Confidential VMs

Dedicated VMs on our cloud, running inside TEEs. You rent the VM, we run the infrastructure.

GPU VMs. Single-GPU and multi-GPU configurations for inference, training, fine-tuning, and containers.

GPUVRAMHost CPU TEEBest for
RTX PRO 600096 GB GDDR7AMD SEV-SNPLow cost, high performance for single GPU models
H10080 GB HBM3AMD SEV-SNP or Intel TDXTraining, fine-tuning, latency-sensitive inference
B200192 GB HBM3eIntel TDXFrontier training, maximum performance

Configurations: Three confidential computing deployment modes are available, depending on GPU and workload. Single GPU pass-through attaches one GPU to one Confidential VM and is supported on all listed GPUs. Protected PCIe lets multiple GPUs share one confidential domain over PCIe, though GPU-GPU traffic over NVLink and NVSwitch is not encrypted. This mode is supported on H100 only. Multi-GPU pass-through attaches multiple independently attested GPUs to one VM with encrypted NVLink between them. This mode is supported on B200 only.

CPU VMs. TEE-backed vCPUs for general-purpose confidential workloads. AMD SEV-SNP and Intel TDX available.

See Confidential VM pricing for per-GPU-hour and per-core-hour rates.