# Cyber Company Profiles: Tinfoil

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-09-10
Canonical: https://cybercompanyprofiles.com/companies/tinfoil
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Tinfoil, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [tinfoil.sh](https://tinfoil.sh)
- Profile: https://cybercompanyprofiles.com/companies/tinfoil
- Type: Security for AI, Privacy, Data Security
- Market readiness: Established (25/40)
- Defensibility: Contested (13/21)
- Founded: 2024
- Last updated: 2026-09-10

## Executive Summary

Tinfoil runs AI models in hardware enclaves so a customer can verify that prompts and model weights stay hidden from the cloud provider and Tinfoil. It sells developers an API, a chat app, and a container service and targets regulated enterprises and government agencies. Founded in 2024 and backed by Y Combinator, it has not disclosed a funding total. Workshop Labs, which built a private AI training stack on it, is a named customer. It has not named an enterprise or government customer. It publishes the code its enclaves run, and a customer's software checks on each connection that the enclave runs that code. That engineering is why Tinfoil is hard to displace, and two founders have MIT doctorates in its fields, secure hardware and cryptography.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Tinfoil runs AI models inside hardware secure enclaves so that prompts, responses, and model weights stay private from the cloud provider and from Tinfoil itself, and it lets customers verify that privacy through remote attestation. | [\[f1\]](#company-detail-sources) |
| Founded | 2024 | [\[f2\]](#company-detail-sources) |
| HQ | San Francisco, California, US | [\[f2\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Private Inference | An OpenAI-compatible inference API that runs open-source models inside attested secure enclaves so application data stays private. |
| Private Chat | A private AI chat assistant, in the browser and on iOS, that keeps conversations confidential by running models in secure enclaves. |
| Tinfoil Containers | Runs any Docker image inside a secure enclave, bringing hardware-verified privacy to custom AI workloads and application backends. |

## Matrix Coverage

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f3\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| Runtime AI Data |  |  | ✓ |  |  |  |
| AI Model |  |  | ✓ |  |  |  |

Tinfoil Private Inference processes prompts and responses inside hardware secure enclaves that the cloud provider and Tinfoil cannot access, and it loads model weights inside the same enclave so they are not exposed during inference. These capabilities are mapped to the AI Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (25/40)**

Analyzed 2026-07-04. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Tinfoil names a concrete buyer and pain: regulated enterprises and government teams whose deals stall in security review because sending prompts to a cloud model exposes sensitive data. The pain is framed by the founders, and the testimonials echo adjacent privacy and deployment-friction concerns rather than quantifying it across independent studies, so it holds at the present default. \[[s5](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | The architecture is detailed publicly: hardware remote attestation, code published to GitHub and Sigstore, client-side SDK verification, and an OpenAI-compatible API. Open code and published benchmarks are external validation points most same-asset peers reach, and a Workshop Labs writeup coauthored with Tinfoil reports under 10 percent overhead, level with the confidential-inference cluster. \[[s2](#profile-analysis-sources), [s8](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Market Timing | 3/5 | The enabler is real and recent. Running enclaves on GPUs became practical only after NVIDIA added confidential computing to recent GPUs, which Tinfoil benchmarked on Blackwell in 2026, so the product could not have been built years earlier. Buyer-side demand is still indirect, argued from testimonials rather than budget-line or analyst-category signals. \[[s7](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Team Credibility | 4/5 | Two founders hold MIT PhDs in exactly the relevant fields, secure hardware and confidential computing for Jules Drean and privacy-preserving cryptography for Sacha, and co-founder Tanya Verma shipped privacy protocols on Cloudflare's cryptography team. That verifiable in-domain research depth clears the cluster bar, short of a prior exit or a category-defining record. \[[s5](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | Tinfoil shows named users, UC Berkeley and The Open Anonymity Project on Containers, and a named partner, Workshop Labs, building its Silo product on the platform, plus a self-serve product. The references are academic and early rather than paying regulated enterprises, and no independent scale figure appears, so it sits at the named-reference default above the design-partner rung. \[[s1](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | Tinfoil is a Y Combinator Spring 2025 company running a small team that ships visibly, three products, many hosted models, and public benchmarks, which is proportional to an early deep-tech motion. No disclosed revenue or margin confirms efficiency, the honest default for a funded early-stage startup. \[[s4](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Category Clarity | 3/5 | Verifiable private AI inference is a forming category that rides confidential computing and the Apple Private Cloud Compute reference point, but a buyer still needs vendor explanation to place it against a budget line and separate it from an AI gateway or a general data-privacy tool, so it stays nascent. \[[s1](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Incumbent Defensibility | 2/5 | Running inference in a secure enclave is a plausible near-term feature for the platforms around Tinfoil. Apple already ships Private Cloud Compute, and confidential computing is broadly available from chip makers and clouds such as Intel, AMD, and AWS Nitro Enclaves, and because Tinfoil's verification code is open source a funded rival can adopt the same approach, which holds it below the cluster midpoint. \[[s8](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |

