All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This analysis is scoped to Fortanix Confidential AI.
Fortanix runs enterprise AI models and inference inside hardware trusted execution environments, so weights and data stay encrypted from the cloud operator. Intel, NVIDIA, and the major clouds sell the confidential-computing hardware and could absorb more of the orchestration over time. Underneath that runtime sits an older asset: a FIPS 140-2 Level 3 hardware security module that releases the keys to decrypt a model or dataset only after the enclave proves what it runs. The buyer's bet is that this key-management position holds as the enclave becomes a feature the platforms hand out. Named AI references are vendor-shown, and the loudest proof so far is a 2025 NVIDIA partnership, not disclosed customer scale.
| Description | Fortanix is a data-security company whose Confidential AI runs enterprise models and inference inside confidential-computing trusted execution environments, keeping data and model IP encrypted and inaccessible to the host, alongside its key management and hardware security module products. | [f1] |
|---|---|---|
| Founded | 2016 | [f2] |
| HQ | Santa Clara, California, US | [f3] |
| Funding | $122M total | [f4] |
| Latest funding | Series C, $90M (2022) | [f4] |
| Product | What it does |
|---|---|
| Fortanix Confidential AI | Confidential-computing runtime that runs enterprise models and inference inside trusted execution environments so model IP and data stay encrypted and inaccessible to the host. |
| Confidential Computing Manager | Control plane that registers nodes and manages trusted execution environments, verifying workloads through composite CPU and GPU attestation before keys are released. |
| Armet AI | Turnkey secure generative AI platform that runs the full AI pipeline on confidential computing with built-in orchestration, observability, and guardrails. |
| Data Security Manager | Enterprise encryption and key management with a FIPS 140-2 Level 3 hardware security module and key management service across hybrid multicloud environments. |
| Key Insight | Cryptographic security posture management that discovers encryption keys and data services, flags at-risk and quantum-vulnerable keys, and prioritizes remediation. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Fortanix Confidential AI runs proprietary models inside a confidential-computing trusted execution environment so model IP and inference data stay encrypted and inaccessible to the host and cloud operator across the AI lifecycle. These capabilities are mapped to the AI Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Fortanix names a concrete buyer, regulated enterprises in healthcare, finance, and government that it says cannot move sensitive data to a shared cloud model, and independent reporting on the 2025 NVIDIA solution frames the same roadblock. The pain is argued through the vendor and press rather than quantified by an independent study or a named mandate, holding at the present default. [s1, s9, s7] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | The public pages document the architecture: CPU and GPU trusted execution environments, composite attestation joining Confidential Computing Manager and NVIDIA remote attestation, and secure key release gated by a FIPS 140-2 Level 3 module. An independent analyst note breaks down the Intel SGX, TDX, and Tiber layers, and the NVIDIA and Intel co-engineering supplies external validation beyond marketing. [s1, s2, s8] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | Confidential AI on GPUs rests on the memory-encryption features Intel TDX and NVIDIA Hopper and Blackwell introduced, and Fortanix timed its 2025 Armet AI preview and NVIDIA launch to that shift. Buyer-side demand is still argued through partner motion and regulated-industry framing rather than independent budget or category signals. [s7, s9, s2] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Co-founders Ambuj Kumar and Anand Kashyap started Fortanix in 2016 and built it into a confidential-computing pioneer backed by In-Q-Tel, Intel Capital, and Goldman Sachs, with Kashyap now CEO. The public record shows verifiable senior in-domain execution and a sustained build, without a documented prior exit or research-publication record that lifts the academic-founder peers to a higher level. [s5, s6, s4, s9, s7] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | The Confidential AI line shows two named references, BeeKeeperAI at UCSF and ElevenLabs, both displayed on Fortanix's own pages, plus independently reported a partnership with NVIDIA. That is real named traction without independent corroboration of customer scale for the AI line, so it sits at the one-or-two-named-references level rather than a multiply-sourced reference base. [s1, s10, s9] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Fortanix raised about $122 million through a 2022 Series C led by Goldman Sachs and has not raised since, while continuing to ship, launching Armet AI in 2025 and a joint NVIDIA solution, which reads as proportional, still-deploying capital rather than a stalled raise. Efficiency itself is unconfirmed because no revenue, margin, or growth-per-dollar figure is disclosed. [s4, s7, s9] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Confidential computing and confidential AI are recognizable but still emerging categories, and Fortanix is described as a confidential-computing pioneer that analysts and press place without difficulty. Buyers still need vendor explanation for what confidential AI adds over standard cloud AI, so placement fits a nascent category rather than an established stack slot. [s7, s8, s9] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The confidential runtime sits on hardware Intel, NVIDIA, and the clouds sell directly and could extend into the orchestration above, which limits the moat, but Fortanix adds real friction through its Confidential Computing Manager orchestration and FIPS 140-2 Level 3 key management gating decryption. That is workflow and key embedding a bundling vendor would need to reproduce, short of a structural data moat. [s2, s1, s9] |
Fortanix Confidential AI targets a specific and legally sharp problem. Regulated enterprises in healthcare, finance, and government want to run modern AI on their most sensitive data, but sending prompts, records, or model weights to a shared cloud model exposes information they are obligated to protect. Fortanix frames the buyer as organizations that cannot move that data off their own controlled environment.
