Tinfoil

A company offering AI inference inside secure hardware enclaves, with remote attestation that clients can check; developer of the Modelwrap model-identity tool.

tinfoil.sh

Tinfoil says it runs AI models inside secure hardware enclaves 1. Its documentation and code describe how a client checks what runs in the enclave:

  • Tinfoil developed Modelwrap, which it reports binds model weights to enclave attestation 2. The open-source tool commits the weights to a dm-verity root hash 3. See Tinfoil model identity (Modelwrap) and Model identity attestation.
  • Tinfoil documents a measured boot chain, reproducible builds, publication of expected measurements through Sigstore, and verification by the client 4, with checks at connection time and transparency logs 5; see TEE remote attestation for AI workloads.
  • Its documentation lists AMD SEV-SNP and Intel TDX confidential virtual machines, and NVIDIA GPUs in confidential-computing mode, as supported hardware 6. The same page documents limitations, including physical attacks, side channels, I/O leakage, denial of service, supply-chain risks and rollback 6.
  • Pour Demain reports running interpretability evaluations of GLM-5.1, an open-weights model of 744 billion parameters, on Tinfoil Containers with Intel TDX and eight NVIDIA H200 GPUs 7. Tinfoil describes the setup as one in which the lab supplies the model, the auditor supplies the evaluation code, and the weights stay inside the enclave 8. See Confidential multi-party verification.
  • Tinfoil reports running safeguard models inside its enclaves that output only a flag, and says the pipeline code is public and its enforcement "verifiable through attestation" 9; see Safeguard attestation.
On this page

Implementations

Implementations this organization develops.

Mechanisms and implementations whose records cite or describe this organization's work.

Publications

Sources this organization authored or published.

Sources

  1. BTinfoil homepage. Tinfoil. Source recordSupports: AI models running inside secure hardware enclaves
  2. CTinfoil Team (2026). How Tinfoil Proves Exactly What Model Is Running. Tinfoil. Source recordSupports: Modelwrap binds model weights to enclave attestation (provider-reported)
  3. BTinfoil (2026). modelwrap: Reproducible dm-verity read-only image of Huggingface models. GitHub. Source recordSupports: Modelwrap code: dm-verity commitment to model weights
  4. BTinfoil (2026). Backend infrastructure. Tinfoil documentation. Source recordSupports: measured boot, reproducible builds, Sigstore measurements, client verification
  5. BTinfoil (2026). How verification works in Tinfoil. Tinfoil documentation. Source recordSupports: connection-time verification and transparency logs
  6. BTinfoil (2026). A primer on secure enclaves. Tinfoil documentation. Source recordSupports: supported hardware (AMD SEV-SNP, Intel TDX, NVIDIA confidential-computing mode) and documented limitations
  7. CA. Tlaie Boria (2026). Confidential computing can enable better frontier AI auditing. Pour Demain. Source recordSupports: Pour Demain's interpretability evaluations of GLM-5.1 on Tinfoil Containers (Intel TDX, eight H200 GPUs)
  8. CD. McCann-Sayles & T. Verma (2026). Auditing a Frontier Model Without Seeing its Weights. Tinfoil blog. Source recordSupports: the lab supplies the model and the auditor the code; weights stay in the enclave (provider-reported)
  9. CD. McCann-Sayles et al. (2026). Safety Without Compromising on Privacy. Tinfoil blog. Source recordSupports: safeguard models run inside enclaves; pipeline code public and attested (provider-reported)

Search

Full search page