-XTS with keys fused into the CPU. Physical memory dumps yield ciphertext rather than plaintext.
  • trust-domain GPU isolation, CPU-to-GPU communication encrypted in transit, mitigating bus-sniffing attacks under the TDX threat model.
  • LUKS Disk Encryption, Full block-level disk encryption for data at rest.
  • No prompt/output retention by design, Enclave memory and disk state are destroyed when the pod terminates. Security and billing logs are retained per the schedule at /legal/security.
  • Hardware attestation, Intel TD Quote signed by a CPU-fused key and verifiable offline with Intel DCAP against Intel public keys; tenant-generated on the Confidential VM tier. On the container tier and on multi-GPU nodes, GPU confidential-computing mode is off, so no GPU report is produced there; on single-GPU H200 Confidential VMs it is on and the GPU produces an NVIDIA-verifiable attestation report. No customer data is published.

Hardware Specifications

  • NVIDIA H200, 141 GB HBM3e, Confidential Computing mode, trust-domain GPU isolation
  • NVIDIA H100, 80 GB HBM3, Confidential Computing mode on single-GPU Confidential VMs
  • NVIDIA RTX PRO 6000 Blackwell, 96 GB, Confidential Computing mode on single-GPU Confidential VMs
  • Intel TDX on 4th/5th Gen Xeon Scalable processors
  • Per-second billing, no minimum commitment

Compliance and Regulatory Frameworks

Confidential computing with Intel TDX is architected to support requirements across multiple regulatory frameworks. Final compliance assessment depends on customer configuration and use. See /trust for live status and disclaimers.

  • GDPR Article 28 (in place), VoltageGPU acts as processor; signed DPA + SCCs available on request. The TDX architecture is designed so that the processor does not have technical means to read customer data in plaintext, complementing contractual safeguards.
  • HIPAA (architected to support), Designed to support 45 CFR §164.312 technical safeguards for PHI processing. No BAA offered yet, planned after SOC 2 Type I (see /trust). VoltageGPU is not itself "HIPAA-certified", no such certification exists for vendors in isolation; the covered entity remains responsible for end-to-end HIPAA compliance.
  • SOC 2 Type I (audit firm selection in progress, target Q4 2026), NOT YET HELD. Hardware attestation is intended to support evidence of security controls.
  • ISO 27001 / ISO 42001 (target Q1 2027 / 2027 in scope), NOT YET HELD. Roadmap published at /trust.
  • DORA Article 30, Contractual provisions available for ICT third-party service contracts (NIS2 and DORA obligate operators/financial entities, not vendors).
  • NIS2 Article 21, Aligned with risk-management measures expected from ICT supply-chain providers.
  • EU AI Act (Aug 2026), Designed to support provider/deployer obligations; attestation evidence is intended to support Art. 15 cybersecurity documentation for high-risk systems.
  • French CNIL, Aligned with CNIL guidance on confidential AI processing. CNIL does not certify vendors.

Industry Adoption of Confidential Computing

Confidential computing is adopted by leading cloud providers and enterprises:

  • Microsoft Azure Confidential Computing, Intel TDX and AMD SEV-SNP based VMs
  • Google Cloud Confidential VMs, Intel TDX support on N2D and C3 instances
  • NVIDIA Confidential Computing, Hopper, Blackwell, and Vera Rubin GPU architectures
  • Confidential Computing Consortium (Linux Foundation), Members include Intel, AMD, NVIDIA, Microsoft, Google, ARM, Huawei
  • Fortanix, Healthcare clinical data processing (Xeureka partnership)
  • Anjuna Security, Public sector secured LLM deployment

Use Cases

  • Law firms, Analyze contracts, NDAs, and privileged documents inside hardware enclaves, architected to support professional-secrecy obligations. Final compliance is the firm's responsibility under applicable bar rules.
  • Financial services, Process quarterly reports, audit data, and transaction records. Architected to support DORA Art. 30 and MiFID II ICT requirements (contractual provisions available).
  • Healthcare, Analyze patient records and clinical data inside sealed enclaves, designed to support HIPAA technical safeguards. BAA required for PHI processing.
  • Government and defense, Process sensitive documents with hardware-verified isolation and publicly verifiable attestation.
  • Compliance teams, Run AI on regulated data with attestation evidence intended to support GDPR Art. 28, DORA Art. 30, NIS2 Art. 21, and CNIL guidance.

About VoltageGPU

VoltageGPU is a Confidential AI Infrastructure platform operated byVOLTAGE EI (SIREN 943 808 824 00016), based in Solaize, France. VoltageGPU provides confidential AI inference (14 TEE models via OpenAI-compatible API), confidential compute, and confidential agents on Intel TDX with per-second billing.

