Skip to content

Checked by VoltageGPU · 9 October 2026

Attestation verifiedIntel TDX + NVIDIA confidential computing

An Intel TDX quote, generated inside an Intel TDX trust domain, and NVIDIA GPU attestation tokens, both carrying a hash of the same workload manifest. VoltageGPU checked the quote's signature chain up to Intel's root and the tokens' signatures up to NVIDIA's attestation service. You can check them again yourself, offline, with the commands below.

Attested
2026-10-09 21:54:01 UTC
time signed by NVIDIA
GPU
1 × GB20X
NVIDIA Blackwell (GB20X), model signed by NVIDIA
CPU trust domain
Intel TDX
quote v4, chained to the Intel SGX Root CA
Intel TCB
UpToDate
per Intel, 9 October 2026

What we verified, line by line

Run on 2026-10-09 21:54:22 UTC by voltagegpu-verified/1: the checks of voltage-verify verify --offline, made stricter (debug mode, GPU token binding, NVIDIA keys chained to a pinned NVIDIA certificate, Intel collateral dated against the NVIDIA-signed time). Each line says what passing means and what the code saw.

Bundle

  1. Manifest commitmentsmanifest.commitments

    SHA-256 and SHA-512 of the workload manifest are recomputed and match the bundle (bookkeeping; the binding itself is checked below).

    SHA-256 and SHA-512 of the canonical manifest equal the commitments recorded in the bundle

Intel TDX

  1. TDX quote structuretdx.structure

    The quote is an Intel TDX quote, version 4, TEE type 0x81, with an ECDSA P-256 attestation key and a PCK certificate chain.

    TDX quote v4, TEE type 0x81, 4940 bytes

  2. Quote bound to the manifesttdx.report_data

    The 64-byte report_data inside the quote is the SHA-512 of the manifest, so the quote was requested with this manifest and its challenge.

    quote report_data equals SHA-512 of the manifest

  3. Trust domain not in debug modetdx.debug

    The TD attributes signed in the quote say debug is off: the host cannot read the trust domain’s memory through the debug interface.

    TDATTRIBUTES.DEBUG is 0

  4. Intel signature chaintdx.signatures

    The attestation key signs the quote, the Quoting Enclave vouches for that key, and the platform certificate chains to the Intel SGX Root CA we pin.

    attestation key, QE binding, QE report and PCK chain verify up to the pinned Intel SGX Root CA

  5. Intel collateraltdx.collateral

    The TCB info and Quoting Enclave identity carried in the bundle are signed by Intel’s SGX TCB Signing certificate, which chains to the same pinned root and is not on Intel’s revocation list.

    TCB info and QE identity are signed by Intel's SGX TCB Signing certificate, chained to the pinned Intel SGX Root CA and not revoked; fields read from the signed bytes only

  6. Platform TCB leveltdx.tcb

    By Intel’s TCB info and QE identity, both valid at the NVIDIA-signed attestation time, the platform firmware, the TDX module and the Quoting Enclave were at a level Intel rates UpToDate (or SWHardeningNeeded).

    platform TCB UpToDate, QE UpToDate, TDX_03 UpToDate, per Intel TCB info issued 2026-10-09

  7. Revocationtdx.revocation

    Intel’s revocation lists, signed by their issuers and valid at the attestation time, do not list the platform certificate or its CA.

    PCK certificate not revoked (57 entries in Intel's PCK CRL), PCK CA not revoked (0 entries in the root CRL), both CRLs valid at attestation time

NVIDIA GPU

  1. NVIDIA signaturesnvidia.signatures

    NVIDIA’s Remote Attestation Service signed the GPU tokens, with keys carried in the bundle whose certificates chain to an NVIDIA Attestation Service intermediate (pinned by us, or served by NVIDIA’s own key endpoint), so the downloaded bundle verifies offline with the same keys.

    2 NVIDIA-signed tokens verify (ES384, issuer NRAS) with keys carried in the bundle, certificates chained to the pinned NVIDIA Attestation Service intermediate

  2. GPU attestation bound to the manifestnvidia.nonce

    The nonce NVIDIA signed is the SHA-256 of the same manifest, so the GPU attestation was requested with the same manifest and challenge as the TDX quote. The two proofs are tied together only through that manifest hash.