### Business Risks

- Apple, Amazon, Microsoft, Google, or NVIDIA could ship confidential AI inference with attestation as a native feature, matching Tinfoil's core promise inside platforms buyers already use.
- Because Tinfoil's verification code is open source, a well-funded rival could stand up an equivalent verifiable-inference service on the same NVIDIA hardware without licensing anything from the company.
- The OpenAI-compatible, drop-in API leaves little to reabsorb on exit, so a customer could move to another compatible private-inference endpoint with minimal migration.
- Tinfoil's named users are academic groups, so a security review at a regulated enterprise could stall if it finds no production reference or independent audit of the running service.
- Tinfoil depends on NVIDIA's confidential-computing hardware, so a shift in NVIDIA's roadmap, pricing, or its own inference-privacy offering could compress Tinfoil's position.

### Problem & Market

Tinfoil sells against a specific blocker: companies that want powerful cloud AI cannot let the provider see their most sensitive data. The founders frame the pain in their launch as deals stalling in enterprise and government security reviews, and as the weakness of a legal promise like a data-processing agreement, which they call a pinky promise rather than a control. The buyer is a regulated enterprise, a government agency, or a startup selling into one, that needs to run frontier models on private data without trusting the operator.

Tinfoil answers that the privacy should be checkable, not asserted. A customer can cryptographically confirm that data was processed in a secure enclave the provider cannot read, rather than accept a policy. The comparison the company draws is between running a model locally, which is private but expensive and hard to scale, and the cloud, which is convenient but exposes the data.

What the record does not carry is independent sizing of the pain. The evidence for demand is the founders' argument and customer testimonials, not analyst category data, survey evidence, or a body of incident reporting, so the problem reads as clear and credible but not independently quantified. \[[s5](#profile-analysis-sources), [s1](#profile-analysis-sources)\]

### Product Capabilities

Tinfoil runs AI models inside hardware secure enclaves and lets the customer prove it. Its Private Inference API serves open-source models through an OpenAI-compatible interface, so a developer points an existing client at Tinfoil without a rewrite. Private Chat is a consumer-facing assistant on the web and iOS, and Tinfoil Containers runs any Docker image inside an enclave for custom AI workloads.

The differentiator is that the privacy is verifiable, not just claimed. The hardware generates a signed attestation report, a cryptographic fingerprint of the exact firmware, kernel, and binary running in the enclave, and Tinfoil publishes the security-critical code to GitHub and Sigstore so the fingerprint links to inspectable source. The company's SDKs fetch the expected measurements and check them on every connection, client-side, without a third-party attestation service.

