O-0141

Tinfoil

A company offering AI inference inside secure hardware enclaves, with remote attestation that clients can check; developer of the Modelwrap model-identity tool.

Source reviewed 2026-09-25Provider-reported evidence

01 / The mechanism and its boundary

What is being described

Tinfoil says it runs AI models inside secure hardware enclaves S-3605. Its documentation and code describe how a client checks what runs in the enclave:

  • Tinfoil developed Modelwrap, which it reports binds model weights to enclave attestation S-0013. The open-source tool commits the weights to a dm-verity root hash S-1209. See Tinfoil model identity (Modelwrap) and Model identity attestation.
  • Tinfoil documents a measured boot chain, reproducible builds, publication of expected measurements through Sigstore, and verification by the client S-1207, with checks at connection time and transparency logs S-1208; see TEE remote attestation for AI workloads.
  • Its documentation lists AMD SEV-SNP and Intel TDX confidential virtual machines, and NVIDIA GPUs in confidential-computing mode, as supported hardware S-1206. The same page documents limitations, including physical attacks, side channels, I/O leakage, denial of service, supply-chain risks and rollback S-1206.
  • Pour Demain reports running interpretability evaluations of GLM-5.1, an open-weights model of 744 billion parameters, on Tinfoil Containers with Intel TDX and eight NVIDIA H200 GPUs S-3361. Tinfoil describes the setup as one in which the lab supplies the model, the auditor supplies the evaluation code, and the weights stay inside the enclave S-3360. See Confidential multi-party verification.
  • Tinfoil reports running safeguard models inside its enclaves that output only a flag, and says the pipeline code is public and its enforcement "verifiable through attestation" S-3362; see Safeguard attestation.

Organization website ↗

Connections in the research map

Related research

Sources and provenance

  1. S-3605 / Tier B

    Tinfoil homepage ↗

    · 2026 · Tinfoil

    Supports: AI models running inside secure hardware enclaves

    Version and catalogue details
  2. S-0013 / Tier C

    How Tinfoil Proves Exactly What Model Is Running ↗

    Tinfoil Team · 2026 · Tinfoil

    Supports: Modelwrap binds model weights to enclave attestation (provider-reported)

    Version and catalogue details
  3. S-1209 / Tier B

    modelwrap: Reproducible dm-verity read-only image of Huggingface models ↗

    Tinfoil · 2026 · GitHub

    Supports: Modelwrap code: dm-verity commitment to model weights

    Version and catalogue details
  4. S-1207 / Tier B

    Backend infrastructure ↗

    Tinfoil · 2026 · Tinfoil documentation

    Supports: measured boot, reproducible builds, Sigstore measurements, client verification

    Version and catalogue details
  5. S-1208 / Tier B

    How verification works in Tinfoil ↗

    Tinfoil · 2026 · Tinfoil documentation

    Supports: connection-time verification and transparency logs

    Version and catalogue details
  6. S-1206 / Tier B

    A primer on secure enclaves ↗

    Tinfoil · 2026 · Tinfoil documentation

    Supports: supported hardware (AMD SEV-SNP, Intel TDX, NVIDIA confidential-computing mode) and documented limitations

    Version and catalogue details
  7. S-3361 / Tier C

    Confidential computing can enable better frontier AI auditing ↗

    A. Tlaie Boria · 2026 · Pour Demain

    Supports: Pour Demain's interpretability evaluations of GLM-5.1 on Tinfoil Containers (Intel TDX, eight H200 GPUs)

    Version and catalogue details
  8. S-3360 / Tier C

    Auditing a Frontier Model Without Seeing its Weights ↗

    D. McCann-Sayles, T. Verma · 2026 · Tinfoil blog

    Supports: the lab supplies the model and the auditor the code; weights stay in the enclave (provider-reported)

    Version and catalogue details
  9. S-3362 / Tier C

    Safety Without Compromising on Privacy ↗

    D. McCann-Sayles, S. Servan-Schreiber, T. Verma · 2026 · Tinfoil blog

    Supports: safeguard models run inside enclaves; pipeline code public and attested (provider-reported)

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review