Independent reporting on the 2025 Fortanix and NVIDIA solution describes the same roadblock, that healthcare records, financial transactions, and classified information must stay protected at all times, which forces a choice between AI adoption and compliance. The pain is real and specific, but the public evidence frames it qualitatively through the vendor and press rather than quantifying it with an independent study or a named regulatory mandate.
The buyer and the problem are clear, which places problem definition at a credible middle rather than an independently established urgency. [s1, s9, s7]
Fortanix Confidential AI runs enterprise models and inference inside hardware trusted execution environments so that data, model weights, and intermediate inference stay encrypted in memory, protected even from privileged insiders, hypervisors, and co-resident workloads. Buyers can bring their own models and data or deploy Armet AI, a turnkey agentic-AI platform built on the same confidential computing.
The architecture is documented in specific terms. Composite attestation joins Fortanix Confidential Computing Manager and NVIDIA remote attestation into a single chain of trust across CPU and GPU, and secure key release through Fortanix Data Security Manager unlocks datasets and model artifacts only after that attestation succeeds. The stack runs on NVIDIA Hopper and Blackwell GPUs and Intel SGX and TDX CPUs, with a FIPS 140-2 Level 3 hardware security module holding the keys.
An independent analyst note details the Intel SGX, TDX, and Tiber Trust Authority layers Armet AI integrates, and the deep NVIDIA and Intel co-engineering supplies external validation of the capability beyond the vendor's own pages. [s1, s2, s8]
The distinguishing feature is what sits beneath the enclave. The confidential runtime rests on hardware Intel, NVIDIA, and the major clouds sell, and those vendors could extend into the orchestration above it, so that layer is available to any competitor. Fortanix pairs it with a mature key-management and hardware-security-module franchise that gates decryption, a capability the enclave runtime layer does not itself supply and one the reviewed sources do not establish for the named confidential-AI startups either way.
That position is a real differentiator today, though it depends on regulated buyers continuing to treat attested, FIPS-validated key release as a distinct requirement rather than a feature the platforms absorb. [s2, s1, s9]
The Confidential AI line shows a small set of named references. BeeKeeperAI, created at the University of California, San Francisco, runs healthcare AI on Fortanix confidential computing, and ElevenLabs is cited as a model provider deploying its text-to-speech models on Fortanix and NVIDIA confidential infrastructure. Both appear on Fortanix's own pages.
The strongest recent go-to-market signal is partnership motion that independent outlets reported: the October 2025 joint solution with NVIDIA demonstrated at NVIDIA GTC and its positioning for AI Factories and regulated environments. These are distribution and co-selling moves rather than disclosed customer counts or revenue.
The broader Fortanix business reports customers across highly regulated industries, but the AI line's own traction is vendor-displayed references plus partner announcements, without independent corroboration of scale. [s10, s1, s9, s4]
Fortanix was founded in 2016 by Ambuj Kumar and Anand Kashyap, who built it into a company widely described as a confidential-computing pioneer. Anand Kashyap is described as co-founder and chief executive in 2025 coverage.
Kumar and Kashyap draw their credibility from a sustained, verifiable build in exactly this domain and from the confidence of strategic investors, In-Q-Tel, Intel Capital, and Goldman Sachs among them. The cited sources emphasize Fortanix's operating history and the founders' security backgrounds rather than a prior in-domain exit or serial-founder pedigree.
A regulatory record corroborates the raise on its own terms. The Form D Fortanix filed with the Securities and Exchange Commission in August 2022 reports an exempt equity offering of $89,781,712, of which $81,999,912 had been sold and $7,781,800 remained to be sold at the filing date. Those figures record capital placed in a single exempt offering, a different measure from the announced round total the company published, and they anchor the investor confidence described above in a filing rather than in a company announcement.
