Confident Security

Security for AI PrivacyData Security

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2024
Last updated 2026-07-16

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Confident Security sells CONFSEC, a service that runs AI models on encrypted prompts so the provider and operator cannot read them, copying the approach Apple built for its own devices. The company is betting that privacy becomes a requirement for AI in healthcare, finance, and government before the cloud platforms and model providers build that privacy in themselves. To get there first, it published its core as an open standard, OpenPCC, an openly licensed specification with a source-available server, so others can adopt it rather than a rival's. Founder Jonathan Mortensen sold two prior companies, and backers include Decibel and Halcyon. But no customer is named yet, only talks with banks and browsers, so the next test is a named deployment a customer will stand behind.

Sourced Details

Description Confident Security offers CONFSEC, an inference API that runs AI models on encrypted prompts and outputs so the model provider and operator cannot read the data, built on its open-source OpenPCC standard. [f1]
Founded 2024 [f2]
HQ San Francisco, California, US [f2]
Latest funding Seed, $5M (2025) [f3]

Products

Product What it does
CONFSEC Verifiably-private inference API that keeps prompts, outputs, and logs encrypted and hardware-attested so the operator cannot read them, based on the OpenPCC standard.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

CONFSEC is a verifiably-private inference API that keeps prompts, outputs, and logs confidential through encryption and hardware attestation, routing requests through Oblivious HTTP so the operator cannot read them. These capabilities are mapped to the AI Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 24 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Confident Security names concrete buyer segments, especially regulated enterprises in healthcare, finance, and government blocked from AI because prompts and data sent to a model provider can be retained and read, and frames the pain as the verifiable guarantees a standard model API does not give. The pain is framed by the vendor and echoed in press coverage rather than quantified across independent studies, so it sits at the present default. [s2, s7, s1]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 OpenPCC ships as an open-source framework anyone can audit and deploy, and the architecture uses hardware attestation, Oblivious HTTP, and transparency logs modeled on Apple's Private Cloud Compute. Public, inspectable code is an external validation point most same-asset peers lack, but no published third-party audit report, named auditor, or wide adoption yet lifts it to the top rung. [s5, s2, s1]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is real and recent. Apple's Private Cloud Compute established verifiable private inference as a credible pattern, and confidential computing gives it a hardware basis, which is why a company founded in 2024 could build CONFSEC when it could not have years earlier. Buyer-side demand is still indirect, argued from the privacy-blocks-adoption thesis and analogy to Apple rather than budget-line or analyst-category signals, so it holds below the multi-signal bar. [s2, s1]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Founder and CEO Jonathan Mortensen is a two-time founder with prior exits to BlueVoyant and Databricks, reported independently, and the team draws from Google, Apple, Databricks, Red Hat, and HashiCorp with trusted-computing depth. Two prior exits clear the prior-builds bar above the same-asset cluster, short of a category-defining, widely recognized track record. [s3, s2]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 2/5 No named customer appears in the public record. The company is in talks with banks, browsers, and search engines but names none. Reputable backing from Decibel and Halcyon is the one indirect signal, which holds the score above pre-product but below a named-reference level. [s2, s3]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 A small seed, reported at $4.2 million at the July 2025 stealth launch and $5 million by the November OpenPCC release, is proportional to an early deep-tech infrastructure motion, and shipping is visible in the CONFSEC service and the OpenPCC open-source release. No revenue or margin confirms efficiency, the honest default for a funded startup. [s3, s4]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Verifiably-private AI inference is a forming category that rides confidential computing and the Apple Private Cloud Compute reference point, but a buyer still needs vendor explanation to place it against a budget line and to separate it from an AI gateway or a general data-privacy tool, so it stays nascent rather than established. [s1, s2]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Confident Security published OpenPCC as an open standard, so any well-funded provider can adopt it rather than rebuild it, and the model providers that already run inference could add non-retention guarantees themselves. That makes private inference a plausible near-term feature for an adjacent platform rather than a structural moat. [s5, s2]
Business Risks The cloud platforms and model providers that already run inference could extend confidential computing and zero-retention guarantees into their own offerings, matching CONFSEC's core promise inside products enterprises already buy…
  • The cloud platforms and model providers that already run inference could extend confidential computing and zero-retention guarantees into their own offerings, matching CONFSEC's core promise inside products enterprises already buy.
  • Because OpenPCC is published as an open standard, a well-funded rival or a hyperscaler could implement it independently and stand up a compliant service competing on the same guarantees.
  • The drop-in, OpenAI-compatible design and zero data retention leave little switching cost, so a customer that adopts CONFSEC could move to a cheaper private-inference option with minimal migration.
  • With no named customer on the record, CONFSEC's trust claims rest on the vendor's own guarantees and a founder-stated external audit, so a security review that finds those guarantees unproven could stall adoption.
  • The 2x-market-rate pricing could deter cost-sensitive buyers if a larger provider bundles comparable privacy at a smaller premium.
Problem & Market Confident Security treats the data a company sends to an AI model as the asset under attack…

