Doc. TMF-004 · Rev 2026.08 Service Specification Classification: Open Sheet 4 of 6

Service Spec · Confidential AI

Run AI on data that cannot leave the building

Frontier-class models applied to your most sensitive data, executing inside hardware enclaves where neither we, nor your cloud provider, nor a model vendor can see it.

Section 01 · Definition

What is Confidential AI?

Most AI adoption stalls at the same wall: the data that would make the model useful is the data you are not permitted to send anywhere. Confidential AI removes that wall by running inference and retrieval inside a hardware trusted execution environment. Data stays encrypted in use, not merely at rest and in transit, and remote attestation lets you prove, cryptographically, which code touched it. Your model weights are protected on the same terms, so proprietary fine-tunes can be deployed onto infrastructure you do not control.

Fig. 01 Encrypted at rest, in transit, and in use.

The Equation

Encrypted at rest
+
Encrypted in transit
+
Encrypted in use
=
Trustless AI

Section 02 · Benefits

What you get

Use the data you cannot export

Patient records, well telemetry, trading positions, IP-bearing documents: put them to work without them ever leaving a boundary you control.

Protect your model IP

Fine-tuned weights stay encrypted on hardware you do not own, so a model can be deployed to a customer site without being handed over.

Attestation you can audit

Remote attestation produces cryptographic evidence of exactly which code and configuration processed the data. Evidence, not assurances.

No third-party data exposure

Prompts, retrieved context, and outputs never reach a model vendor's logs. The trust boundary ends at your enclave.

Runs at the edge

The same architecture deploys to a rig, a plant, or a substation, where bandwidth is thin and the data has regulatory reasons to stay put.

A defensible compliance story

GDPR, HIPAA, SOC 2, and data-residency reviews go materially faster when the answer is a hardware guarantee.

Section 03 · Scope

Our comprehensive offering

Enclave platform

  • Confidential compute on Intel SGX and TDX, AMD SEV-SNP, or confidential GPUs
  • Kubernetes-based orchestration with a confidential service mesh
  • Remote attestation, key management, and policy enforcement
  • Secure provisioning of models and secrets into the enclave

Private inference and retrieval

  • Model serving inside the enclave with vLLM or Triton
  • Retrieval over an encrypted vector store, with citation fidelity preserved
  • Prompt, context, and output handling that never leaves the boundary
  • Throughput and latency tuning under enclave overhead

Assurance and audit

  • Attestation reports wired into your compliance evidence
  • Tamper-evident audit logging of every inference
  • Key rotation, revocation, and break-glass procedures
  • Threat modelling for side channels and data egress

Section 04 · Engagement Model

Two ways to fly

Build and Transfer

We build the capability and then hand it over to your team, documented and running.

Build and Operate

We build it and keep running it, on a fixed-price subscription.

Pricing

Scalable without sacrificing affordability

Tiered on the number of enclaves, models, and environments under management, so cost tracks the estate you actually run, not hours spent.

Fig. 02 Pricing tracks the estate under management.

Section 05 · Technology

The stack we reach for

Enclaves & hardware
Intel SGXIntel TDXAMD SEV-SNPConfidential GPUs
Runtime & orchestration
GramineMarbleRunKubernetesConfidential service mesh
Inference & retrieval
vLLMTritonpgvectorHybrid search + rerank
Keys, policy & evidence
Remote attestationHashiCorp VaultOPASigstore

Section 06 · Why Us

Why choose The Moonshot Factory

We did not arrive at confidential computing through AI. We built a full confidential edge deployment for an oil & gas software provider, porting applications and compute onto enclave hardware at customer sites, with a CI/CD pipeline that configures and tests inside the secure enclave and encryption protecting code, data, and configuration. Confidential AI is that same architecture with a model in the middle.

Get Started Today →

Fig. 03 Same practices we preach, on every project we run.

Section 07 · Contact

Want to build a rocketship?

Contact Us →