{
  "schema_version": "1.2.0",
  "rubric_version": "1.1",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "O-0141",
    "slug": "tinfoil",
    "title": "Tinfoil",
    "aliases": [],
    "status": "published",
    "last_reviewed": "2026-09-25",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": [
        "codex-review"
      ]
    },
    "risk_flags": [],
    "flags": [
      "provider-reported"
    ],
    "kind": "company",
    "homepage": "https://tinfoil.sh/",
    "one_liner": "A company offering AI inference inside secure hardware enclaves, with remote attestation that clients can check; developer of the Modelwrap model-identity tool.",
    "sources": [
      {
        "source": "S-3605",
        "supports": "AI models running inside secure hardware enclaves"
      },
      {
        "source": "S-0013",
        "supports": "Modelwrap binds model weights to enclave attestation (provider-reported)"
      },
      {
        "source": "S-1209",
        "supports": "Modelwrap code: dm-verity commitment to model weights"
      },
      {
        "source": "S-1207",
        "supports": "measured boot, reproducible builds, Sigstore measurements, client verification"
      },
      {
        "source": "S-1208",
        "supports": "connection-time verification and transparency logs"
      },
      {
        "source": "S-1206",
        "supports": "supported hardware (AMD SEV-SNP, Intel TDX, NVIDIA confidential-computing mode) and documented limitations"
      },
      {
        "source": "S-3361",
        "supports": "Pour Demain's interpretability evaluations of GLM-5.1 on Tinfoil Containers (Intel TDX, eight H200 GPUs)"
      },
      {
        "source": "S-3360",
        "supports": "the lab supplies the model and the auditor the code; weights stay in the enclave (provider-reported)"
      },
      {
        "source": "S-3362",
        "supports": "safeguard models run inside enclaves; pipeline code public and attested (provider-reported)"
      }
    ],
    "type": "organization",
    "url": "https://trustbutveri.fyi/organizations/tinfoil/",
    "source_file": "content/organizations/tinfoil.md",
    "flags_all": [
      "provider-reported"
    ],
    "body_markdown": "Tinfoil says it runs AI models inside secure hardware enclaves [[S-3605]]. Its documentation and code describe how a client checks what runs in the enclave:\n\n- Tinfoil developed Modelwrap, which it reports binds model weights to enclave attestation [[S-0013]]. The open-source tool commits the weights to a dm-verity root hash [[S-1209]]. See [[I-0006]] and [[M-0012]].\n- Tinfoil documents a measured boot chain, reproducible builds, publication of expected measurements through Sigstore, and verification by the client [[S-1207]], with checks at connection time and transparency logs [[S-1208]]; see [[M-0008]].\n- Its documentation lists AMD SEV-SNP and Intel TDX confidential virtual machines, and NVIDIA GPUs in confidential-computing mode, as supported hardware [[S-1206]]. The same page documents limitations, including physical attacks, side channels, I/O leakage, denial of service, supply-chain risks and rollback [[S-1206]].\n- Pour Demain reports running interpretability evaluations of GLM-5.1, an open-weights model of 744 billion parameters, on Tinfoil Containers with Intel TDX and eight NVIDIA H200 GPUs [[S-3361]]. Tinfoil describes the setup as one in which the lab supplies the model, the auditor supplies the evaluation code, and the weights stay inside the enclave [[S-3360]]. See [[M-0025]].\n- Tinfoil reports running safeguard models inside its enclaves that output only a flag, and says the pipeline code is public and its enforcement \"verifiable through attestation\" [[S-3362]]; see [[M-0023]].",
    "body_text": "Tinfoil says it runs AI models inside secure hardware enclaves [S-3605]. Its documentation and code describe how a client checks what runs in the enclave: - Tinfoil developed Modelwrap, which it reports binds model weights to enclave attestation [S-0013]. The open-source tool commits the weights to a dm-verity root hash [S-1209]. See Tinfoil model identity (Modelwrap) and Model identity attestation. - Tinfoil documents a measured boot chain, reproducible builds, publication of expected measurements through Sigstore, and verification by the client [S-1207], with checks at connection time and transparency logs [S-1208]; see TEE remote attestation for AI workloads. - Its documentation lists AMD SEV-SNP and Intel TDX confidential virtual machines, and NVIDIA GPUs in confidential-computing mode, as supported hardware [S-1206]. The same page documents limitations, including physical attacks, side channels, I/O leakage, denial of service, supply-chain risks and rollback [S-1206]. - Pour Demain reports running interpretability evaluations of GLM-5.1, an open-weights model of 744 billion parameters, on Tinfoil Containers with Intel TDX and eight NVIDIA H200 GPUs [S-3361]. Tinfoil describes the setup as one in which the lab supplies the model, the auditor supplies the evaluation code, and the weights stay inside the enclave [S-3360]. See Confidential multi-party verification. - Tinfoil reports running safeguard models inside its enclaves that output only a flag, and says the pipeline code is public and its enforcement \"verifiable through attestation\" [S-3362]; see Safeguard attestation.",
    "referenced_by": [
      {
        "id": "M-0025",
        "title": "Confidential multi-party verification",
        "url": "https://trustbutveri.fyi/mechanisms/confidential-multi-party-verification/"
      },
      {
        "id": "M-0012",
        "title": "Model identity attestation",
        "url": "https://trustbutveri.fyi/mechanisms/model-identity-attestation/"
      },
      {
        "id": "M-0023",
        "title": "Safeguard attestation",
        "url": "https://trustbutveri.fyi/mechanisms/safeguard-attestation/"
      },
      {
        "id": "M-0008",
        "title": "TEE remote attestation for AI workloads",
        "url": "https://trustbutveri.fyi/mechanisms/tee-remote-attestation/"
      },
      {
        "id": "I-0006",
        "title": "Tinfoil model identity (Modelwrap)",
        "url": "https://trustbutveri.fyi/implementations/tinfoil-model-identity/"
      },
      {
        "id": "S-3360",
        "title": "Auditing a Frontier Model Without Seeing its Weights",
        "url": "https://trustbutveri.fyi/sources/tinfoil-auditing-frontier-model-without-weights/"
      },
      {
        "id": "S-1207",
        "title": "Backend infrastructure",
        "url": "https://trustbutveri.fyi/sources/tinfoil-docs-attestation-architecture/"
      },
      {
        "id": "S-1206",
        "title": "A primer on secure enclaves",
        "url": "https://trustbutveri.fyi/sources/tinfoil-docs-secure-enclave-primer/"
      },
      {
        "id": "S-1208",
        "title": "How verification works in Tinfoil",
        "url": "https://trustbutveri.fyi/sources/tinfoil-docs-verification-in-tinfoil/"
      },
      {
        "id": "S-3605",
        "title": "Tinfoil homepage",
        "url": "https://trustbutveri.fyi/sources/tinfoil-homepage/"
      },
      {
        "id": "S-1209",
        "title": "modelwrap: Reproducible dm-verity read-only image of Huggingface models",
        "url": "https://trustbutveri.fyi/sources/tinfoil-modelwrap-code/"
      },
      {
        "id": "S-0013",
        "title": "How Tinfoil Proves Exactly What Model Is Running",
        "url": "https://trustbutveri.fyi/sources/tinfoil-proving-model-identity/"
      },
      {
        "id": "S-3362",
        "title": "Safety Without Compromising on Privacy",
        "url": "https://trustbutveri.fyi/sources/tinfoil-safety-without-compromising-privacy/"
      }
    ]
  }
}