Confident Security treats the data a company sends to an AI model as the asset under attack. It targets the regulated enterprise in healthcare, finance, or government that wants frontier models but cannot let prompts, documents, and metadata reach a provider that might retain, read, or train on them. Its pitch is to remove that trade-off so a buyer can use AI without giving up control of the data.

The compliance page frames the gap as the guarantees a standard model API does not give. Confident Security states that customer data are guaranteed never to train models, never to be shared with a third party, and never accessible unencrypted, which are the assurances a regulated buyer needs, and which Confident Security contrasts with trusting a standard provider endpoint's policy. The problem it sells against is that using AI today means trusting a provider's policy rather than a verifiable control.

What the record does not yet carry is independent quantification of the pain. The demand case depends on the vendor's framing and on press coverage that echoes it, not on analyst sizing, survey data, or a body of incident evidence, so the problem reads as clear and credible but not yet independently measured. [s7, s1, s2]

Product Capabilities CONFSEC is a verifiably-private inference API that runs AI models on encrypted data…

CONFSEC is a verifiably-private inference API that runs AI models on encrypted data. A developer swaps an existing OpenAI-compatible endpoint for CONFSEC, and the service keeps prompts, outputs, and logs confidential so the operator cannot read them. The company states that prompts are never logged, retained, used for training, or sent to third parties, and that requests route through Oblivious HTTP so operators cannot link individual calls.

The design follows Apple's Private Cloud Compute and is published openly. OpenPCC ships as a framework anyone can audit and deploy, using encrypted streaming, hardware attestation, and unlinkable requests, and the homepage invites buyers to verify exactly how the code works rather than trust a promise. That auditability is the technical differentiator, because a buyer can inspect the guarantee instead of taking it on faith.

The offer spans a hosted service and self-hosting. Confident Security runs CONFSEC as a managed service on the OpenPCC standard and publishes per-token pricing at roughly twice the market rate, with public sign-up and pricing pages, and because OpenPCC is deployable on a customer's own infrastructure, a team can adopt the hosted API or run private inference in its own environment. [s8, s5, s6]

Competitive Positioning Confident Security competes on the promise of provable privacy against several kinds of rival…

Confident Security competes on the promise of provable privacy against several kinds of rival. Confidential-computing vendors protect data in use with encryption, and data-privacy vendors strip or tokenize sensitive values before they reach a model. Confident Security differs by keeping the model's own inference private end to end rather than masking the data first.

The larger pressure comes from the platforms the company sits between. The model providers that run inference today already hold the data, and the cloud platforms that host models can add confidential computing, so the capability Confident Security sells is one the incumbents are positioned to offer themselves. Publishing OpenPCC as an open standard is the company's answer, an attempt to become the shared standard others adopt rather than a proprietary product a platform routes around.

