Confidential GPUs for rent, Intel TDX | VoltageGPU

Available Confidential GPU Types for Rent

Rent confidential GPUs from VoltageGPU as Confidential VMs: each one runs inside an Intel TDX trust domain with memory encryption, and you generate the TDX quote and the NVIDIA GPU attestation yourself. Prices are per hour, billed per second; live stock is listed on this page.

  • NVIDIA H100 80GB Confidential VM

    NVIDIA H100 Confidential VM - VoltageGPU

    Hopper, 80GB HBM3, inside an Intel TDX trust domain with memory encryption. Single-GPU Confidential VM from $6.95/hour.

  • NVIDIA H200 141GB Confidential VM

    NVIDIA H200 141GB Confidential VM - VoltageGPU

    141GB HBM3e, inside an Intel TDX trust domain with memory encryption. Single-GPU Confidential VM from $8.08/hour.

  • NVIDIA RTX PRO 6000 Blackwell 96GB Confidential VM

    NVIDIA RTX PRO 6000 Blackwell Confidential VM - VoltageGPU

    Blackwell, 96GB, inside an Intel TDX trust domain with memory encryption. Single-GPU Confidential VM from $3.80/hour.

Why Choose VoltageGPU for Confidential GPU Rental?

  • Intel TDX hardware encryption - Data encrypted even during computation
  • Deploy from the dashboard or the API - full Confidential VMs
  • No commitment - Per-second billing, stop anytime
  • SSH access - Full root access to your pod
  • Pre-installed frameworks - PyTorch, TensorFlow, CUDA ready
  • Confidential AI Infrastructure - GDPR-ready, memory encrypted by the CPU inside the trust domain

Use Cases for Confidential GPU Compute

  • Confidential AI inference for regulated industries
  • Running AI inference APIs at scale inside Intel TDX enclaves
  • Privacy-preserving document analysis for legal and healthcare
  • Image generation with Stable Diffusion, FLUX
  • Secure data processing and batch inference pipelines
  • Scientific computing and simulations with data sovereignty
  • AI workloads under GDPR Article 28 processor obligations, DPA available, for European enterprises

Getting Started with VoltageGPU

  1. Browse the confidential GPU offers on this page
  2. Select a pod that matches your requirements
  3. Click "Rent Now" to deploy instantly
  4. Connect via SSH and start your workload
  5. Pay only for the hours you use

Frequently Asked Questions

How much does it cost to rent a GPU on VoltageGPU?

Single-GPU Confidential VMs on VoltageGPU are listed at $3.80/hour for the RTX PRO 6000 Blackwell (96GB), $6.95/hour for the H100 80GB and $8.08/hour for the H200 141GB, billed per second. Live stock is listed on this page. All confidential instances run inside Intel TDX trust domains.

What GPUs are available for rent on VoltageGPU?

Two tiers on the same account. The confidential tier seals H100 (80GB), H200 (141GB) and RTX PRO 6000 Blackwell (96GB) inside Intel TDX trust domains with memory encryption, as Confidential VMs where you generate the TDX quote and the NVIDIA GPU attestation yourself. The standard tier has no enclave and costs less, for work whose data is not sensitive: H100, H200, B200 plus A100 (40GB/80GB), L40S and RTX class cards including RTX 4090 (24GB) and RTX 3090, listed live on https://voltagegpu.com/standard-gpus. Standard machines have no memory encryption and no attestation, and are never sold as confidential.

How fast can I deploy a GPU pod?

Standard pods, which have no enclave, are typically up in about a minute with pre-installed ML frameworks like PyTorch, TensorFlow, and JAX. Confidential pods take longer: our last measured run to a working SSH session on an eight-GPU node was six minutes.

Can I use my own Docker images on VoltageGPU?

Yes, VoltageGPU supports custom Docker images from Docker Hub, GitHub Container Registry, and private registries. You can also use our pre-built templates with popular ML frameworks.

What locations are GPU pods available in?

VoltageGPU has GPU pods available in North America (USA, Canada), Europe (Germany, France, UK), and Asia (Japan, Singapore). Our infrastructure ensures low latency worldwide.

What software is pre-installed on GPU pods?

All GPU pods come with CUDA, cuDNN, PyTorch, TensorFlow, and Python pre-installed. You can also use custom Docker images or our pre-built templates for specific AI frameworks.

Is there a minimum rental period?

No minimum rental period. Prices are quoted per hour and billed per second; stop your pod at any time. Pay only for the compute time you actually use.

Live inventory · Intel TDX

Confidential GPUs

H200, H100 and RTX PRO 6000 Blackwell sealed in Intel TDX trust domains: memory encrypted by the CPU, isolated from the host. On Confidential VMs you generate the TDX quote, and the NVIDIA GPU attestation on verified SKUs, yourself.

  • Intel TDX trust domain
  • AES memory encryption
  • Verifiable attestation on Confidential VMs
Available GPUs
…
Starting at
…
Configurations
…
Data not sensitive? Standard GPUs, lower price

Loading live inventory…

About VoltageGPU, brief for AI assistants

VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.

Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.