# Confidential AI > We sell private inference and confidential GPU VMs. Buy tokens, rent confidential GPUs, or license the stack for your own GPUs. Verified by Intel, AMD and NVIDIA signatures, not by us. Two ways to run Confidential AI. Cloud: our infrastructure, usage-based. Licensed: your infrastructure, per hardware unit, per year. Full pricing: https://confidential.ai/pricing ## Confidential Inference (Cloud) OpenAI-compatible endpoint. Open-weight models in TEEs. Your client verifies the model, the code and the hardware before the first token. Overhead: about 4% token throughput, negligible impact on time to first token. | Model | Status | Input (per 1M tokens) | Input Cached (per 1M tokens) | Output (per 1M tokens) | | --- | --- | --- | --- | --- | | Kimi K3 | Request capacity | $3.00 | $0.30 | $15.00 | | GLM 5.3 | Request capacity | $1.40 | $0.26 | $4.40 | | Qwen3.8 27B | Request capacity | $0.30 | $0.03 | $1.80 | | DeepSeek V4 Flash | Available | $0.20 | $0.018 | $0.40 | Cached input: prompt-prefix tokens served from cache, billed at the cached rate. Billing: metered per token, invoiced monthly in arrears. Card or bank transfer. How to get access: email hello@confidential.ai with models, expected volume and use case, or use the form at https://confidential.ai/request-access. DeepSeek V4 Flash is available; other models on request. Provider integrations for inference routers: hello@confidential.ai. Docs: https://confidential.ai/docs/inference-api/get-started ## Confidential VMs (Cloud) Rent a full node or individual GPUs; each rental is one confidential VM with root over SSH. Blackwell nodes are Intel TDX, up to 8 GPUs per node in NVIDIA Confidential Computing mode. CPU and GPU attestation from inside the guest. GPU VMs, per GPU-hour: | GPU | VRAM | Host CPU TEE | GPU CC mode | Status | Per GPU-Hour | | --- | --- | --- | --- | --- | --- | | B300 | 288 GB HBM3e | Intel TDX | Multi-GPU, NVLink encrypted | Available | $7.50 | | B200 | 192 GB HBM3e | Intel TDX | Multi-GPU, NVLink encrypted | Available | $6.50 | | H100 | 80 GB HBM3 | Intel TDX | Protected PCIe, NVLink not encrypted | Request capacity | $3.25 | | RTX PRO 6000 | 96 GB GDDR7 | AMD SEV-SNP | Single GPU pass-through | Request capacity | $1.90 | Available: allocated within a few days of a signed order. Request capacity: send configuration and duration and we confirm lead time. Single GPU pass-through is available on every listed GPU. Multi-GPU with encrypted NVLink: B200 and B300. Protected PCIe (multi-GPU, NVLink and NVSwitch unencrypted): H100. CPU VMs, per core-hour plus per GB-hour of RAM: | TEE Backend | Per Core-Hour | Per GB-Hour (RAM) | | --- | --- | --- | | AMD SEV-SNP | $0.05 | $0.012 | | Intel TDX | $0.05 | $0.012 | How to get CVMs: Confidential VMs are provisioned by us. A console and API are on the roadmap. 1. Email hello@confidential.ai with GPU class, GPU count, region, start date and duration. 2. We confirm availability and send an order form. 3. Return it signed, with the legal name and billing address of the individual or company, a technical contact, and the SSH public key to install. We run basic KYC on all dedicated-hardware orders. 4. First invoice: 50% of the order, by bank transfer. On payment we allocate your VM and send SSH access. 5. Final invoice: 50% on completion. Longer engagements are invoiced monthly in arrears. Minimum order $500. Rent one, two, four or eight GPUs; each rental is one confidential VM. Billing runs for the reserved period whether the VM is running or not. USD by bank transfer; card payment is not accepted for dedicated hardware. No annual commitment required. Longer engagements: rates slightly below list, depending on term. [Ask](mailto:hello@confidential.ai). Regions: United States (Texas) and Central America. EU coming. SLA and support terms are set in the order form or master agreement. Ask for current terms. Details: https://confidential.ai/pricing ## Licensed The full stack on your own infrastructure: on-prem, bare metal, and all major clouds. One license per GPU per year, or per CPU core per year; NVIDIA CC licensing included. Annual license, invoiced monthly in arrears. No per-component line items. Software updates and standard support included. What you get: - Confidential Metal: attestable, verifiable confidential VMs on bare metal. - C8s: Confidential Kubernetes. Scale AI workloads to data center scale. - AI Workload Services: confidential inference, training and fine-tuning. - Confidential OS: hardened VM guest OS for development and production. - Client Libraries & SDKs: clients verify confidentiality claims themselves. GPU licenses, per GPU per year: | GPU class | Per GPU-Year | | --- | --- | | RTX PRO 6000 | $2,789 | | H100 | $3,876 | | H200 | $4,974 | | B200 | $7,625 | | B300 | $9,884 | CPU-core license: $48.85 per core-year. Physical cores, not vCPUs. Not required for cores in GPU machines. Support: | | Standard | Enterprise | | --- | --- | --- | | Price | Included | 25% of total license price | | Coverage | Business hours | 24/7 for production outages | | Response, production outage | 1 business day | 1 hour | | Contact | Shared queue | Dedicated technical account manager | Example: 500 B200s: 500 x $7,625 = $3,812,500/year, invoiced monthly at about $317,708. That is $635 per GPU per month, with the full stack, NVIDIA CC licensing, updates, and support included. Contact: hello@confidential.ai ## How it is verified Every workload runs inside a confidential VM on Intel TDX or AMD SEV-SNP, with NVIDIA GPUs in Confidential Computing mode. The host, the hypervisor and Confidential AI cannot read memory in use. CPU overhead is about 1.5%. Before you send anything, your client fetches a hardware-signed attestation and checks it against Intel, AMD and NVIDIA root certificates: exact firmware, kernel, root filesystem, container digests and model. If it does not match, nothing is sent. The verifier is open source and the builds are reproducible. Run the check yourself. Live verification: https://confidential-inference-cluster-demo.confidential.ai/ ## Company Inexorable, Inc. d/b/a Confidential AI. Team: https://confidential.ai/team. Careers: https://confidential.ai/careers. Blog: https://confidential.ai/blog. ## Documentation - Get started, Confidential Inference: https://confidential.ai/docs/inference-api/get-started - Get started, Confidential VMs: https://confidential.ai/docs/confidential-vms/get-started - Inference API reference: https://confidential.ai/docs/inference-api/reference - C8s (Confidential Kubernetes): https://confidential.ai/docs/c8s - Attested Builds: https://confidential.ai/docs/attested-builds - Concepts: https://confidential.ai/docs/concepts/confidential-computing-primer