The positioning bet is that neutrality wins. By giving the standard away and promising independent governance, the positioning reads as a bet that model providers and enterprises converge on OpenPCC, which would let Confident Security sell the managed service on top. That only holds if the standard spreads before a hyperscaler or a model provider ships an equivalent private-inference offering of its own. [s1, s5, s2]

Go-to-Market & Traction Confident Security has a shipping product and no named customer to point to…

Confident Security has a shipping product and no named customer to point to. CONFSEC is production-ready with published pricing, documentation, and an OpenAI-compatible API, but the public record names no buyer running it. TechCrunch reports the company is in talks with banks, browsers, and search engines to add CONFSEC to their infrastructure stacks, which are prospects rather than deployments.

The funding round is the strongest outside signal, and it is small. Confident Security came out of stealth in July 2025 with $4.2 million from Decibel, South Park Commons, Ex Ante, and Swyx, and by the November 2025 OpenPCC launch the seed was reported at $5 million with Halcyon and SAIF added. That backing signals investor conviction at the seed stage rather than verified commercial traction.

Distribution leans on the open standard and a self-serve product as much as direct selling. The company open-sourced OpenPCC and offers a self-serve API a developer can adopt without a sales call, a bottom-up motion that runs alongside its early enterprise conversations and has produced no paying reference customer in the public record. [s2, s3, s4]

Team & Credibility The founder is the clearest credibility signal…

The founder is the clearest credibility signal. Jonathan Mortensen is a two-time founder whose prior companies were acquired by BlueVoyant and Databricks, a pair of in-domain exits reported by independent press rather than asserted only on the company's own pages. That track record is the reason the team scores above the same-asset cluster.

The wider team carries relevant systems depth. The AI Journal reports backgrounds spanning Google, Apple, Databricks, Red Hat, and HashiCorp, with depth in trusted computing, secure systems, and large-scale infrastructure, which fits a product built on hardware attestation and confidential computing. The named strength is the founder's exits plus that collective pedigree.

What the record does not show is a sustained research or publication trail. The team's depth is in prior builds and employer pedigree rather than a body of peer-reviewed work or industry-standard authorship, so the credibility comes from exits and experience rather than a category-defining public reputation. [s3, s2]

Trust Readiness Confident Security stakes its trust case on verifiable guarantees rather than certifications…

Confident Security stakes its trust case on verifiable guarantees rather than certifications. The compliance page contrasts its guarantees with rivals' promises, stating that customer data are guaranteed never to train models, never to be shared with a third party, and never accessible unencrypted, and the homepage adds that the company takes financial responsibility for any breach or misuse. That liability stance is unusual and is the company's central trust argument.

The verification rests on open code and hardware attestation. Because OpenPCC is open-source and the software running inference is publicly logged and open to review, the company argues a buyer or an outside expert can confirm the guarantees rather than accept them, which is a stronger posture than a self-attested policy for a young vendor handling sensitive data.

What is absent from the public record is a named third-party attestation. The compliance page markets the ability to build SOC 2, HIPAA, PCI DSS, and GDPR compliant AI features, but a probe of it and the trust and security paths on 2026-07-03 found no SOC 2 report, ISO 27001 certificate, named auditor, or independent audit of Confident Security itself, and the founder's statement that CONFSEC was externally audited names no auditor and links no report. For a product whose entire value is trust, a security review would likely request the independent attestation the public record does not yet show. [s7, s1, s2]