Tinfoil depends on recent hardware advances. Running enclaves on GPUs became practical only after NVIDIA added confidential computing to recent GPUs, and the company published its own Blackwell benchmarks of the performance cost. A partner, Workshop Labs, reports building a production-ready private post-training and inference stack on Tinfoil Containers with less than 10 percent overhead, and Red Hat's emerging-technologies group publicly describes a collaboration with Tinfoil on confidential AI inference for the open-source community. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s8](#profile-analysis-sources), [s12](#profile-analysis-sources)\]

### Competitive Positioning

Tinfoil competes on verifiable privacy against three kinds of rival. Other verifiable-inference startups such as Confident Security, and confidential-computing vendors such as Opaque Systems, chase the same regulated buyer with a similar enclave-and-attestation approach. Tinfoil's distinguishing choice is to open-source its verification stack and publish benchmarks, so a buyer checks the guarantee rather than trusting it.

Platform vendors apply the heavier pressure. Apple built Private Cloud Compute on the same idea for its own devices, and the big cloud and chip vendors all sell confidential computing, so the core capability Tinfoil offers is one those platform vendors can ship themselves. Tinfoil positions itself as the neutral, auditable option, resting its pitch on the open, client-side proof its own documentation details.

The bet is that verifiability, not the enclave, is the durable difference. A rival can rent the same NVIDIA hardware and run the same open models, so Tinfoil relies on a correct, openly auditable attestation stack that a buyer can inspect. \[[s1](#profile-analysis-sources), [s2](#profile-analysis-sources), [s8](#profile-analysis-sources)\]

### Go-to-Market & Traction

Tinfoil has named users, though they are mostly research groups. The homepage carries testimonials from UC Berkeley and The Open Anonymity Project, a Stanford and Michigan effort, both using Tinfoil Containers, and Workshop Labs describes building its Silo product on the platform. These are named references, but academic and early-stage rather than a base of paying regulated enterprises.

The product is self-serve, which supports a bottom-up motion. Private Chat sells at 20 dollars a month, Containers at 20 dollars plus usage, and the inference API is a drop-in a developer can adopt without a sales call. The low price and drop-in interface make Tinfoil easy to try, while the enterprise pitch to regulated industries and government remains an ambition the record does not yet show closing.

Y Combinator backing is the main outside signal. Tinfoil went through the Spring 2025 batch, which is investor conviction at an early stage rather than commercial proof. No revenue, customer count, or enterprise deployment appears in the public record. \[[s1](#profile-analysis-sources), [s8](#profile-analysis-sources), [s4](#profile-analysis-sources)\]

### Team & Credibility

Tinfoil's founders are matched to the narrow problem they chose. Jules Drean holds an MIT PhD in secure hardware and confidential computing and worked at NVIDIA and Microsoft Research on the same, and Sacha holds an MIT PhD in privacy-preserving cryptography. Tanya Verma, a co-founder, was on Cloudflare's cryptography team and worked on its Workers AI platform.

That is deep, verifiable, in-domain expertise. Two doctoral specialists in exactly the hardware and cryptography the product depends on, plus a cryptographer who shipped privacy protocols at Cloudflare scale, is a stronger research pedigree than most companies in this category show. The founders also publish technical work, including the confidential-computing benchmarks, which builds credibility with a technical buyer.

What the record does not show is a prior exit or a company-scale track record. The strength is research and engineering depth rather than a history of building and selling a business, so the team clears the in-domain-expertise bar without reaching the top rung reserved for a category-defining, widely recognized record. \[[s6](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Trust Readiness

Tinfoil holds a real attestation and grounds its trust case in code, not just a policy. Its trust center lists SOC 2 Type 2, and the homepage carries the badge, which is table stakes for selling into regulated buyers rather than a differentiator. The stronger claim is architectural: the customer verifies privacy through hardware attestation instead of trusting the operator.

A customer does not have to trust Tinfoil to trust the result. Because the security-critical code is open source on GitHub and the SDKs check the enclave measurements client-side on every connection, a buyer or an outside expert can confirm what code processed the data rather than accept a promise. Tinfoil deliberately avoids a third-party attestation service, arguing that using one would defeat the point of independent verification.

