{
  "schema_version": "1.2.0",
  "rubric_version": "1.1",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "O-0140",
    "slug": "nvidia",
    "title": "NVIDIA",
    "aliases": [],
    "status": "published",
    "last_reviewed": "2026-09-25",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": [
        "codex-review"
      ]
    },
    "risk_flags": [],
    "flags": [
      "provider-reported"
    ],
    "kind": "company",
    "homepage": "https://www.nvidia.com/",
    "one_liner": "An accelerated-computing company whose Hopper and Blackwell data-centre GPUs offer a confidential-computing mode with hardware attestation.",
    "sources": [
      {
        "source": "S-3604",
        "supports": "self-description as pioneer of accelerated computing"
      },
      {
        "source": "S-1200",
        "supports": "confidential computing on Hopper and Blackwell GPUs; performance counters disabled in confidential-computing mode",
        "locator": "pp. 6-18"
      },
      {
        "source": "S-1201",
        "supports": "H100 confidential-computing launch: on-die root of trust, device identity key, SPDM attestation"
      },
      {
        "source": "S-1206",
        "supports": "NVIDIA GPUs in confidential-computing mode listed as supported hardware by Tinfoil"
      },
      {
        "source": "S-1413",
        "supports": "opt-in, customer-installed fleet-management service with read-only telemetry; statement on tracking, kill switches and backdoors (provider-reported)"
      },
      {
        "source": "S-3180",
        "supports": "Fleet Intelligence: open-source read-only agent, telemetry and attestation on Blackwell and Vera Rubin (provider-reported)"
      },
      {
        "source": "S-1402",
        "supports": "NVIDIA reportedly developing delay-based location verification with NVIDIA-run servers (citing Reuters)"
      }
    ],
    "type": "organization",
    "url": "https://trustbutveri.fyi/organizations/nvidia/",
    "source_file": "content/organizations/nvidia.md",
    "flags_all": [
      "provider-reported"
    ],
    "body_markdown": "NVIDIA describes itself as having \"pioneered accelerated computing\" [[S-3604]]. Its public material relevant to verification concerns its data-centre GPUs:\n\n- **Confidential-computing mode.** NVIDIA documents a confidential-computing mode for its Hopper and Blackwell data-centre GPUs, in which the GPU is paired with a CPU trusted execution environment and attests its identity and firmware [[S-1200]]; see [[M-0008]].\n- **H100 launch.** NVIDIA engineers describe the feature's launch on the H100, with an on-die root of trust, a fused device identity key and SPDM attestation [[S-1201]].\n- **Counters in confidential mode.** NVIDIA disables performance counters in full confidential-computing mode, stating that they could provide an avenue for side-channel attacks [[S-1200]]; see [[M-0010]].\n- **Fleet telemetry.** NVIDIA reports an opt-in, customer-installed fleet-management service that provides read-only GPU telemetry [[S-1413]]. Its Fleet Intelligence service uses a read-only, open-source agent that sends GPU power, performance, health and configuration data to an NVIDIA cloud service [[S-3180]]. The service supports attestation only on Blackwell and Vera Rubin GPUs [[S-3180]]. NVIDIA states that its GPUs \"do not have hardware tracking technology, kill switches and backdoors\" [[S-1413]]. See [[M-0010]].\n- **Location verification.** Avellar and Grunewald report, citing Reuters, that NVIDIA has confirmed it is developing location verification that estimates a chip's location from communication delays with NVIDIA-run servers [[S-1402]]; see [[M-0018]].\n- **Use by others.** Tinfoil's documentation lists NVIDIA GPUs in confidential-computing mode as supported hardware for its enclaves [[S-1206]]; see [[I-0006]].",
    "body_text": "NVIDIA describes itself as having \"pioneered accelerated computing\" [S-3604]. Its public material relevant to verification concerns its data-centre GPUs: - Confidential-computing mode. NVIDIA documents a confidential-computing mode for its Hopper and Blackwell data-centre GPUs, in which the GPU is paired with a CPU trusted execution environment and attests its identity and firmware [S-1200]; see TEE remote attestation for AI workloads. - H100 launch. NVIDIA engineers describe the feature's launch on the H100, with an on-die root of trust, a fused device identity key and SPDM attestation [S-1201]. - Counters in confidential mode. NVIDIA disables performance counters in full confidential-computing mode, stating that they could provide an avenue for side-channel attacks [S-1200]; see On-chip telemetry from timing, memory and performance counters. - Fleet telemetry. NVIDIA reports an opt-in, customer-installed fleet-management service that provides read-only GPU telemetry [S-1413]. Its Fleet Intelligence service uses a read-only, open-source agent that sends GPU power, performance, health and configuration data to an NVIDIA cloud service [S-3180]. The service supports attestation only on Blackwell and Vera Rubin GPUs [S-3180]. NVIDIA states that its GPUs \"do not have hardware tracking technology, kill switches and backdoors\" [S-1413]. See On-chip telemetry from timing, memory and performance counters. - Location verification. Avellar and Grunewald report, citing Reuters, that NVIDIA has confirmed it is developing location verification that estimates a chip's location from communication delays with NVIDIA-run servers [S-1402]; see Chip location verification. - Use by others. Tinfoil's documentation lists NVIDIA GPUs in confidential-computing mode as supported hardware for its enclaves [S-1206]; see Tinfoil model identity (Modelwrap).",
    "referenced_by": [
      {
        "id": "M-0018",
        "title": "Chip location verification",
        "url": "https://trustbutveri.fyi/mechanisms/chip-location-verification/"
      },
      {
        "id": "M-0008",
        "title": "TEE remote attestation for AI workloads",
        "url": "https://trustbutveri.fyi/mechanisms/tee-remote-attestation/"
      },
      {
        "id": "S-1201",
        "title": "Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AI",
        "url": "https://trustbutveri.fyi/sources/apsey-confidential-computing-h100-gpus/"
      },
      {
        "id": "S-1611",
        "title": "Boost GPU Memory Performance with No Code Changes Using NVIDIA CUDA MPS",
        "url": "https://trustbutveri.fyi/sources/nassernia-cuda-mps-gpu-memory-performance/"
      },
      {
        "id": "S-3604",
        "title": "About NVIDIA",
        "url": "https://trustbutveri.fyi/sources/nvidia-about/"
      },
      {
        "id": "S-1815",
        "title": "Now in General Availability: NVIDIA H100 GPUs in Microsoft Azure Confidential Virtual Machines",
        "url": "https://trustbutveri.fyi/sources/nvidia-azure-confidential-h100-ga/"
      },
      {
        "id": "S-3180",
        "title": "Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization",
        "url": "https://trustbutveri.fyi/sources/nvidia-fleet-intelligence-technical-blog/"
      },
      {
        "id": "S-1413",
        "title": "Opt-In NVIDIA Software Enables Data Center Fleet Management",
        "url": "https://trustbutveri.fyi/sources/nvidia-opt-in-fleet-management-software/"
      },
      {
        "id": "S-1200",
        "title": "NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper)",
        "url": "https://trustbutveri.fyi/sources/nvidia-secure-ai-blackwell-hopper-whitepaper/"
      },
      {
        "id": "S-3122",
        "title": "NVIDIA Trusted Computing Solutions Release Notes (R595 TRD1)",
        "url": "https://trustbutveri.fyi/sources/nvidia-trusted-computing-r595-release-notes/"
      },
      {
        "id": "S-3162",
        "title": "No Backdoors. No Kill Switches. No Spyware.",
        "url": "https://trustbutveri.fyi/sources/reber-no-backdoors-no-kill-switches/"
      }
    ]
  }
}