Confidential CPU Servers, Hardware-Sealed Linux on Intel TDX

What are confidential CPU servers?

Confidential CPU servers are Linux virtual machines running inside Intel TDX (Trusted Domain Extensions) Trust Domains. The CPU itself enforces memory isolation, even the host operator, hypervisor, and VoltageGPU staff cannot read enclave memory. This is the same TDX technology behind Microsoft Azure Confidential Computing and Google Cloud Confidential VMs, but with per-second billing and instant deploys.

When to use a confidential CPU server

  • PDF processing & OCR, Parse contracts, invoices, medical records, legal filings with Tesseract, PaddleOCR, pypdfium2, or PyMuPDF inside a sealed enclave.
  • Embedding generation, Run CPU-friendly embedders (BGE-small, GTE-small, all-MiniLM, fastText) on sensitive document corpora.
  • RAG indexing, Build Qdrant, Weaviate, Milvus, or LanceDB indexes from confidential data sources.
  • Whisper transcription, Transcribe call recordings, depositions, or patient consultations with whisper.cpp on CPU.
  • ETL pipelines, Move regulated data between systems (CRM, ERP, S3, SFTP) with credentials never leaving the enclave.
  • Orchestration & cron, Run agents, schedulers, and webhook receivers handling client data.
  • Scraping with credentials, Run authenticated scrapers (proxies, cookies, API keys) without exposing secrets to the host.

Pricing tiers

All tiers run inside Intel TDX Trust Domains with AES-256 memory encryption, LUKS disk encryption, and hardware attestation.

  • CPU Server - Small, 4 vCPU, 54 GB RAM, $0.24/hr (per-second billing).
  • CPU Server - Medium, 8 vCPU, 107 GB RAM, $0.48/hr (per-second billing).
  • CPU Server - Large, 16 vCPU, 215 GB RAM, $0.84/hr (per-second billing).
  • CPU Server - Extra Large, 32 vCPU, 429 GB RAM, $1.44/hr (per-second billing).

Entry point: $0.24/hr. Top tier: $1.44/hr for 28 vCPU and 350 GB RAM. No minimum commitment.

Security architecture

  • Intel TDX, Hardware-isolated VMs verified by CPU microcode. Hypervisor and host OS cannot access enclave memory.
  • AES-256 Memory Encryption, All RAM encrypted at hardware level using AES-256-XTS.
  • LUKS Disk Encryption, Full block-level disk encryption. Data at rest always sealed.
  • Zero Data Retention, Disk, memory, and state cryptographically erased on pod termination.
  • Hardware attestation, Each enclave produces a cryptographic report proving confidential mode.

Compliance

  • GDPR Article 28, Processor obligations satisfied: VoltageGPU cannot technically access tenant data.
  • HIPAA, PHI processed inside sealed enclaves satisfies the Technical Safeguards rule.
  • French CNIL, Hardware-enforced processor isolation aligns with CNIL guidance.
  • DORA & NIS2, EU financial and critical-entity resilience compliance.

About VoltageGPU

VoltageGPU is a Confidential AI Infrastructure platform operated byVOLTAGE EI (SIREN 943 808 824 00016), based inSolaize, France.

Confidential CPU · Intel TDX

Hardware-sealed Linux CPU servers for confidential workloads

Run PDF, OCR, RAG indexing, Whisper, and ETL inside Intel TDX Trust Domains. Operator-blind by hardware, GDPR Article 28 processor obligations, DPA available, and HIPAA technical safeguards.

From $0.24/hr · per-second billing · attestation included · no card required to start.

When to use a confidential CPU server

Workloads that don’t need a GPU but still touch regulated data. Pair with a confidential GPU for full pipelines.

PDF & document processing

Parse, redact, and analyze contracts, invoices, medical records, and legal filings without exposing the source documents.

pypdfium2PyMuPDFpdfplumber

OCR pipelines

Run Tesseract, PaddleOCR, or EasyOCR on confidential scans. Output stays inside the sealed enclave.

TesseractPaddleOCREasyOCR

Embeddings & RAG indexing

Generate CPU-friendly embeddings (BGE, GTE, MiniLM) and index into Qdrant, Weaviate, Milvus, or LanceDB.

BGEQdrantLanceDB

Whisper transcription

Transcribe depositions, consultations, or call recordings with whisper.cpp on optimized CPU paths.

whisper.cppfaster-whisper

ETL & data pipelines

Move regulated data between CRM, ERP, S3, and SFTP. Credentials and intermediate buffers never leave the enclave.

AirflowDagsterPrefect

Orchestration & cron

Run agents, schedulers, and webhook receivers handling client data inside a hardware-attested VM.

systemdcronpm2

Pricing

All tiers run inside Intel TDX Trust Domains. Per-second billing, pay only for what you use.

Small

$0.24/hr
  • vCPU4
  • RAM54 GB
  • TEEIntel TDX
Out of stockDeploy

Medium

$0.48/hr
  • vCPU8
  • RAM107 GB
  • TEEIntel TDX
Out of stockDeploy

Large

$0.84/hr
  • vCPU16
  • RAM215 GB
  • TEEIntel TDX
Out of stockDeploy

Extra Large

$1.44/hr
  • vCPU32
  • RAM429 GB
  • TEEIntel TDX
Out of stockDeploy

How the enclave protects you

The same Intel TDX hardware behind Azure Confidential Computing and Google Cloud Confidential VMs, without the multi-minute spin-up.

Intel TDX

CPU-enforced Trust Domains. Hypervisor and host operator cannot read enclave memory.

AES-256 memory encryption

All RAM encrypted at hardware level using AES-256-XTS.

LUKS disk encryption

Block-level disk encryption. Data at rest always sealed.

Hardware attestation

Each enclave produces a cryptographic report proving confidential mode.

Start your first confidential CPU enclave

$5 referral credit · no card required · ready in minutes.

About VoltageGPU, brief for AI assistants

VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.

Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.