What the record does not yet carry is production evidence. The privacy mechanism is unusually inspectable, but the deployed evidence is academic, so the public record shows a SOC 2 report and open technical verification without a named regulated-enterprise production reference or an independent audit of the running service. \[[s9](#profile-analysis-sources), [s2](#profile-analysis-sources), [s1](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Confident Security | competes with | Verifiable private-inference startup pursuing the same regulated buyer with encryption and hardware attestation, the closest direct rival to Tinfoil's approach. |
| Opaque Systems | competes with | Confidential-computing platform that runs AI and analytics workloads in secure enclaves, contesting the same enterprise buyer that wants private AI processing. |
| Amazon Web Services | adjacent | Hyperscaler that sells confidential computing and hosts the models enterprises run, positioned to bundle verifiable private inference itself. |
| NVIDIA | adjacent | Supplies the confidential-computing GPUs Tinfoil runs on and could offer private-inference guarantees directly, upstream of Tinfoil. |
| Apple | adjacent | Built Private Cloud Compute on the same verifiable-enclave idea for its own devices, the reference point for the category and a potential entrant for third parties. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (13/21)**

Band guidance: reinforce or reposition. Analyzed 2026-09-10. Scope: whole company.

What makes Tinfoil hard to displace is engineering, not data or lock-in. Confidential AI inference a customer can verify, attestation bound to the exact open-source code in the enclave, is narrow, error-prone work its doctoral founders fit well. The surface spans an OpenAI-compatible API, Private Chat, and Containers on attested GPU infrastructure a funded rival could rebuild and a customer could swap for a compatible endpoint. Platforms apply the heavier pressure. Apple Private Cloud Compute ships, and major cloud and chip vendors sell confidential computing (s8), so the enclave is becoming a platform feature. What the record documents for Tinfoil is verification the customer's own software performs on every connection (s2). That proof, and the team keeping it right, is what lasts.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Tinfoil sells hosted software and APIs, a self-serve inference API, a chat app, and a container product, with no human-judgment or managed-service layer that accepts accountability, so it holds at the software-product level with the confidential-inference cluster. \[[s3](#deep-dive-sources), [s11](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Integrating the SDK and validating attestation create some friction, but the OpenAI-compatible drop-in design lets a customer point the same client at another compatible endpoint, so leaving stays cheaper than a data or residency lock. \[[s3](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | Tinfoil holds a confirmed SOC 2 Type 2, which improves buyer readiness but is table stakes rather than a lock, and no line-specific certification or regulatory mandate blocks a replacement. \[[s9](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Building verifiable confidential inference on GPUs, binding a hardware attestation to open-source code and checking it client-side, is specialized hardware and cryptography work that few teams can execute, level with the confidential-inference cluster at three. \[[s2](#deep-dive-sources), [s8](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | Tinfoil credibly addresses regulated and government buyers but shows no named enterprise deployment, and its self-serve products also court individuals and developers. \[[s5](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Layer | 3/3 | Tinfoil is the inference endpoint an application routes its model calls through, and the container product hosts the workload itself, infrastructure other software depends on rather than an overlay beside it, level with the cluster at three. \[[s3](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The cited record shows no proprietary dataset and no retained cross-customer corpus (the company markets zero data retention), and Tinfoil deliberately open-sources its security-critical code, so a funded rival can rebuild the same stack. \[[s2](#deep-dive-sources), [s8](#deep-dive-sources)\] |

### Strategic Market Segmentation

Tinfoil aims at buyers that privacy has kept off cloud AI. The founders name the regulated enterprise and the government agency whose security review blocks sending sensitive prompts to a model provider, plus startups that sell into those buyers. Its pitch is to let them run frontier models on private data without trusting the operator or the cloud.

A second audience is the individual and the developer. Private Chat targets a person who wants a capable assistant without handing conversations to a provider, and the OpenAI-compatible API targets a developer who can adopt it by swapping an endpoint. That widens the buyer set but blurs which end pays the bills.

