01 / The mechanism and its boundary
What is being described
Tinfoil says it runs AI models inside secure hardware enclaves S-3605. Its documentation and code describe how a client checks what runs in the enclave:
- Tinfoil developed Modelwrap, which it reports binds model weights to enclave attestation S-0013. The open-source tool commits the weights to a dm-verity root hash S-1209. See Tinfoil model identity (Modelwrap) and Model identity attestation.
- Tinfoil documents a measured boot chain, reproducible builds, publication of expected measurements through Sigstore, and verification by the client S-1207, with checks at connection time and transparency logs S-1208; see TEE remote attestation for AI workloads.
- Its documentation lists AMD SEV-SNP and Intel TDX confidential virtual machines, and NVIDIA GPUs in confidential-computing mode, as supported hardware S-1206. The same page documents limitations, including physical attacks, side channels, I/O leakage, denial of service, supply-chain risks and rollback S-1206.
- Pour Demain reports running interpretability evaluations of GLM-5.1, an open-weights model of 744 billion parameters, on Tinfoil Containers with Intel TDX and eight NVIDIA H200 GPUs S-3361. Tinfoil describes the setup as one in which the lab supplies the model, the auditor supplies the evaluation code, and the weights stay inside the enclave S-3360. See Confidential multi-party verification.
- Tinfoil reports running safeguard models inside its enclaves that output only a flag, and says the pipeline code is public and its enforcement "verifiable through attestation" S-3362; see Safeguard attestation.
Connections in the research map
Related research
Sources and provenance
- S-3605 / Tier B
Tinfoil homepage ↗
· 2026 · Tinfoil
Supports: AI models running inside secure hardware enclaves
Version and catalogue details - S-0013 / Tier C
How Tinfoil Proves Exactly What Model Is Running ↗
Tinfoil Team · 2026 · Tinfoil
Supports: Modelwrap binds model weights to enclave attestation (provider-reported)
Version and catalogue details - S-1209 / Tier B
modelwrap: Reproducible dm-verity read-only image of Huggingface models ↗
Tinfoil · 2026 · GitHub
Supports: Modelwrap code: dm-verity commitment to model weights
Version and catalogue details - S-1207 / Tier B
Backend infrastructure ↗
Tinfoil · 2026 · Tinfoil documentation
Supports: measured boot, reproducible builds, Sigstore measurements, client verification
Version and catalogue details - S-1208 / Tier B
How verification works in Tinfoil ↗
Tinfoil · 2026 · Tinfoil documentation
Supports: connection-time verification and transparency logs
Version and catalogue details - S-1206 / Tier B
A primer on secure enclaves ↗
Tinfoil · 2026 · Tinfoil documentation
Supports: supported hardware (AMD SEV-SNP, Intel TDX, NVIDIA confidential-computing mode) and documented limitations
Version and catalogue details - S-3361 / Tier C
Confidential computing can enable better frontier AI auditing ↗
A. Tlaie Boria · 2026 · Pour Demain
Supports: Pour Demain's interpretability evaluations of GLM-5.1 on Tinfoil Containers (Intel TDX, eight H200 GPUs)
Version and catalogue details - S-3360 / Tier C
Auditing a Frontier Model Without Seeing its Weights ↗
D. McCann-Sayles, T. Verma · 2026 · Tinfoil blog
Supports: the lab supplies the model and the auditor the code; weights stay in the enclave (provider-reported)
Version and catalogue details - S-3362 / Tier C
Safety Without Compromising on Privacy ↗
D. McCann-Sayles, S. Servan-Schreiber, T. Verma · 2026 · Tinfoil blog
Supports: safeguard models run inside enclaves; pipeline code public and attested (provider-reported)
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review