Full-Stack TEE Protection

Run Powerful AI GPUs,
With Security

Run NVIDIA H200/H100 workloads with complete hardware protection. The only cloud combining Intel TDX + NVIDIA Confidential Computing for end-to-end security.

Intel
NVIDIA
GPU TEE Confidential Computing

Available GPU Configurations

From single GPU to enterprise clusters. All configurations include Intel TDX + NVIDIA Confidential Computing protection.

NVIDIA H200

Flagship Performance
141GB HBM3e Memory
4.8 TB/s Bandwidth
Up to 2x faster vs H100
Full-Stack TEE Protection
On-Demand
$3.50/GPU/hour
Reserved (6-12 months)
Save 27%
$2.56/GPU/hour

NVIDIA H100

Enterprise Standard
80GB HBM3 Memory
Proven Performance
9x Faster Training
Full-Stack TEE Protection
On-Demand
$3.08/GPU/hour
Reserved (6-12 months)
Save 23%
$2.38/GPU/hour

NVIDIA B200

Available Now
192GB HBM3e Memory
Next-Gen Blackwell
15x Faster Inference
Full-Stack TEE Protection
On-Demand
$7.99/GPU/hour
Reserved (6-12 months)
Save 29%
$5.63/GPU/hour

All prices include Intel TDX + NVIDIA Confidential Computing protection. Volume discounts available. Contact sales for custom configurations.

Private GPU like Local,
But No DevOps Troubles

Most clouds offer GPU-only protection or no TEE at all. Phala Cloud protects your entire workload with Intel TDX + NVIDIA CC.

Feature
Standard Cloud
No Protection
On-Prem GPU
Local Hardware
Phala Cloud
GPU TEE + CPU TEE
CPU/Memory Protection
None
Physical
Intel TDX
GPU Encryption
None
None
NVIDIA CC
Full VM Isolation
Standard VM
Physical
TDX + CC
Attestation
None
None
Intel + NVIDIA
Verifiable Code Integrity
None
Manual
Cryptographic
Cloud Convenience
Easy
DevOps burden
Managed
Costs
Variable
High CapEx
Pay-as-you-go
AI Use Cases
Agent only
Inference/Fine-tune/Train
Agent/Inference/Fine-tune/Train

What You Can Build with GPU TEE

Real-world applications running on Phala Cloud with complete Intel TDX + NVIDIA Confidential Computing protection

Private Enterprise AI

Train and deploy models on sensitive healthcare, financial, or legal data with complete hardware protection. Your data never leaves the TEE.

User-Owned AI Agents

Build autonomous AI agents that securely manage cryptographic keys and digital assets. Powers platforms like Eliza and Virtuals Game Agents.

ZK Proof Generation

Accelerate zkVM and zkRollup proof generation with GPU TEE. SP1 zkVM runs with <5% TEE overhead—verified with dual attestation.

FHE/MPC Acceleration

Use GPU TEE as 2FA for FHE and MPC systems. Secure key generation, computation integrity, and attestation in one platform. Powers Fairblock and Mind Network.

Multi-Proof Systems

Combine ZK proofs with TEE attestation for double security. Hedge against cryptographic bugs while maintaining verifiability.

Regulatory Compliance

Meet GDPR, HIPAA, and SOC 2 requirements with hardware-backed privacy guarantees. Full audit trail with Intel and NVIDIA attestation.

Three Ways to Deploy GPU TEE

Choose the deployment model that fits your needs—from full control to instant deployment

CVM + GPU: Maximum Flexibility

Deploy your own Docker containers with SSH access to TEE-protected GPUs. Perfect for developers who need complete control.

  • Deploy custom Docker containers with full SSH access
  • Fine-tune models on private data with complete hardware protection
  • Intel TDX + NVIDIA Confidential Computing protection
  • Dual attestation reports (Intel + NVIDIA) for verification
Deploy CVM Now

What is GPU TEE?

GPU TEE (Trusted Execution Environment) provides hardware-level isolation for your entire AI workload—from CPU to GPU. Unlike traditional cloud computing where your data is exposed to the host system, GPU TEE creates a secure enclave that not even the cloud provider can access.

Phala Cloud is the only platform combining Intel TDX (CPU/memory protection) with NVIDIA Confidential Computing (GPU encryption) for complete Full-Stack TEE protection. This dual-layer security enables private AI training, ZK proof generation, and cryptographic operations with cryptographic verification through dual attestation reports.

Full VM Isolation
Intel TDX creates a Trust Domain that isolates your entire VM from the host OS and hypervisor. Not even the cloud provider can access your data.
GPU Memory Encryption
NVIDIA Confidential Computing encrypts all data in GPU memory. Model weights, training data, and inference results stay encrypted during computation.
Dual Remote Attestation
Get cryptographic proof from both Intel and NVIDIA that your workload runs in genuine TEE hardware. Verify independently with our open-source tools.
End-to-End Encryption
Data encrypted in transit (TLS), at rest (AES-256), and during processing (TEE). Network traffic stays within the TEE boundary.
Global Availability
Deploy in US-West and India regions. More locations coming soon. All regions offer the same Full-Stack TEE protection.
Compliance Ready
Hardware-backed security meets GDPR, HIPAA, and SOC 2 requirements. Audit-ready with attestation logs and compliance reports.