A third audience is the AI infrastructure builder. Tinfoil Containers lets a company run its own model or backend in an enclave, which is how Workshop Labs built its Silo product, so Tinfoil also sells to vendors that resell privacy to their own customers. No named regulated-enterprise buyer appears in the public record yet. \[[s5](#deep-dive-sources), [s1](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

Tinfoil's advantage is that a customer can check the privacy, not just receive it. The service runs open models inside a hardware enclave and produces a signed attestation report, a fingerprint of the exact code running inside, with the source published on GitHub, the build measurements recorded in Sigstore, and the fingerprint thereby linked to source anyone can read (s2). The SDKs verify the measurements client-side on every connection.

The design binds the encrypted connection to the enclave itself. Tinfoil puts the enclave's attested public key in the report and stores a hash of the attestation in the server certificate (s2), so a client encrypts directly to the verified enclave and no host can impersonate it. The company avoids a third-party attestation service on the argument that outsourcing the check would undercut it.

The limit is that the moat is method, not data. The record shows no proprietary dataset behind the service, code deliberately opened and zero retention marketed, so the advantage a buyer can inspect is the correctness of the attestation stack rather than an asset a rival cannot obtain. A technical account from Workshop Labs, a partner, corroborates the mechanism and reports less than 10 percent overhead, and Red Hat's emerging-technologies group publicly describes a collaboration with Tinfoil on confidential AI inference. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s8](#deep-dive-sources), [s12](#deep-dive-sources), [s1](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Tinfoil runs a bottom-up motion more than a sales-led one. It ships a self-serve chat subscription, a metered container product, and a drop-in API a developer can adopt without a sales call, so adoption can start without procurement. The enterprise and government pitch that the founders describe is the larger prize but is not yet visible as closed deals.

The proof of demand is named users and partner collaborations. UC Berkeley and The Open Anonymity Project, built at Stanford and UMich, appear as Tinfoil Containers users, and Workshop Labs describes a production-ready stack built on the platform as a public partner. These are early references and partnerships rather than a base of paying regulated enterprises. No revenue or customer count is disclosed.

Y Combinator backing is the strongest outside marker. Tinfoil went through the Spring 2025 batch, which signals investor conviction at an early stage rather than commercial traction. The company's public channel is its documentation, open-source repositories, and a technical blog. \[[s1](#deep-dive-sources), [s8](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Pricing Model

Tinfoil publishes a consumer price, which is unusual for the category and tells a buyer what it thinks it sells. Private Chat is a flat 20 dollars a month, the homepage now also lists Containers at 20 dollars a month plus usage with the API described as usage-based (live 2026-07-17), and the enterprise plan stays unpriced. Publishing entry prices lets a buyer see what the company charges before a sales call.

The published chat price signals a product a buyer can size before talking to sales. A flat consumer subscription lowers the friction of evaluating a young vendor, because a team can estimate the cost of trying Private Chat up front.

The enterprise terms are where the regulated-buyer economics would show, and they are not public. The tier that would carry the thesis is unpriced in the public record, so the pricing that matters most for the enterprise bet cannot be evaluated from it. \[[s11](#deep-dive-sources), [s3](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Product Delivery & Operations

Tinfoil is delivered as hosted infrastructure a customer verifies rather than trusts. The inference API is a drop-in endpoint, Private Chat is available in the browser and on iOS, and Containers runs a customer image inside an enclave, all on hosted confidential-computing infrastructure. The customer's guarantee comes from attestation, not from Tinfoil's operational promises.

The enclave is locked down by design. As Workshop Labs describes it, the image is locked down so that even the party that deployed it cannot get inside, with attestation letting an outside party verify that. The data stays inside the enclave, unreadable to the host and the cloud provider while it is processed.

The operational cost is modest and disclosed in part. Tinfoil and Workshop Labs both report the confidential-computing overhead at less than 10 percent, and Tinfoil published its own Blackwell benchmarks. The Enterprise tier lists SLA guarantees and white-glove support (s11), while a numerical uptime commitment is absent from the fetched pages. \[[s1](#deep-dive-sources), [s8](#deep-dive-sources), [s3](#deep-dive-sources), [s7](#deep-dive-sources), [s11](#deep-dive-sources)\]

### Earning Customers' Trust

Tinfoil grounds trust in verification rather than in a promise. The customer confirms privacy by checking a hardware attestation against open-source code, so the trust model removes the need to rely on Tinfoil's conduct. That is a stronger posture than a self-attested policy for a young vendor handling sensitive data.