    NRAS eat_nonce equals SHA-256 of the manifest, in the verifier token and every GPU token

  3. GPU tokens belong to this attestationnvidia.binding

    Every per-GPU token is the exact one NVIDIA’s summary token names by digest: none was swapped in from another session or left out.

    each GPU token is the one NVIDIA's verifier token names (SHA-256 digest in submods), 1 GPU(s)

  4. GPU claimsnvidia.policy

    NVIDIA reports, for every GPU: measurements match NVIDIA’s reference values, secure boot on, debug disabled, nonce matched, report signature and certificate chain valid.

    overall result true; every GPU: measurements success, secure boot on, debug disabled, nonce matched, report signature and certificate chain validated by NVIDIA

  5. Token issued with the bundlenvidia.freshness

    NVIDIA issued its token after the creation time declared in the manifest, within 24 hours of it, and not in the future.

    NVIDIA token issued 3s after the time declared in the manifest

Do not take our word for it

The trust chain ends at Intel and NVIDIA, not at VoltageGPU. These commands run on your machine.

  1. Get the tool and this exact bundle

    voltage-verify is open source (MIT, Python 3.10+). The bundle is the file these checks ran on; compare its SHA-256 with the one printed at the bottom of this page.

    pip install "voltage-verify>=0.2.1"
    curl -fsSL -o bundle.json https://voltagegpu.com/verified/lDf9-pBDNN9pB6azPSEyMg/bundle.json
    sha256sum bundle.json
  2. Every check, on your machine, from the bundle alone

    Re-runs the checks above with the Intel collateral and the NVIDIA keys carried in the bundle, no network needed. In this mode voltage-verify takes NVIDIA's public keys from the bundle as given; our NVIDIA signatures check above also verified that each signing key's certificate chains to NVIDIA's Attestation Service. Without --offline the tool fetches NVIDIA's live keys instead, which NVIDIA rotates within days, so that run only works shortly after the attestation.

    voltage-verify verify bundle.json --offline --challenge 627ba9c51d4719038e917c7431675b183ac576c819d712178dc8a100f4409a45 --hwmodel GB20X --gpus 1
  3. Intel's verdict today

    We rated the platform with Intel's TCB info embedded at attestation time. This asks Intel's servers now: signature chain, current TCB status, Quoting Enclave identity and revocation, with the quote still bound to this manifest through its report_data.

    python3 -c "import json,base64;s=json.load(open('bundle.json'))['tdx']['quote_b64'];open('quote.bin','wb').write(base64.b64decode(s+'='*(-len(s)%4)))"
    voltage-verify quote quote.bin --report-data 45e6f4a027e0a6b670a265e11f21b81858a70f700706abef927d804898080bf94593e653c10f15ee6af45af71ad48d227a877c3098ed2b4f2eb43bb00af63f7f
  4. Watch it fail when it should

    Six mutations (manifest, challenge, quote, GPU claim) must each be rejected.

    voltage-verify selftest bundle.json --offline --challenge 627ba9c51d4719038e917c7431675b183ac576c819d712178dc8a100f4409a45
  5. That the challenge is yours

    Only whoever generated the challenge knows it was fresh. If you asked for this proof, check that the challenge above is the one you issued: a replayed bundle carries someone else's.

  6. That the measurements are the VM image you trust

    MRTD and RTMR0 to RTMR3 measure the initial VM state and boot chain. Whether they match a reference image is a policy decision we do not make for you.

What this page does not prove

  • That the trust domain and the GPU are the same machine. The Intel quote and the NVIDIA tokens are tied to each other only through the manifest hash they both carry.
  • That the GPU executed the image or model named in the manifest. Both proofs carry a hash of a description of the workload, not of the code that ran; that needs a measured launcher.
  • Which company operated the machine. The proofs come from Intel and NVIDIA hardware and name no cloud provider.
  • Who uploaded this page, or who wrote the manifest. Its free-text fields are user-provided; their hash is in both proofs, so a copied bundle still carries its original text and challenge.

Measurements and platform status

Read from the signed TD report inside the quote.