REAL-WORLD PERFORMANCE

Hardware Security Without Compromise

Full-Stack TEE protection delivers near-native performance. Benchmarked with SP1 zkVM generating ZK proofs in GPU TEE environment.

Full-Stack TEE Advantage

vs GPU-Only Protection

Phala Cloud
GPU-Only TEE

Performance Benchmarks

TEE Overhead

<5%

Near-native performance with complete hardware protection

H200 vs H100

2x Faster

Up to 2x faster LLM inference with 141GB HBM3e memory

SP1 zkVM in TEE

4-5% Overhead

Verified benchmark generating ZK proofs in GPU TEE

Security Guarantees

Full VM Isolation

Intel TDX Trust Domain isolates entire VM from host

GPU Encryption

NVIDIA CC encrypts all GPU memory during computation

Dual Attestation

Cryptographic proof from Intel + NVIDIA verifying TEE

Compliance Ready

Meets GDPR, HIPAA, SOC 2 with attestation logs

NVIDIA H200
Flagship Performance

The most powerful AI GPU with complete TEE protection:

  • 141GB HBM3e Memory
  • 4.8 TB/s Bandwidth
  • 2x faster vs H100
  • Intel TDX + NVIDIA CC

Scale 1-8 GPUs. Deploy instantly or save 27% with reserved pricing.

On-demand from $3.50/GPU/hr or reserved from $2.56/GPU/hr with 6-month commitment.

Learn More About H200
H200 GPU

NVIDIA H100
Enterprise Standard

Battle-tested GPU for enterprise AI workloads:

  • 80GB HBM3 Memory
  • 3 TB/s Bandwidth
  • 9x faster vs A100
  • Intel TDX + NVIDIA CC

Full-stack TEE protection. Perfect for training on private data.

On-demand from $3.08/GPU/hr or reserved from $2.50/GPU/hr with volume discounts.

Learn More About H100
H100 GPU

NVIDIA B200
Available Now

Next-generation Blackwell architecture with revolutionary performance:

  • 192GB HBM3e Memory
  • 8 TB/s Bandwidth
  • 15x faster inference vs H100
  • Intel TDX + NVIDIA CC

Scale 1-8 GPUs. Deploy instantly or save 29% with reserved pricing.

On-demand from $7.99/GPU/hr or reserved from $5.63/GPU/hr with 6-month commitment.

Learn More About B200
B200 GPU
FAQ

Common Questions & Answers

Everything you need to know about GPU TEE

1

What makes Phala Cloud different from other GPU cloud providers?

Phala Cloud is the only provider offering Full-Stack TEE: Intel TDX for CPU/memory protection + NVIDIA Confidential Computing for GPU protection. Most providers offer GPU-only security or no TEE at all, leaving your data exposed to the host system.

2

What is dual attestation?

Dual attestation means you get cryptographic proof from both Intel (for TDX) and NVIDIA (for Confidential Computing) that your workload runs in genuine TEE hardware. You can verify these attestation reports independently with our open-source tools.

3

What's the performance overhead of TEE?

Our benchmarks show <5% overhead for most workloads. For example, SP1 zkVM running in GPU TEE shows only 4-5% performance impact compared to non-TEE environments, while providing complete hardware protection.

4

Can I train AI models on private data?

Yes! Full-Stack TEE protection means your training data, model weights, and inference results are all protected by hardware encryption. Perfect for healthcare, financial, and legal AI applications where data privacy is critical.

5

How do I deploy my own models?

Three options: (1) Deploy CVM + GPU for full control with SSH access, (2) Use our Confidential AI Models for one-click deployment, or (3) Contact us for Enterprise Solutions with dedicated clusters and custom SLAs.

6

What about ZK proof generation and FHE workloads?

GPU TEE is optimized for cryptographic operations. We support SP1 zkVM, zkRollups, FHE acceleration, and MPC systems. Our customers include projects like Fairblock, Mind Network, and various zkRollup providers.

7

Which GPUs are available?

Currently: H200 (141GB HBM3e), H100 (80GB HBM3). Coming soon: B200 (192GB HBM3e). All GPUs include Intel TDX + NVIDIA Confidential Computing protection. Scale from 1 to 8 GPUs per instance.

8

What's the pricing?

On-demand: H200 from $3.50/GPU/hr, H100 from $3.08/GPU/hr. Reserved (3+ months): H200 from $2.30/GPU/hr (34% savings), H100 from $2.50/GPU/hr (30% savings). Volume discounts available for enterprise.

9

How do I verify attestation?

Use our attestation API or open-source verification tools. You'll receive attestation reports from both Intel and NVIDIA that you can verify independently. We also provide a public PCCS server at https://pccs.phala.network for quote verification.