Senior in-domain execution over nearly a decade is clear, while the founder-pedigree signals that would place the team above that level are not established in public sources. [s5, s6, s9, s4, s7, s13]
Trust is central to what Fortanix Confidential AI sells, and the line leans on concrete cryptographic assurances rather than only policy claims. Secure key release runs through a FIPS 140-2 Level 3 hardware security module, and composite CPU and GPU attestation provides a verifiable chain of trust before any model or dataset is decrypted.
The offering supports on-premises deployment for buyers that must retain local control, and it uses Azure confidential VMs, reflecting a long Azure confidential-computing partnership dating to 2020. For regulated healthcare, finance, and government workloads, these are the readiness signals buyers check first.
Two independent records qualify those assurances. The NIST Cryptographic Module Validation Program lists the validated module as the Fortanix SDKMS Appliance, described there as the building block for a unified HSM and key management service, so the FIPS certification the product pages cite is recorded under the platform's earlier name. The National Vulnerability Database separately documents a flaw in the Fortanix Confidential Computing Manager platform for Intel SGX, where missing pointer-alignment validation allowed a local attacker to reach unauthorized information before release 3.32. Attested hardware narrows the trusted computing base, and the enclave runtime above it remains code that can carry defects.
The strongest evidenced trust signals here are cryptographic and hardware-rooted. Public sources focus on those guarantees rather than detailing the service's broader audit-attestation posture, so the hardware-rooted assurances carry the trust story. [s1, s2, s9, s11, s12]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Opaque Systems | competes with | N/AWe scored these companies at different scopes, so the totals measure different things. | |
| Tinfoil | competes with | N/AWe scored these companies at different scopes, so the totals measure different things. | |
| Anjuna Security | competes with | N/AWe scored these companies at different scopes, so the totals measure different things. | |
| Enveil | adjacent | N/AWe scored these companies at different scopes, so the totals measure different things. | |
| Duality Technologies | adjacent | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with Fortanix.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Fortanix Confidential AI's durability sits in an asset its own marketing understates. The enclave that runs models and inference encrypted rests on primitives Intel, NVIDIA, and the clouds supply, suppliers positioned to extend into the orchestration, so the runtime reads as copyable. Fortanix's friction is the FIPS 140-2 Level 3 hardware security module that gates when a model or dataset is decrypted, a named cryptographic-module validation. The record identifies no cross-customer dataset, so nothing documented accumulates into a data lead. Cancelling it means re-platforming AI workloads and moving the keys the business runs on. The lasting advantage is the key-management franchise it carries from its data-security business, which reaches regulated buyers, not the runtime itself.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Fortanix Confidential AI delivers software, the Confidential Computing Manager control plane, Data Security Manager key management, and Armet AI orchestration, at the software-product level. The attestation and audit evidence it generates is software output rather than a human-judgment or managed-service layer that accepts accountability. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Once production AI workloads run inside the confidential runtime with policies, composite attestation, and Data Security Manager key release wired in, leaving means re-platforming those workloads and migrating enterprise keys, meaningful integration effort. No data-residency network lock appears in the record, so the friction is effort rather than a structural lock, at the top of the cluster level. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | Secure key release for Confidential AI runs through a FIPS 140-2 Level 3 hardware security module, a named cryptographic-module validation. The validation raises buyer readiness in regulated procurement as a concrete named signal, though it does not by itself block a determined replacement. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Binding a single chain of trust across CPU and GPU trusted execution environments, composite attestation, and attestation-gated key release is specialized hardware and cryptography engineering that few teams execute, level with the confidential-computing cluster. An independent analyst note details the Intel SGX, TDX, and Tiber layers the platform integrates. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | Fortanix Confidential AI credibly addresses regulated and government buyers, evidenced by an adjacent BeeKeeperAI confidential-computing deployment in healthcare, the ElevenLabs model-provider reference, and the Fortanix-NVIDIA joint solution positioned for regulated markets. The evidenced named base is still a single healthcare deployment plus model-provider interest rather than a broad regulated-procurement roster, holding it level with the cluster. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | The AI workload executes inside Fortanix's confidential runtime, execution infrastructure other software depends on rather than an overlay beside it, and removing it means moving production AI workloads off the platform. This matches the confidential-computing cluster at the infrastructure level. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | By design the platform keeps model weights and inference data inside the customer's enclave, and no proprietary cross-customer corpus appears in the record, so no proprietary dataset accumulates into a content or data advantage. The differentiating cryptography and orchestration are expertise and code a funded rival could also build on the same commodity hardware. |
Fortanix Confidential AI aims at organizations whose data is too sensitive or regulated to run on shared cloud AI, concentrating on healthcare and financial services, and government and defense. The product pages describe processing patient records, financial transactions, and classified information under confidentiality guarantees, and the 2025 NVIDIA solution is positioned explicitly for these regulated verticals.
