Run AI on your most sensitive data without trusting anyone with it
Garnet is a Confidential AI platform: the entire AI stack — orchestration, execution, acceleration — runs inside hardware-sealed environments with keys you control. Run local models fully confidential, or use OpenAI, Anthropic, Google Gemini and LLaMA-based services through PrivacyMode, which pseudonymizes sensitive data before it ever leaves your trust boundary.
Buying by problem rather than product? Start at Confidential AI. Available from a single laptop to a fully managed service.
AI can't access the data that matters most
The most valuable enterprise data is the most protected — and that is exactly where AI is blocked, because it must process data in clear form on infrastructure others operate.
Garnet closes that trust gap. The whole AI stack runs inside a confidential environment with hardware-backed isolation and attestation, keys under your control. Models, prompts and outputs are never in plaintext to operators.
Choose per use case — maximum sovereignty with local models, or state-of-the-art external models without exposing raw data. Both run under the same architecture, policy and audit trail.
Open-source and custom models run entirely inside Garnet's confidential environment — inference on confidential GPUs, orchestration in confidential Kubernetes, data never leaving your boundary.
Use OpenAI, Anthropic, Google Gemini or LLaMA-based services. Before any prompt or context leaves the trust boundary, PrivacyMode detects sensitive entities and replaces them with deterministic pseudonyms — Name_43590, Company_9034943. The provider sees structure, never substance.
Garnet unifies enclaive's confidential computing technologies into one AI platform — no isolated security silos, no fragmented trust architecture.
All AI workloads are orchestrated in a confidential Kubernetes environment — control plane and worker nodes inside trusted execution environments. Prompts, documents, model parameters and results stay protected throughout processing.
Confidential GPU support brings hardware acceleration inside the trust boundary — high-performance inference today, training workloads on the roadmap, without sacrificing confidentiality.
Encryption keys stay under your control and are released only to workloads that pass remote attestation — proving what software runs, on what hardware, unmodified, policy-compliant. Access is governed by cryptographic policy, not administrative privilege.
A privacy proxy inside the confidential environment analyzes prompts and context in real time, pseudonymizes sensitive entities deterministically, and reconstructs responses on return — raw confidential data never leaves the Garnet trust boundary.
Every deployment model runs the same privacy architecture — confidential execution, PrivacyMode, attestation, customer-controlled keys. Choose by how you want to operate, not by how much protection you get.
For consultants, healthcare practitioners, legal teams and executives: use external AI on confidential documents from a standard laptop — PrivacyMode pseudonymizes before anything leaves the device, and no GPU investment is needed.
Shared workspaces, organizational knowledge bases, notebooks and domain assistants under centralized governance — with local open-source models, external providers through PrivacyMode, or both, balanced per use case.
Deploy on confidential VMs and managed Kubernetes at AWS, Azure, Google Cloud or sovereign clouds — elastic scale, on-demand confidential GPUs, cloud economics with Garnet's attestation and key architecture on top.
enclaive operates the confidential infrastructure, updates and security monitoring; you keep control of data and policy. Token-based consumption — start small, scale fast, no upfront capital expenditure.
For deployments with confidential computing enabled, the infrastructure must support trusted execution environments. Sizing depends on models, document volumes and concurrency — these are the baselines.
SINGLE-USER LAPTOP DEPLOYMENTS USING EXTERNAL MODELS VIA PRIVACYMODE DON'T REQUIRE CONFIDENTIAL HARDWARE OR A GPU — THE HEAVY COMPUTATION RUNS AT THE MODEL PROVIDER, ON PSEUDONYMIZED DATA.
Workload starts
Code, config and platform state measured by the CPU
Evidence produced
Hardware-rooted attestation report, signed
Policy checked
Nitride verifies the measurement against your policy
Keys released
vHSM and vault unseal — only now, only to this workload
Workload starts
Tampered image, injected container or rogue host
Evidence produced
Measurement does not match what you approved
Policy rejects
Mismatch logged with its reason, for the audit file
Nothing released
No keys, no secrets — the data stays ciphertext
What evaluators ask
What does an external provider like OpenAI or Anthropic actually see?
Pseudonymized prompts and context: sensitive entities — names, company identifiers, locations, patient references — replaced with deterministic tokens before transmission. The provider processes structure and language, never the original values; the mapping lives inside your trust boundary and is never exposed. Responses are de-pseudonymized on return, so semantics are preserved for the user.
Does pseudonymization degrade answer quality?
The design goal is exposure minimization with utility preserved: deterministic pseudonyms keep referential consistency, so the model can reason about “Name_43590” as coherently as about the real name. For most support, drafting and document tasks the effect is negligible — and where a use case genuinely needs raw data, the fully confidential local mode exists so it never has to leave your boundary at all.
Which models can we run locally?
Open-source and LLaMA-family models run fully inside the confidential environment — on confidential GPUs for serious inference, or CPU-bound where workloads allow. On a single-user laptop, local model capacity is limited by the hardware; that's exactly the case PrivacyMode with external providers covers.
How much latency does PrivacyMode add?
Entity detection and pseudonymization run in the request path, so the honest answer is a measured one.
We already have DLP and a secure web gateway. Why isn't that enough?
Those tools classify files and destinations. AI risk lives in prompt-and-response flows: context assembled from retrieval, PII embedded mid-sentence, per-model policy, and the audit question of who asked what. Garnet inspects and enforces at that layer — and composes with your existing DLP rather than replacing it.
How does Garnet relate to eMCP and the rest of the platform?
Garnet is built on the same foundation as enclaive's confidential computing portfolio — Dyneemes containers, Buckypaper GPU VMs, vHSM keys and attestation — so adopting Confidential AI doesn't create a security silo. Organizations running eMCP operate Garnet within the same trust architecture and evidence model.
How do we buy it?
By deployment model: software subscription plus AI token consumption for single-user, infrastructure plus licensing for on-premises and cloud, and token-based consumption for the managed service. Bring your use case and preferred model strategy to the first call; pricing follows the deployment.
Bring the dataset AI isn't allowed to touch_
Patient records, transactions, contracts, citizen data — tell us what's blocked and which models you want. We'll show you Garnet running on your kind of data, in the deployment model that fits.
Want the problem-first view? Confidential AI covers the protection layers end to end.
.png)
