platoseed
← All companies
Tinfoil logo

Tinfoil

Active

Encrypted AI with verifiable privacy

Spring 2025Founded 20245 peopleSan Francisco, CA, USA

About

Tinfoil makes it easy to make your AI workloads secure and provably private. You get the privacy of on-prem deployments, while running on the cloud. It's like end-to-end encrypted messaging but for your AI applications. We’ve built a full-stack platform on top of the latest NVIDIA GPUs offering confidential computing capabilities, meaning that you don’t have to trade off performance for privacy. We integrate a suite of recent advances in secure hardware technologies, in particular NVIDIA’s confidential compute mode available on Hopper and Blackwell. When combined with Tinfoil’s software stack, companies can prove their security claims like "we can't see and don’t log your queries.” Tinfoil guarantees that all data always stays private and cannot be accessed by anyone other than the end user -- not even by Tinfoil or the cloud provider it’s processed on. Everything can be made end-to-end encrypted and private with Tinfoil. The founding team combines deep academic and industry experience in security and Internet protocols. Tanya was previously a systems engineer at Cloudflare, where she built Internet security protocols used by billions, and contributed to the Workers AI platform. Jules and Sacha hold PhDs from MIT, where they worked on secure hardware, cryptography, and privacy technologies. Jules has also worked at NVIDIA on their confidential computing team. Tinfoil was born from our personal frustration with the false choice between access to powerful AI and the massive data privacy implications of deeply integrated AI. AI is a universal tool that becomes part of our personal lives and business workflows. In the process, it needs access to all personal, private, and proprietary data. Right now, the only solutions are data processing agreements (i.e., "pinky promises"), band-aids like PII redaction that don't work in practice, or AI locally/on-prem, which doesn't scale. Tinfoil promises to unlock significantly deeper AI adoption and integrations by making it easy to obtain true privacy, just as TLS on the Internet enabled e-commerce to flourish by securing credit cards on the network. Today we offer several self-serve products: - A consumer-facing chatbot that keeps your chats end-to-end encrypted and provides zero-access inference with powerful open-source models like Kimi, Gemma, and GLM. You can try it out for free: https://chat.tinfoil.sh - A developer-friendly API that allows you to build AI applications where all user data is kept private and we as the inference provider cannot see any of the prompts. Our SDKs make sure that all relevant security measures are checked for you before even sending a single byte of data. Learn more:https://docs.tinfoil.sh - An advanced confidential computing platform we call Tinfoil Containers that allows you to secure any Docker application. We make it easy to deploy your own logic and applications inside secure enclaves and prove to the world what code is running inside. This enables attested workloads and publicly verifiable privacy policies for sensitive applications. Learn more: https://tinfoil.sh/containers

From their website

as of Jun 7, 2026tinfoil.sh
SubscriptionSubscription · Chat product priced at $20 / month with features including generous rate limits, project access, web search, multi-device sync, and speech-to-text; GPU access pricing exists via request, but explicit tiered pricing beyond the $20/mo note is not provided in the text.

Tinfoil provides private AI that runs in secure hardware enclaves to keep data private while providing AI capabilities. It offers an open-source, verifiable software stack with chat, private inference APIs, and containerized workloads for confidential computing.

Services include Private Chat (conversations private), Private Inference API (OpenAI-compatible, verifiable privacy for AI apps), and Tinfoil Containers (run any Docker image in a secure enclave). The platform emphasizes data processing in secure enclaves, verifiability, and compatibility with OpenAI interfaces; it also highlights on-prem-like privacy with cloud-like power and provides multi-model support (open-source and proprietary models) plus integration via a Python/JavaScript/Swift/Go/Rust API client.

Who it’s for: Teams and developers needing private, verifiably private AI workloads; organizations requiring confidential computing for chat, inference, or custom AI applications.

Features
  • Private Chat with verifiable privacy
  • OpenAI-compatible Private Inference API
  • Tinfoil Containers for secure enclave workloads
  • Open-source, verifiable software stack
  • Multi-model support (GPT-OSS, Kimi, Gemma, Llama, etc.)
  • On-prem/privacy-first data handling
  • Cross-language SDKs (Python, JavaScript, Swift, Go, Rust)

Pricing page present; product pages for Chat, Inference, and Containers; collaborations and case studies referenced (Llama case study, Red Hat collaboration, Ubuntu foundation) indicating industry engagement and ongoing development.

Founders · 3

Tanya Verma
Tanya VermaFounder
UIUC

Co-founder @ Tinfoil | Systems, Cryptography and AI @ Cloudflare | CubeSats & CS @ UIUC

Jules Drean
Jules DreanFounder
MicrosoftNvidiaMIT

Jules has an MIT PhD in secure hardware and confidential computing. He has industry experience working at Microsoft Research and NVIDIA on the technologies underlying Tinfoil. During his PhD, Jules has built secure enclaves from the ground up and studied how to attack and defend these systems against advance microarchitectural attacks. His work also looked at using trusted hardware to securely deploy advanced cryptographic primitives such as FHE and MPC.

Sacha Servan-Schreiber
Sacha Servan-SchreiberFounder
MIT

Co-founder of Tinfoil | PhD at MIT in cryptography Personal website: sachaservanschreiber.com

Launch

Launched on Y Combinator · May 2025
View launch post ↗

We host models and AI workloads on the cloud while guaranteeing zero data access and retention

Tinfoil launches a cloud hosting solution for AI models that guarantees zero data access and retention, enabling confidential LLM inference on cloud GPUs via secure enclaves. It targets regulated industries, government, and enterprises seeking privacy-preserving AI workloads without fully trusting the cloud provider.

Website over time

How Tinfoil’s homepage introduced itself over the years — each line is the page title the web actually saw, linked to that moment’s archived capture.

  1. 2024Tinfoil
  2. 2025Tinfoil - Provable AI Security
  3. 2026Tinfoil - Private AI
  4. Nowtinfoil.sh

Browse every capture in the Wayback Machine ↗

B2BSecurityArtificial IntelligenceDeveloper ToolsSecurityPrivacyCloud Computing

Featured in themes

Related startups

Also in Spring 2025