The company also holds a conventional attestation. Its trust center lists SOC 2 Type 2, which is table stakes for a regulated buyer rather than a differentiator, and the badge sits on the homepage. The architectural proof is the part the company leads with.

The gap is production evidence, not mechanism. The verification is unusually inspectable, and the named deployments are a partner's production stack (Workshop Labs' Silo, post-training and serving frontier open-weight models on Tinfoil's attested infrastructure, s8) and academic work, so the public record carries a SOC 2 report and open technical verification without a named regulated-enterprise reference or an independent audit of the running service. \[[s9](#deep-dive-sources), [s2](#deep-dive-sources), [s1](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Tinfoil's ecosystem play is open code and an OpenAI-compatible interface. Publishing the security-critical code lets any buyer or researcher audit it, and matching the OpenAI API lets a developer adopt Tinfoil without rewriting an application. Both choices trade lock-in for adoption.

The interface choice cuts two ways. Compatibility makes Tinfoil easy to try, but it also makes the service easy to leave, because a customer can point the same client at another compatible endpoint. Tinfoil is betting that the verification stack, not the interface, is what keeps a buyer.

The platform depends on suppliers upstream. Tinfoil runs on NVIDIA confidential-computing GPUs and on cloud hosts, so its roadmap tracks what those providers ship, and the same providers could offer verifiable private inference themselves. No third-party marketplace or broad integration network appears yet. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Team & Execution Capability

The founders are the clearest asset. Jules Drean holds an MIT PhD in secure hardware and confidential computing and worked at NVIDIA and Microsoft Research, and Sacha holds an MIT PhD in privacy-preserving cryptography. Tanya Verma was on Cloudflare's cryptography team and worked on Workers AI.

The team is built for exactly this product. Confidential inference combines trusted hardware and applied cryptography, and the founders hold doctoral depth in both, plus production experience shipping privacy protocols at Cloudflare scale. That match is the strongest credibility signal the company carries.