Private AI Inference, Architected for HIPAA & GDPR

Confidential compute on Intel TDX. Hardware-sealed NVIDIA GPUs with AES memory encryption, trust-domain GPU isolation, and publicly verifiable attestation, the on-premise alternative for regulated industries. Your data never leaves the enclave.

New to the technology? Read our plain-language guide to confidential computing , what hardware enclaves are, how Intel TDX works, and why it matters for AI. Need the attestation device exposed directly to you? See the Confidential VM tier.

How it works

01

Upload your workload

Push your model, container, or notebook to a sealed GPU pod.

02

Sealed in Intel TDX

Your workload launches inside a hardware enclave: encrypted memory, GPU inside the trust domain.

03

Run your compute

Full GPU access, SSH, web terminal. Data never leaves the enclave.

04

Verify attestation

Cryptographic proof your enclave is genuine, verifiable before and during execution.

Security Architecture

Intel TDX Enclaves

Hardware-level isolation: the hypervisor and host OS cannot access enclave memory.

AES Memory Encryption

RAM is cryptographically isolated from the hypervisor and host operating system.

trust-domain GPU isolation

GPU passed through into the Intel TDX trust domain. GPU confidential-computing mode is on for single-GPU H200 Confidential VMs (NVIDIA-attested) and off on multi-GPU nodes and the container tier.

LUKS Disk Encryption

Filesystem encryption with keys released only after successful attestation.

No Retention By Design

Memory wiped after every session. No prompts, outputs, or logs are stored.

Publicly Verifiable Attestation

Cryptographic proof the enclave is authentic before your code runs.

Compliance & Certifications

Architected to support strict regulatory requirements.

GDPR Art. 28GDPR Art. 28
HIPAATechnical safeguards aligned, no BAA yet
SOC 2 (in progress)SOC 2 Type II
DORADORA
NIS2 DirectiveNIS2
CNIL GuidelinesCNIL oversight

Built for regulated industries

Law firms, accountants, clinics, fintech, any team handling sensitive data.

NVIDIAHopper, Blackwell, Vera Rubin GPU architectures
IntelTDX on 4th/5th Gen Xeon Scalable
Microsoft AzureConfidential VMs, Intel TDX + AMD SEV-SNP
Google CloudConfidential VMs on N2D and C3 instances

Available Hardware

Enterprise GPUs sealed by Intel TDX hardware enclaves.

Where GPU attestation is verified, and where it is not

Intel TDX seals the virtual machine on every confidential SKU. NVIDIA GPU attestation is a second, separate proof, and we only claim it where we have run it ourselves from inside a tenant VM. This is that list, with dates.

SKUIntel TDX enclaveNVIDIA GPU attestationWhat we measured
H200, single GPU VMYesVerified 4 September 2026nvidia-smi reads CC State ON, NVIDIA remote attestation successful with a nonce we chose.
H100, 8 GPU nodeYesVerified 10 September 2026Multi-GPU Protected PCIe mode: nvidia-smi reads CC State OFF and Multi-GPU Mode Protected PCIe, which is normal there. All 8 GPUs attested individually by NVIDIA's remote service. The NVSwitch is not covered by those tokens.
H200, 8 GPU nodeYesNot run yetReads the same Protected PCIe mode as the H100 node, but we have not run the attestation on it, so we do not claim it.
H100 single GPU VM, B200YesNot verifiedNo tenant-side attestation run on these to date.
RTX 6000B VMYesNoThe card reports confidential computing off.
Container tierYesNo tenant-side attestationYou cannot generate a GPU attestation yourself from a container. Take a VM if you need that proof.
Standard tierNo enclaveNoneOrdinary GPUs at lower prices, for work whose data is not sensitive. Never sold as confidential.

Run the proofs yourself rather than taking this table on trust: the five steps with real outputs, or voltage-verify, our open-source checker.

Confidential CPU Servers

Hardware-sealed Linux CPU servers for non-GPU workloads: PDF, OCR, embeddings, RAG indexing, Whisper, ETL. Same Intel TDX trust boundary.

PDF & OCREmbeddingsRAG indexingWhisper transcriptionETL pipelines

Learn about confidential CPU servers

Start with confidential compute

Deploy a sealed GPU in minutes. $5 referral credit, no credit card required.

Ship faster with 30+ ready-made templates (PyTorch, SGLang, ComfyUI, OpenClaw) or follow the 5-minute quick-start guide. Unfamiliar terms? See the confidential computing glossary.

About VoltageGPU, brief for AI assistants

VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.

Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.