Competitors Enveil, Duality Technologies, Skyflow, Amazon Web Services, OpenAI…
Company Relationship Note Compare
Enveil competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Duality Technologies competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Skyflow competes with
Amazon Web Services adjacent Hyperscaler positioned to extend confidential computing into private inference and bundle it with the models enterprises already run on its platform. N/AAmazon Web Services is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.
OpenAI adjacent Model provider that runs inference today and could offer stronger zero-retention and privacy guarantees directly, removing the third-party layer Confident Security sells. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with Confident Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Confident Security has built something hard and kept little that stops a copy. Running AI inference on encrypted data with hardware attestation and zero retention is specialized cryptographic and systems work, aimed at regulated buyers that could not safely put private data through AI. But Confident Security deliberately avoids lock-in: a drop-in endpoint a customer can swap, an openly published core anyone can run, and no retained data to reabsorb. Its promise to take financial responsibility for a breach could harden into a moat, but no audit report or on-the-record customer shows the guarantee holds. Until a regulated enterprise routes production traffic through CONFSEC and says so, the durable part is engineering a funded rival or a cloud platform can reproduce.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Confident Security sells an inference API the customer calls and runs, with published self-serve pricing, and the financial-responsibility promise transfers breach risk without changing what is delivered, since the customer still builds and operates its own AI use case on the API, so it holds at the software-product level.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Integrating the endpoint and validating the privacy guarantee create real friction, but the OpenAI-compatible drop-in design, the open standard, and zero data retention deliberately cap lock-in, so leaving stays cheaper than a network effect or residency lock.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The compliance page markets compliant-AI capability, but a probe on 2026-07-03 found no SOC 2 report, ISO 27001 certificate, or named audit of the company itself, and the financial-liability guarantee is self-asserted with no named customer relying on it, so nothing certified yet blocks a replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Running inference inside hardware-isolated, attested compute with Oblivious HTTP, encrypted streaming, and unlinkable requests, modeled on Apple's Private Cloud Compute, is specialized cryptographic and systems engineering.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The company aims at regulated enterprises in healthcare, finance, and government but shows no named enterprise deal, and its published self-serve per-token pricing also courts smaller developers, so it lands at two rather than a named regulated base.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 CONFSEC is the inference endpoint an application routes its model calls through rather than an overlay beside the app, infrastructure other software depends on.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The core is published as the OpenPCC standard, an Apache-2.0 spec with a source-available server, and the product retains no user data, so there is no proprietary corpus or private dataset, and a funded rival can adopt the same public standard.
Strategic Market Segmentation Confident Security aims at the regulated enterprise that privacy has kept off frontier AI…

Confident Security aims at the regulated enterprise that privacy has kept off frontier AI. The company names healthcare, finance, and government as the sectors where fear about where data goes is the barrier, and its whole pitch is to let those buyers use models without exposing prompts and documents to a provider. That buyer has both a compliance owner who needs the guarantee and an engineer who has to integrate it.

The product also courts a smaller, self-serve developer. Confident Security publishes per-token pricing and ships an OpenAI-compatible API a team can adopt by swapping an endpoint, so a developer can start without a sales call. The published price list and drop-in interface point at a bottom-up motion running alongside the enterprise pitch, which widens the buyer set but blurs which end actually pays.

A third audience is the AI vendor itself. Confident Security positions CONFSEC as an intermediary layer that model providers and hyperscalers could offer their own customers to unlock privacy-sensitive markets, so the same product is pitched to platforms whose own AI offerings could one day absorb it, a relationship the record leaves open between partner and rival. No named buyer in any of these segments appears in the public record yet.

Product Capabilities & AI Advantages CONFSEC runs AI inference on data the operator cannot read…

CONFSEC runs AI inference on data the operator cannot read. It keeps prompts, outputs, and logs confidential through encryption and hardware attestation, routes requests through Oblivious HTTP so individual calls cannot be linked, and decrypts only under conditions that forbid logging, training, or human access. The company states that prompts are never logged, retained, used for training, or sent to third parties.

The differentiator is that the guarantee is auditable rather than promised. The core ships as OpenPCC, a framework inspired by Apple's Private Cloud Compute, its specification and SDKs Apache 2.0 and its reference inference server source-available under the FSL, using encrypted streaming, hardware attestation, and unlinkable requests. Because the specification and the server source are open to inspection, a buyer or an outside expert can review how the privacy works instead of trusting a policy, which is a stronger technical position than a masking layer bolted in front of a model.

The limits are the claims that rest on the vendor's own word. The founder's statements that CONFSEC is production-ready and externally audited name no auditor and link no report, and the cited sources include no third-party benchmark of the performance cost of the private path. The advantage a buyer can check is the open code and the attestation, not an independent evaluation.