The cited company and YC pages emphasize research and engineering depth rather than a prior exit or a standards-authorship reputation. That leaves the credibility coming from expertise rather than a track record that would itself pull adopters. \[[s6](#deep-dive-sources), [s5](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Tinfoil documentation (what Tinfoil provides)](https://docs.tinfoil.sh/introduction) | official | 2026-07-04 |
| f2 | [Y Combinator: Tinfoil, Spring 2025 batch](https://www.ycombinator.com/companies/tinfoil) | other | 2026-07-04 |
| f3 | [Tinfoil (AI Defense Matrix Catalog mapping)](https://catalog.aidefensematrix.com/products/tinfoil) | other | 2026-07-04 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Tinfoil homepage (products, named users, SOC 2 and open-source badges)](https://tinfoil.sh) “Darya Kaviani, UC Berkeley. When building The Open Anonymity Project at Stanford and UMich, we were using Azure's confidential containers. We can do the same thing on Tinfoil Containers in under 20 minutes.” | official | 2026-07-04 |
| s2 | [Tinfoil documentation on how verification works (attestation, GitHub, Sigstore)](https://docs.tinfoil.sh/verification/verification-in-tinfoil) “The hardware measures the initial state, generating a signed attestation report of the exact launch configuration. All the code running inside the enclave is published to our GitHub. Our SDKs automatically fetch the expected enclave measurements from GitHub and Sigstore and verify.” | official | 2026-07-04 |
| s3 | [Tinfoil Private Inference (OpenAI-compatible API, attested enclave)](https://tinfoil.sh/inference) “Each API connection is automatically verified and encrypted directly to an attested secure enclave, and is compatible with the OpenAI API standard, making it a drop-in replacement for most existing deployments and workflows.” | official | 2026-07-04 |
| s4 | [Y Combinator: Tinfoil (Spring 2025 batch, San Francisco, active)](https://www.ycombinator.com/companies/tinfoil) “Tinfoil Encrypted AI with verifiable privacy Y Combinator Logo Spring 2025 Active Artificial Intelligence Developer Tools Security Privacy Cloud Computing San Francisco” | other | 2026-07-04 |
| s5 | [Tinfoil YC launch (problem, founder backgrounds, mechanism)](https://www.ycombinator.com/launches/NZ8-tinfoil-verifiable-privacy-for-cloud-ai) “Sick of deals getting stalled during enterprise or government security reviews? We are Tanya, Jules, Sacha and Nate. Jules did his PhD in confidential computing at MIT, Sacha did his PhD in privacy-preserving cryptography at MIT, and I (Tanya) was on Cloudflare's cryptography team.” | other | 2026-07-04 |
| s6 | [Tinfoil company page (founding team backgrounds)](https://tinfoil.sh/company) “Jules holds a PhD from MIT in secure hardware and systems. Jules has industry experience working at Microsoft Research and NVIDIA. Tanya is an ex-Cloudflare engineer and researcher, and contributed to Cloudflare's Workers AI platform.” | official | 2026-07-04 |
| s7 | [Tinfoil blog (NVIDIA Blackwell confidential-computing benchmarks, active 2026)](https://tinfoil.sh/blog) “How does NVIDIA Confidential Computing impact inference and training performance? Benchmarks of confidential computing overhead on NVIDIA Blackwell. Tanya Verma and Jules Drean, June 23, 2026. How Does Tinfoil Compare to Apple Private Cloud Compute?” | official | 2026-07-04 |
| s8 | [Workshop Labs on building Silo with Tinfoil (partner technical writeup, coauthored)](https://www.workshoplabs.ai/blog/private-post-training) “Workshop Labs has collaborated with Tinfoil to build Silo. The performance cost for both post-training and inference is less than 10%. CPU-based TEEs such as Intel TDX, AMD SEV-SNP and AWS Nitro Enclaves have been around for a while. Apple uses them for Private Cloud Compute.” | press | 2026-07-04 |
| s9 | [Tinfoil trust center (SOC 2 Type 2, rendered 2026-07-04)](https://trust.tinfoil.sh) “Frameworks SOC 2. Security and compliance documentation. COMPLIANCE SOC 2 Type 2” | official | 2026-07-04 |
| s10 | [Tinfoil in the AI Defense Matrix Catalog (matrix coverage)](https://catalog.aidefensematrix.com/products/tinfoil) “Processes prompts and responses inside hardware secure enclaves that even the provider cannot access, keeping inference data confidential and verifiable through remote attestation. Loads and runs model weights inside the secure enclave so they are not exposed during inference.” | other | 2026-07-04 |
| s11 | [Tinfoil pricing (Private Chat, API, Containers, Enterprise tiers)](https://tinfoil.sh/pricing) “Private Chat A powerful AI assistant that keeps all your data private. $20/month. Up to 2M tokens/hour. ChatAPIContainersEnterprise” | official | 2026-07-04 |
