Skip to content

Confidential AI

Train and run AI.
Keep your data private.

Run training and inference in confidential hardware that protects your data and models while they’re in use. Verify the software and control what it can share.

Docker deployments

Run your container in confidential hardware.

Use your own application or a vendor’s Docker container. Verify the code and control which services it can connect to.

Confidential virtual machine
Your applicationDocker container
Network proxyChecks allowed destinations
Permitted servicesAccounts, tools & APIsOutside the confidential runtime
The application and network policy are part of the same measured release.
  1. 01

    Choose your software.

    Select an exact Docker image version, the data it needs, and the services it can reach.

  2. 02

    Approve changes on-chain.

    Changing the code or permitted connections requires a new release and on-chain approval.

  3. 03

    Check before connecting.

    Use hardware attestation to confirm that the running software matches an approved release.

Training & inference

Keep data private
while models use it.

Training & fine-tuning

Keep datasets and model weights inside the confidential runtime during training. Decide who can receive the trained model.

Inference

Process prompts and private context inside confidential hardware. Control where responses go and what gets retained.

Connections & data controls

Decide what gets in.
And what gets out.

Connect to accounts, tools, and services without giving the application unrestricted network access.

01

Accounts & credentials

Connect private databases, business accounts, and MCP tools using credentials stored in the confidential runtime.

02

Shared network controls

The proxy runs in confidential hardware, with its code and connection rules verified against on-chain approval. Your organization and software provider can approve changes together. Lit or an independent party can operate the hardware without gaining control over those rules.

03

Responses & logs

Your code determines what the application sends or saves. Review it alongside the network rules.

Working with Lit

Tell us what
you want to run.

Share your model, the data it needs, and your performance goals. We’ll help you choose suitable hardware and plan the deployment.

Contact for Lit AI

Common questions.

What if my application calls an external model?
The provider can see the data your application sends to it. To protect the model’s execution with confidential hardware, the model itself must run inside that hardware.
What can I verify?
You can check which software is running and whether it has on-chain approval. This does not prove that a model’s answers are correct. Model weights downloaded separately also need to be checked against the version you expect.
Which models and hardware are supported?
Contact us with your model and performance requirements. We’ll confirm hardware compatibility and availability before planning a deployment.
Can I start from the crypto dashboard?
Contact the Lit team to set up AI training or inference. The self-serve dashboard is for crypto automation.

Build with Lit

Bring your AI workload to Lit.