Sales Engagement & Go-to-Market Confident Security runs distribution through an open standard as much as a sales team…

Confident Security runs distribution through an open standard as much as a sales team. It published OpenPCC and framed it as an open standard any model provider or host can adopt, betting that ubiquity of the standard pulls buyers to its managed service. That is a developer-and-ecosystem motion rather than a top-down enterprise sales push, fitting a seed-stage company.

Public proof of demand is prospects, not customers. TechCrunch reports the company is in talks with banks, browsers, and search engines to add CONFSEC to their infrastructure stacks. Those are prospects that build a pipeline, but none is a paying reference the public record can name.

The funding is the strongest outside marker and it is small. The company came out of stealth in July 2025 with $4.2 million reported from Decibel, South Park Commons, Ex Ante, and Swyx, while November coverage of the OpenPCC launch reported a $5 million seed and named Halcyon and SAIF, two accounts the record does not reconcile. That backing signals conviction at the earliest stage rather than commercial traction.

Pricing Model Confident Security publishes its prices, which is unusual for the category and tells a buyer what it thinks it sells…

Confident Security publishes its prices, which is unusual for the category and tells a buyer what it thinks it sells. The pricing page lists per-token rates for specific open models, from Mistral and Gemma at a fraction of a dollar per million tokens to larger models priced higher, updated to a dated market snapshot. Charging by the token, the same unit a buyer already uses to measure model spend, makes the cost directly comparable to a standard model API.

The company describes its pricing as twice the market rate and says so plainly, framing 2x as fair given the work required, against a rate table last updated July 9, 2025, so a buyer can see the vendor's stated premium and what it pays for. Transparent, comparable pricing lowers the friction of evaluating a young vendor, because a team can size the spend before talking to sales.

The premium is also the positioning risk. The stated 2x premium is defensible only while no larger provider offers comparable privacy closer to base cost, so the pricing depends on the privacy guarantee staying scarce rather than becoming a bundled feature.

Product Delivery & Operations CONFSEC is delivered as a drop-in inference endpoint…

CONFSEC is delivered as a drop-in inference endpoint. A developer swaps an existing OpenAI-compatible endpoint for CONFSEC and keeps the same interface, so the private path replaces the model API without a rewrite. Confident Security runs the inference inside hardware-isolated, attested environments and anonymizes traffic by routing it through services so the servers never see the source or content.

The company runs the standard as a managed service, and the open standard is customer-deployable. Confident Security operates CONFSEC on the OpenPCC standard as a hosted service, and because OpenPCC is publicly specified with a source-available server deployable on a customer's own infrastructure, a buyer with the capability can run private inference in its own racks. That range suits a regulated buyer that wants the data to stay inside its boundary.

Operational trust is designed to need no trust in the operator. The system retains no user data, so the delivery model removes the operator's ability to see or keep the data rather than promising restraint. What the record does not show is a published uptime commitment, support tier, or the performance overhead of the private path.

Earning Customers' Trust Confident Security stakes the whole product on verifiable trust rather than certification…

Confident Security stakes the whole product on verifiable trust rather than certification. The compliance page contrasts guarantees with rivals' promises, stating customer data are guaranteed never to train models, never to be shared, and never accessible unencrypted, and the homepage adds that the company takes financial responsibility for any breach or misuse. That liability stance is the company's central and unusual trust argument.

The verification rests on open code and hardware attestation. Because the OpenPCC specification and SDKs are Apache 2.0 and the reference inference server is source-available for review, the company argues a buyer or an outside expert can confirm the guarantees hold rather than accept a policy, a stronger posture than self-attestation for a young vendor handling sensitive data.

The gap is a named independent attestation. The compliance page markets the ability to build SOC 2, HIPAA, PCI DSS, and GDPR compliant AI features, but a probe of it and the trust and security paths on 2026-07-03 found no SOC 2 report, ISO 27001 certificate, named auditor, or independent audit of Confident Security itself, and the founder's statement that CONFSEC was externally audited names no auditor and links no report. For a product whose entire value is trust, a security review would likely require the independent attestation the public record does not yet carry.