A second segment is AI model providers themselves. Fortanix pitches confidential deployment as a way for a model owner to run proprietary weights inside a customer's environment without revealing the model, a tension the ElevenLabs reference describes directly. This two-sided framing, protecting both the enterprise's data and the provider's model IP, widens the addressable buyer set beyond one side of the transaction.
The segmentation is coherent and matches where confidential computing has real regulatory pull, though the evidenced deployments cluster in healthcare and model-provider pilots rather than spanning all the named verticals.
The core capability is running the full AI lifecycle, fine-tuning, training, and inference, inside trusted execution environments so raw data and model weights are never exposed to the host, the hypervisor, or co-resident workloads. Composite attestation binds Fortanix Confidential Computing Manager and NVIDIA remote attestation into one chain of trust across CPU and GPU, and Data Security Manager releases keys only after that attestation.
Armet AI layers a turnkey generative-AI pipeline on top, with secure chat over internal data, role-based access control, and guardrails that redact sensitive data and filter harmful inputs and outputs, all running inside confidential computing. An independent analyst note credits the integration of Intel SGX, TDX, and Tiber Trust Authority as the security foundation.
The AI-specific advantage is less any model capability and more the verifiable trust envelope around whatever model runs. That envelope is hard engineering, but it is built from hardware primitives the chip and cloud vendors supply, so the durable advantage concentrates in the orchestration and key management Fortanix adds rather than in the enclave itself.
Fortanix reaches the market through a mix of its own enterprise sales, Azure confidential-computing availability, and increasingly through hardware and platform partners. The October 2025 NVIDIA joint solution, demonstrated at NVIDIA GTC and positioned for AI Factories and regulated environments, is the clearest go-to-market lever, pairing Fortanix with NVIDIA's enterprise-AI channel.
That joint solution routes Fortanix Confidential AI toward buyers already purchasing AI infrastructure, which suits a product that must sit on specific confidential-computing hardware from a chip or cloud vendor.
The named references are vendor-displayed and adjacent: Fortanix's own case study attributes BeeKeeperAI to its data-security and confidential-computing products rather than the Confidential AI line, and ElevenLabs appears as a collaboration reference rather than a disclosed paying customer, so the public go-to-market evidence is strong on partner distribution and thinner on independently corroborated customer wins for the AI line specifically.
Fortanix does not publish pricing for the Confidential AI line in the public sources reviewed. The offering is sold through enterprise engagements and is available on Azure, with on-premises options for buyers that require local control, which points to negotiated, deployment-dependent pricing rather than a public self-serve tier.
Because the platform runs on specific confidential-computing hardware, total cost also depends on the underlying GPU and CPU capacity a buyer provisions, whether in a cloud or an on-premises AI factory. That coupling to hardware is inherent to confidential computing and shapes the economics more than a list price would.
The absence of public pricing is normal for an enterprise, compliance-driven security product at this stage and is not itself a weakness, though it limits outside assessment of packaging and value capture.
Fortanix Confidential AI is delivered as software packaged around the Confidential Computing Manager control plane, Data Security Manager for key management, and the Armet AI orchestration layer. It runs across cloud, on-premises, and AI-factory environments, and Fortanix has been an Azure confidential-computing partner since 2020.
Operationally, the product's promise is that workloads run inside enclaves while attestation and key release happen automatically before any decryption. The platform supports customer-controlled deployments and produces cryptographic evidence as output, though the cited pages do not document the operating split for every deployment and Fortanix itself describes Armet AI as a service.
This is a software-product delivery model. It scales through partner infrastructure and cloud availability rather than through a services organization, which keeps delivery lean but places the operational burden of running confidential workloads on the customer.
Trust is the product, and Fortanix roots it in hardware rather than assertions. Secure key release runs through a FIPS 140-2 Level 3 hardware security module, a named cryptographic-module validation, and composite CPU and GPU attestation provides a verifiable chain of trust before any model or dataset is decrypted.
For regulated buyers, the offering supports on-premises deployment and targets HIPAA-governed healthcare data, financial data, and government classification levels. The FIPS-validated key management is a concrete, hardware-rooted trust signal beyond a self-asserted attestation.
