Tinfoil
A company offering AI inference inside secure hardware enclaves, with remote attestation that clients can check; developer of the Modelwrap model-identity tool.
Tinfoil says it runs AI models inside secure hardware enclaves 1. Its documentation and code describe how a client checks what runs in the enclave:
- Tinfoil developed Modelwrap, which it reports binds model weights to enclave attestation 2. The open-source tool commits the weights to a dm-verity root hash 3. See Tinfoil model identity (Modelwrap) and Model identity attestation.
- Tinfoil documents a measured boot chain, reproducible builds, publication of expected measurements through Sigstore, and verification by the client 4, with checks at connection time and transparency logs 5; see TEE remote attestation for AI workloads.
- Its documentation lists AMD SEV-SNP and Intel TDX confidential virtual machines, and NVIDIA GPUs in confidential-computing mode, as supported hardware 6. The same page documents limitations, including physical attacks, side channels, I/O leakage, denial of service, supply-chain risks and rollback 6.
- Pour Demain reports running interpretability evaluations of GLM-5.1, an open-weights model of 744 billion parameters, on Tinfoil Containers with Intel TDX and eight NVIDIA H200 GPUs 7. Tinfoil describes the setup as one in which the lab supplies the model, the auditor supplies the evaluation code, and the weights stay inside the enclave 8. See Confidential multi-party verification.
- Tinfoil reports running safeguard models inside its enclaves that output only a flag, and says the pipeline code is public and its enforcement "verifiable through attestation" 9; see Safeguard attestation.
On this page
Implementations
Implementations this organization develops.
- Tinfoil's method for proving which model weights its enclave-hosted inference service runs, by binding a dm-verity hash of the weights into remote attestation.
Related records
Mechanisms and implementations whose records cite or describe this organization's work.
- Establishes that responses come from a specific, committed set of model weights, using enclave measurements or recomputation of sampled outputs.
- Trusted execution environments (TEEs) in CPUs and GPUs sign reports of loaded software, so a remote party can check which code ran an AI workload.
- Lets mutually distrusting parties run an agreed check over private models or records inside attested enclaves or zero-knowledge proofs, revealing only the result.
- Hardware-signed evidence that an AI service ran its declared safeguards, such as a guardrail classifier or monitor, when producing a given response.
Publications
Sources this organization authored or published.
- BTinfoil (2026). A primer on secure enclaves. Tinfoil documentation. Source recordCited by Model identity attestation; TEE remote attestation for AI workloads; Tinfoil model identity (Modelwrap); NVIDIA; Tinfoil
- CD. McCann-Sayles & T. Verma (2026). Auditing a Frontier Model Without Seeing its Weights. Tinfoil blog. Source recordCited by Tinfoil
- BTinfoil (2026). Backend infrastructure. Tinfoil documentation. Source recordCited by Model identity attestation; TEE remote attestation for AI workloads; Tinfoil model identity (Modelwrap); Tinfoil
- CTinfoil Team (2026). How Tinfoil Proves Exactly What Model Is Running. Tinfoil. Source recordCited by Model identity attestation; Safeguard attestation; TEE remote attestation for AI workloads; Tinfoil model identity (Modelwrap); The declared model is the one being served; Tinfoil
- BTinfoil (2026). How verification works in Tinfoil. Tinfoil documentation. Source recordCited by Model identity attestation; TEE remote attestation for AI workloads; Tinfoil model identity (Modelwrap); The declared model is the one being served; Tinfoil
- BTinfoil (2026). modelwrap: Reproducible dm-verity read-only image of Huggingface models. GitHub. Source recordCited by Model identity attestation; TEE remote attestation for AI workloads; Tinfoil model identity (Modelwrap); Tinfoil
- CD. McCann-Sayles et al. (2026). Safety Without Compromising on Privacy. Tinfoil blog. Source recordCited by Safeguard attestation; Tinfoil
- BTinfoil homepage. Tinfoil. Source recordCited by Tinfoil
Sources
- BTinfoil homepage. Tinfoil. Source recordSupports: AI models running inside secure hardware enclaves
- CTinfoil Team (2026). How Tinfoil Proves Exactly What Model Is Running. Tinfoil. Source recordSupports: Modelwrap binds model weights to enclave attestation (provider-reported)
- BTinfoil (2026). modelwrap: Reproducible dm-verity read-only image of Huggingface models. GitHub. Source recordSupports: Modelwrap code: dm-verity commitment to model weights
- BTinfoil (2026). Backend infrastructure. Tinfoil documentation. Source recordSupports: measured boot, reproducible builds, Sigstore measurements, client verification
- BTinfoil (2026). How verification works in Tinfoil. Tinfoil documentation. Source recordSupports: connection-time verification and transparency logs
- BTinfoil (2026). A primer on secure enclaves. Tinfoil documentation. Source recordSupports: supported hardware (AMD SEV-SNP, Intel TDX, NVIDIA confidential-computing mode) and documented limitations
- CA. Tlaie Boria (2026). Confidential computing can enable better frontier AI auditing. Pour Demain. Source recordSupports: Pour Demain's interpretability evaluations of GLM-5.1 on Tinfoil Containers (Intel TDX, eight H200 GPUs)
- CD. McCann-Sayles & T. Verma (2026). Auditing a Frontier Model Without Seeing its Weights. Tinfoil blog. Source recordSupports: the lab supplies the model and the auditor the code; weights stay in the enclave (provider-reported)
- CD. McCann-Sayles et al. (2026). Safety Without Compromising on Privacy. Tinfoil blog. Source recordSupports: safeguard models run inside enclaves; pipeline code public and attested (provider-reported)