Confidential CPU Servers, Hardware-Sealed Linux on Intel TDX
What are confidential CPU servers?
Confidential CPU servers are Linux virtual machines running inside Intel TDX (Trusted Domain Extensions) Trust Domains. The CPU itself enforces memory isolation, even the host operator, hypervisor, and VoltageGPU staff cannot read enclave memory. This is the same TDX technology behind Microsoft Azure Confidential Computing and Google Cloud Confidential VMs, but with per-second billing and instant deploys.
When to use a confidential CPU server
PDF processing & OCR, Parse contracts, invoices, medical records, legal filings with Tesseract, PaddleOCR, pypdfium2, or PyMuPDF inside a sealed enclave.
Embedding generation, Run CPU-friendly embedders (BGE-small, GTE-small, all-MiniLM, fastText) on sensitive document corpora.
RAG indexing, Build Qdrant, Weaviate, Milvus, or LanceDB indexes from confidential data sources.
Whisper transcription, Transcribe call recordings, depositions, or patient consultations with whisper.cpp on CPU.
ETL pipelines, Move regulated data between systems (CRM, ERP, S3, SFTP) with credentials never leaving the enclave.
Orchestration & cron, Run agents, schedulers, and webhook receivers handling client data.
Scraping with credentials, Run authenticated scrapers (proxies, cookies, API keys) without exposing secrets to the host.
Pricing tiers
All tiers run inside Intel TDX Trust Domains with AES-256 memory encryption, LUKS disk encryption, and hardware attestation.
CPU Server - Small, 4 vCPU, 54 GB RAM, $0.24/hr (per-second billing).
CPU Server - Medium, 8 vCPU, 107 GB RAM, $0.48/hr (per-second billing).
CPU Server - Large, 16 vCPU, 215 GB RAM, $0.84/hr (per-second billing).
CPU Server - Extra Large, 32 vCPU, 429 GB RAM, $1.44/hr (per-second billing).
Entry point: $0.24/hr. Top tier: $1.44/hr for 28 vCPU and 350 GB RAM. No minimum commitment.
Security architecture
Intel TDX, Hardware-isolated VMs verified by CPU microcode. Hypervisor and host OS cannot access enclave memory.
AES-256 Memory Encryption, All RAM encrypted at hardware level using AES-256-XTS.
LUKS Disk Encryption, Full block-level disk encryption. Data at rest always sealed.
Zero Data Retention, Disk, memory, and state cryptographically erased on pod termination.
Hardware attestation, Each enclave produces a cryptographic report proving confidential mode.
VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.
Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.