| s12 | [Red Hat Emerging Technologies: Enhancing AI inference security with confidential computing](https://next.redhat.com/2025/10/23/enhancing-ai-inference-security-with-confidential-computing-a-path-to-private-data-inference-with-proprietary-llms/) “Red Hat and Tinfoil are investigating how to combine existing security technologies to solve this problem” | press | 2026-07-04 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Tinfoil homepage (products, named users, SOC 2 and open-source badges, Kaviani testimonial re-captured verbatim)](https://tinfoil.sh) “Running our own custom Docker container on Tinfoil Containers is a major unlock. It lets us run our full end-to-end system in trusted hardware using the same simple Python SDK we already use to call Tinfoil's embedding and LLM models.” | official | 2026-07-17 |
| s2 | [Tinfoil documentation on how verification works (attestation, GitHub, Sigstore)](https://docs.tinfoil.sh/verification/verification-in-tinfoil) “The hardware measures the initial state, generating a signed attestation report of the exact launch configuration. All the code running inside the enclave is published to our GitHub. Our SDKs automatically fetch the expected enclave measurements from GitHub and Sigstore and verify.” | official | 2026-07-04 |
| s3 | [Tinfoil Private Inference (OpenAI-compatible API, attested enclave)](https://tinfoil.sh/inference) “Each API connection is automatically verified and encrypted directly to an attested secure enclave, and is compatible with the OpenAI API standard, making it a drop-in replacement for most existing deployments and workflows.” | official | 2026-07-04 |
| s4 | [Y Combinator: Tinfoil (Spring 2025 batch, San Francisco, active)](https://www.ycombinator.com/companies/tinfoil) “Tinfoil Encrypted AI with verifiable privacy Y Combinator Logo Spring 2025 Active Artificial Intelligence Developer Tools Security Privacy Cloud Computing San Francisco” | other | 2026-07-04 |
| s5 | [Tinfoil YC launch (problem, founder backgrounds, mechanism)](https://www.ycombinator.com/launches/NZ8-tinfoil-verifiable-privacy-for-cloud-ai) “Sick of deals getting stalled during enterprise or government security reviews? We are Tanya, Jules, Sacha and Nate. Jules did his PhD in confidential computing at MIT, Sacha did his PhD in privacy-preserving cryptography at MIT, and I (Tanya) was on Cloudflare's cryptography team.” | other | 2026-07-04 |
| s6 | [Tinfoil company page (founding team backgrounds)](https://tinfoil.sh/company) “Jules holds a PhD from MIT in secure hardware and systems. Jules has industry experience working at Microsoft Research and NVIDIA. Tanya is an ex-Cloudflare engineer and researcher, and contributed to Cloudflare's Workers AI platform.” | official | 2026-07-04 |
| s7 | [Tinfoil blog (NVIDIA Blackwell confidential-computing benchmarks, active 2026)](https://tinfoil.sh/blog) “How does NVIDIA Confidential Computing impact inference and training performance? Benchmarks of confidential computing overhead on NVIDIA Blackwell. Tanya Verma and Jules Drean, June 23, 2026. How Does Tinfoil Compare to Apple Private Cloud Compute?” | official | 2026-07-04 |
| s8 | [Workshop Labs on building Silo with Tinfoil (partner technical writeup, coauthored)](https://www.workshoplabs.ai/blog/private-post-training) “Workshop Labs has collaborated with Tinfoil to build Silo, a production-ready multi-GPU private post-training and inference stack for frontier models. The performance cost for both post-training and inference is less than 10%. No one can get in from the outside, even the one who deployed it.” | press | 2026-07-04 |
| s9 | [Tinfoil trust center (SOC 2 Type 2, rendered 2026-07-04)](https://trust.tinfoil.sh) “Frameworks SOC 2. Security and compliance documentation. COMPLIANCE SOC 2 Type 2” | official | 2026-07-04 |
| s10 | [Tinfoil in the AI Defense Matrix Catalog (matrix coverage)](https://catalog.aidefensematrix.com/products/tinfoil) “Processes prompts and responses inside hardware secure enclaves that even the provider cannot access, keeping inference data confidential and verifiable through remote attestation. Loads and runs model weights inside the secure enclave so they are not exposed during inference.” | other | 2026-07-04 |
| s11 | [Tinfoil pricing (Private Chat, API, Containers, Enterprise tiers)](https://tinfoil.sh/pricing) “Private Chat A powerful AI assistant that keeps all your data private. $20/month. Up to 3M tokens/hour. ChatAPIContainersEnterprise” | official | 2026-07-17 |
| s12 | [Red Hat Emerging Technologies: Enhancing AI inference security with confidential computing](https://next.redhat.com/2025/10/23/enhancing-ai-inference-security-with-confidential-computing-a-path-to-private-data-inference-with-proprietary-llms/) “Red Hat and Tinfoil are investigating how to combine existing security technologies to solve this problem” | press | 2026-07-04 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