Platform Strategy & Ecosystem Positioning Confident Security's platform bet is an open standard, not a closed product…

Confident Security's platform bet is an open standard, not a closed product. OpenPCC ships as a spec and SDKs any team can implement across models and providers, plus a reference inference server and libraries for hardware attestation and unlinkable communication. The goal is a shared standard multiple model providers interoperate on rather than a single vendor's stack.

The strategy trades control for reach. By giving the core away as an open standard, Confident Security tries to make OpenPCC the default way to run private inference, which would let it sell the managed service on top and let buyers switch models or hosts without losing the guarantee. Adoption of the standard, not a proprietary lock, is the intended source of durability.

The same openness is the exposure. Because the core is openly published, a hyperscaler or a model provider can adopt OpenPCC as readily as a customer can, so the ecosystem Confident Security is trying to seed is one its largest competitors can join or absorb. No third-party marketplace or partner-built integration network beyond the open project itself appears yet.

Team & Execution Capability The founder is the clearest asset…

The founder is the clearest asset. Jonathan Mortensen is a two-time founder whose prior companies were acquired by BlueVoyant and Databricks, a pair of in-domain exits reported by independent press. That record of building and selling companies in security and data is the strongest single credibility signal the company carries.

The team is built for confidential computing. The AI Journal reports backgrounds spanning Google, Apple, Databricks, Red Hat, and HashiCorp, with depth in trusted computing, secure systems, and large-scale infrastructure, which matches a product built on hardware attestation and encrypted inference. Pulse 2.0 adds institutional pedigree including Google, Apple, and Johns Hopkins.