The strongest evidenced trust signals here are cryptographic and hardware-rooted. Public sources focus on those guarantees rather than detailing the service's broader audit-attestation posture, so the hardware-rooted assurances carry the trust story.
Fortanix Confidential AI is deeply embedded in a hardware and cloud ecosystem it does not own. It runs on Intel SGX and TDX CPUs and NVIDIA Hopper and Blackwell confidential-computing GPUs, uses NVIDIA remote attestation, and is available on Microsoft Azure, with a confidential- computing partnership dating to 2020.
The October 2025 NVIDIA joint solution makes NVIDIA the central platform relationship. This ecosystem position is a distribution advantage, routing Fortanix toward buyers already committed to confidential-computing hardware.
The same dependence is a strategic exposure. The chip and cloud vendors that supply the enclave primitives could extend into competing or bundled confidential-AI orchestration, a risk inferred from Fortanix's dependence on their platforms rather than documented current competition, so the ecosystem is simultaneously its channel and its most likely source of absorption.
Fortanix was co-founded in 2016 by Ambuj Kumar and Anand Kashyap and grew into a company widely described as a confidential-computing pioneer. Anand Kashyap is described as co-founder and chief executive in 2025 coverage.
Strategic investors reinforce the team's standing. In-Q-Tel, Intel Capital, and Goldman Sachs backed the company through its 2022 Series C, and In-Q-Tel's involvement in particular signals credibility with government and intelligence buyers.
The cited sources emphasize Fortanix's operating history and the founders' security backgrounds rather than a prior in-domain exit. The team's demonstrated strength is operating and scaling Fortanix itself over nearly a decade, rather than the serial-founder pedigree that distinguishes some direct peers.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Fortanix Confidential AI product page (TEE runtime, model IP and data protection) | official | 2026-07-06 |
| f2 | TechCrunch: Cybersecurity firm Fortanix secures capital to provide confidential computing services | press | 2026-07-06 |
| f3 | Fortanix platform page footer (US headquarters address) | official | 2026-07-06 |
| f4 | Fortanix press release: Raises $90M Series C, total over $122 million | official | 2026-07-06 |
| f5 | AI Defense Matrix Catalog mapping (aligned to catalog) | other | 2026-07-06 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Fortanix Confidential AI product page (TEE runtime, FIPS 140-2 Level 3 HSM secure key release, model IP and inference protection, ElevenLabs reference) “CPU and GPU memory encryption keeps sensitive data, model weights, and inference protected in memory, even from privileged insiders, hypervisors, and co-resident workloads.” | official | 2026-07-06 |
| s2 | Fortanix Armet AI product page (composite CPU and GPU attestation, DSM secure key release, NVIDIA Hopper and Blackwell, Intel SGX and TDX) “Fortanix Data Security Manager allows access to datasets and model artifacts only after verified attestation” | official | 2026-07-06 |
| s3 | Fortanix homepage (Confidential AI positioning, customer case-study carousel) “Secure AI models, prompts, and data in use with Confidential Computing for trust, security and sovereignty.” | official | 2026-07-06 |
| s4 | Fortanix press release: $90M Series C led by Goldman Sachs Asset Management, over $122M total “announced $90 million in Series C financing bringing the total amount the company has raised to over $122 million.” | official | 2026-07-06 |
| s5 | TechCrunch: Fortanix secures capital for confidential computing (founded 2016 by Kumar and Kashyap) “Kumar founded Fortanix alongside Anand Kashyap in 2016.” | press | 2026-07-06 |
| s6 | Futuriom: Momentum for Multicloud, Fortanix founders and 2016 founding “Founded in 2016 in Mountain View, Calif., Fortanix has risen to prominence by combining encryption, confidential computing, tokenization, and key management in a multi-layered approach” | press | 2026-07-06 |
| s7 | SiliconANGLE: Fortanix introduces Armet AI, public preview April 2025 on Intel Confidential Computing “today announced the public preview of Fortanix Armet AI, a new service that allows enterprises to create secure and compliant custom generative artificial intelligence applications to mitigate data exposure risk.” | press | 2026-07-06 |
| s8 | NAND Research note: Fortanix Armet AI public preview (Intel SGX, TDX, Tiber Trust Authority) “combining Intel's trusted execution environments (SGX, TDX) with fine-grained access control, policy enforcement, and AI-specific security mechanisms.” | research | 2026-07-06 |