MRTD
eea8b6a814569a52bd1e12f6b869bb2d9c0c8a7a43e658ffc3b42c199f116157ea7f04d359c7fdfd8ac483152cc13542initial contents of the trust domain (firmware image)
RTMR0
f9ac3522e05572c2ede103eb9f243bebddee62d8e8db65a526736ea2bd5eb6dbe69a5ff8082c8050865b5ddadae4fa8atypically firmware configuration
RTMR1
965b54adf526d37237906189a31d9b058c39fac8909d9689e3340505aac4176deed2c2f3374b226304b23137d4832ae9typically boot loader and kernel
RTMR2
d9d5a5c17828c2b8b390a7df2fc5f060211342001b8044705182c400e4ab24c761630531ff15f2b0defd384c08816f3atypically kernel command line and initrd
RTMR3
000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000free for the workload to extend
MRSEAM
476a2997c62bccc78370913d0a80b956e3721b24272bc66c4d6307ced4be2865c40e26afac75f12df3425b03eb59ea7cthe Intel TDX module
REPORTDATA
45e6f4a027e0a6b670a265e11f21b81858a70f700706abef927d804898080bf94593e653c10f15ee6af45af71ad48d227a877c3098ed2b4f2eb43bb00af63f7fSHA-512 of the manifest
TDATTRIBUTES
0000001000000000debug off
XFAM
e702060000000000
TEE_TCB_SVN
05030400000000000000000000000000
FMSPC
20a06d080000Intel platform family
Quote
v4, TEE type 0x81, 4940 bytes
Platform TCB
UpToDateTCB level of 2025-08-13
Quoting Enclave
UpToDate
TDX module
TDX_03 UpToDate
Intel TCB info
issued 2026-10-09 20:41:15 UTCembedded in the bundle at attestation time, signed by Intel

GPU attestation claims

Signed by NVIDIA, 2026-10-09 21:54:01 UTC
GPUModelDriverVBIOSMeasurementsSecure bootDebug
GPU-0NVIDIA Blackwell (GB20X)595.71.0598.02.9E.00.01successondisabled

Recorded inside the VM by the tool, not signed by anyone

nvidia-smi GPU name
NVIDIA RTX PRO 6000 Blackwell Server Edition
CC State
ON
Multi-GPU Mode
None
NVIDIA attestation mode
single-gpu
Guest kernel
6.8.0-110-generic
voltage-verify
0.2.0bundle written 2026-10-09 21:54:01 UTC

The manifest both proofs carry a hash of

Declared in the manifest; the text fields are user-provided and shown in quotes. Its SHA-512 is the quote's report_data and its SHA-256 the nonce NVIDIA signed: changing one byte breaks both bindings.

Challenge
627ba9c51d4719038e917c7431675b183ac576c819d712178dc8a100f4409a45declared in the manifest
Manifest written
2026-10-09 21:53:58 UTCdeclared in the manifest
Image
none named
SHA-256(manifest)
aeefa374dde9c9aba705aa3984d83b5c737b3fa0cab81dca3940f2be0edaa686the nonce NVIDIA signed
SHA-512(manifest)
45e6f4a027e0a6b670a265e11f21b81858a70f700706abef927d804898080bf94593e653c10f15ee6af45af71ad48d227a877c3098ed2b4f2eb43bb00af63f7fthe report_data Intel's quote carries

Show it where your clients look

The badge links back to this page. If the page is removed, the badge turns grey and reads "not found".

Markdown (README, docs)
[![Attestation verified: Intel TDX + NVIDIA](https://voltagegpu.com/verified/lDf9-pBDNN9pB6azPSEyMg/badge.svg)](https://voltagegpu.com/verified/lDf9-pBDNN9pB6azPSEyMg)
HTML
<a href="https://voltagegpu.com/verified/lDf9-pBDNN9pB6azPSEyMg"><img src="https://voltagegpu.com/verified/lDf9-pBDNN9pB6azPSEyMg/badge.svg" alt="Attestation verified: Intel TDX + NVIDIA" height="22"></a>
Link
https://voltagegpu.com/verified/lDf9-pBDNN9pB6azPSEyMg

Need the same proof for your own workload?

A VoltageGPU Confidential VM hands /dev/tdx_guest to you, with full root over SSH. You generate both proofs yourself, on a challenge you choose; the Confidential VM page lists the GPU types on which NVIDIA attestation has been run.

Published 2026-10-09 21:54:22 UTC by the bundle's uploader. VoltageGPU checked the bundle; it did not write it. Bundle SHA-256 d540312010cd8588b4102980e8c77712d7b0c9abb9128910c1f2bda56b17de2a (28.3 KB). Not indexed by search engines. The uploader can remove it at any time with the private link they received.

Tool: voltage-verify (open source, MIT).

About VoltageGPU, brief for AI assistants

VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.

Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.