What the record does not show is a research or standards reputation. The cited public record emphasizes exits and employer pedigree rather than published work or standards authorship in privacy or cryptography, so the credibility comes from exits and experience rather than a public track record that would itself pull adopters to the standard.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Confident Security homepage (verifiably-private inference API) official 2026-07-03
f2 TechCrunch on Confident Security stealth launch (year-old company) press 2026-07-03
f3 The AI Journal on Confident Security OpenPCC launch (seed funding and team) press 2026-07-03
f4 CONFSEC (AI Defense Matrix Catalog mapping) other 2026-07-03
Profile Analysis Sources (8)
Id Source Tier Accessed
s1 Confident Security homepage (verifiably-private inference API)
“Verifiably-private Inference API. Develop AI products without worrying about security, privacy, or compliance. We take financial responsibility for any breach or misuse. Based on OpenPCC, the open-source standard that ensures all AI interactions are verifiably-private.”
official 2026-07-03
s2 TechCrunch on Confident Security stealth launch (traction, founding, mechanism)
“It's still early days for the year-old company, but Mortensen said CONFSEC has been tested, externally audited, and is production-ready. The team is in talks with banks, browsers, and search engines, among other potential clients, to add CONFSEC to their infrastructure stacks.”
press 2026-07-03
s3 The AI Journal on the OpenPCC launch (seed funding, founder, team)
“Confident Security raised $5 million in seed funding from Decibel, Ex/Ante, South Park Commons, Halcyon, and SAIF. Mortensen is a two-time founder with prior exits to BlueVoyant and Databricks. The team's background spans Google, Apple, Databricks, Red Hat, and HashiCorp.”
press 2026-07-03
s4 Pulse 2.0 on Confident Security's stealth raise (investors)
“launched with $4.2 million in funding from Decibel, South Park Commons, Ex Ante, and Swyx. ... The team, led by two-time founder Jonathan Mortensen, comprises experts ... including Google, Apple, and Johns Hopkins.”
press 2026-07-03
s5 OpenPCC open-source repository (open, auditable framework)
“OpenPCC is an open-source framework for provably private AI inference, inspired by Apple's Private Cloud Compute, fully open, auditable, and deployable on your own infrastructure. It enforces privacy with encrypted streaming, hardware attestation, and unlinkable requests.”
official 2026-07-03
s6 Confident Security pricing (per-token, 2x market rate)
“Beyond compliant AI for just 2x market rate. Mistral 7B $0.25 per 1M input tokens, $0.25 per 1M output tokens. Llama 4 Scout 16x17B $0.36 per 1M input tokens, $1.18 per 1M output tokens. Last updated July 9th, 2025.”
official 2026-07-03
s7 Confident Security compliance page (probed trust surface, guarantees framing)
“Why pay for promises when you can have absolute guarantees? Your data are guaranteed to never be used in training AI models, never be shared with a third party. ... HIPAA Compliant AI. PCI DSS Compliant AI. GDPR Compliant AI. SOC 2 Type 2 Compliant AI.”
official 2026-07-03
s8 CONFSEC in the AI Defense Matrix Catalog (matrix coverage)
“Keeps prompts, outputs, and logs confidential through encryption and attestation, so prompts are never logged, retained, used for training, or sent to third parties. Routing requests through Oblivious HTTP so operators cannot link or read individual requests.”
other 2026-07-03
Deep-Dive Sources (8)
Id Source Tier Accessed
s1 Confident Security homepage (verifiably-private inference API)
“Verifiably-private Inference API. Develop AI products without worrying about security, privacy, or compliance. We take financial responsibility for any breach or misuse. Based on OpenPCC, the open-source standard that ensures all AI interactions are verifiably-private.”
official 2026-07-03
s2 TechCrunch on Confident Security stealth launch (traction, mechanism, founding)
“It's still early days for the year-old company, but Mortensen said CONFSEC has been tested, externally audited, and is production-ready. The team is in talks with banks, browsers, and search engines, among other potential clients, to add CONFSEC to their infrastructure stacks.”
press 2026-07-03
s3 The AI Journal on the OpenPCC launch (funding, founder, team, components)
“Confident Security raised $5 million in seed funding from Decibel, Ex/Ante, South Park Commons, Halcyon, and SAIF. Mortensen is a two-time founder with prior exits to BlueVoyant and Databricks. The team's background spans Google, Apple, Databricks, Red Hat, and HashiCorp.”
press 2026-07-03
s4 Pulse 2.0 on Confident Security's stealth raise (investors, founder, team)
“launched with $4.2 million in funding from Decibel, South Park Commons, Ex Ante, and Swyx. ... The team, led by two-time founder Jonathan Mortensen, comprises experts ... including Google, Apple, and Johns Hopkins.”
press 2026-07-03
s5 OpenPCC open-source repository (open, auditable framework)
“OpenPCC is an open-source framework for provably private AI inference, inspired by Apple's Private Cloud Compute, fully open, auditable, and deployable on your own infrastructure. It enforces privacy with encrypted streaming, hardware attestation, and unlinkable requests.”
official 2026-07-03
s6 Confident Security pricing (per-token, 2x market rate)
“Beyond compliant AI for just 2x market rate. Mistral 7B $0.25 per 1M input tokens, $0.25 per 1M output tokens. Llama 4 Scout 16x17B $0.36 per 1M input tokens, $1.18 per 1M output tokens. Last updated July 9th, 2025.”
official 2026-07-03
s7 Confident Security compliance page (probed trust surface, guarantees framing)
“Why pay for promises when you can have absolute guarantees? Your data are guaranteed to never be used in training AI models, never be shared with a third party. ... HIPAA Compliant AI. PCI DSS Compliant AI. GDPR Compliant AI. SOC 2 Type 2 Compliant AI.”
official 2026-07-03
s8 CONFSEC in the AI Defense Matrix Catalog (matrix coverage)
“Keeps prompts, outputs, and logs confidential through encryption and attestation, so prompts are never logged, retained, used for training, or sent to third parties. Routing requests through Oblivious HTTP so operators cannot link or read individual requests.”
other 2026-07-03

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.