| s9 | SiliconANGLE: Fortanix and NVIDIA enable confidential AI for healthcare, finance, and government (Oct 2025) “a new joint solution with Nvidia Corp. that offers a turnkey, on-premises platform for running secure and sovereign, agentic artificial intelligence in AI Factories and highly regulated environments.” | press | 2026-07-06 |
| s10 | Fortanix case study: BeeKeeperAI accelerates healthcare AI with Fortanix confidential computing “Created at the University of California, San Francisco (UCSF), Center for Digital Health Innovation (CDHI), BeeKeeperAI accelerates the development and deployment of artificial intelligence (AI) algorithms in healthcare.” | official | 2026-07-06 |
| s11 | NIST CMVP certificate #4139: Fortanix SDKMS Appliance, FIPS 140-2 overall level 3, validated 2022-01-19, sunset 2026-09-21 “Fortanix SDKMS appliance is the building block for running Fortanix Self-Defending Key Management Service (SDKMS), a unified HSM and Key Management solution.” | regulatory | 2026-09-01 |
| s12 | NVD CVE-2023-38021: local information disclosure in Fortanix Confidential Computing Manager for Intel SGX, CVSS 5.5 medium, fixed in 3.32 “An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.32 for Intel SGX. Lack of pointer-alignment validation logic in entry functions allows a local attacker to access unauthorized information.” | regulatory | 2026-09-01 |
| s13 | SEC Form D for an exempt equity offering by Fortanix, Inc., CIK 0001707138, signed 2022-08-11 “Total Offering Amount $ 89,781,712 USD or Indefinite Total Amount Sold $ 81,999,912 USD Total Remaining to be Sold $ 7,781,800 USD” | regulatory | 2026-09-01 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Fortanix Confidential AI product page (TEE runtime, FIPS 140-2 Level 3 HSM secure key release, model IP and inference protection, ElevenLabs reference) “CPU and GPU memory encryption keeps sensitive data, model weights, and inference protected in memory, even from privileged insiders, hypervisors, and co-resident workloads.” | official | 2026-07-06 |
| s2 | Fortanix Armet AI product page (composite CPU and GPU attestation, DSM secure key release, NVIDIA Hopper and Blackwell, Intel SGX and TDX) “Fortanix Data Security Manager allows access to datasets and model artifacts only after verified attestation” | official | 2026-07-06 |
| s3 | Fortanix homepage (Confidential AI positioning, customer case-study carousel) “Secure AI models, prompts, and data in use with Confidential Computing for trust, security and sovereignty.” | official | 2026-07-06 |
| s4 | Fortanix press release: $90M Series C led by Goldman Sachs Asset Management, over $122M total “announced $90 million in Series C financing bringing the total amount the company has raised to over $122 million.” | official | 2026-07-06 |
| s5 | TechCrunch: Fortanix secures capital for confidential computing (founded 2016 by Kumar and Kashyap) “Kumar founded Fortanix alongside Anand Kashyap in 2016.” | press | 2026-07-06 |
| s6 | Futuriom: Momentum for Multicloud, Fortanix founders and 2016 founding “Founded in 2016 in Mountain View, Calif., Fortanix has risen to prominence by combining encryption, confidential computing, tokenization, and key management in a multi-layered approach” | press | 2026-07-06 |
| s7 | SiliconANGLE: Fortanix introduces Armet AI, public preview April 2025 on Intel Confidential Computing “today announced the public preview of Fortanix Armet AI, a new service that allows enterprises to create secure and compliant custom generative artificial intelligence applications to mitigate data exposure risk.” | press | 2026-07-06 |
| s8 | NAND Research note: Fortanix Armet AI public preview (Intel SGX, TDX, Tiber Trust Authority) “combining Intel's trusted execution environments (SGX, TDX) with fine-grained access control, policy enforcement, and AI-specific security mechanisms.” | research | 2026-07-06 |
| s9 | SiliconANGLE: Fortanix and NVIDIA enable confidential AI for healthcare, finance, and government (Oct 2025) “a new joint solution with Nvidia Corp. that offers a turnkey, on-premises platform for running secure and sovereign, agentic artificial intelligence in AI Factories and highly regulated environments.” | press | 2026-07-06 |
| s10 | Fortanix case study: BeeKeeperAI accelerates healthcare AI with Fortanix confidential computing “Created at the University of California, San Francisco (UCSF), Center for Digital Health Innovation (CDHI), BeeKeeperAI accelerates the development and deployment of artificial intelligence (AI) algorithms in healthcare.” | official | 2026-07-06 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.