Skip to content
Hardware-isolated by default

Security for shared
GPU compute

Encrypted upload, host attestation, isolated execution, and teardown for shared GPU compute.

AES-256
at rest + transit
Isolated
single-tenant GPUs
SOC 2
readiness work
Audit
append-only logs

$

Security baked into every layer

From the silicon up to your API token - here's what keeps a two-sided GPU marketplace trustworthy.

Hardware attestation

Every host proves its identity and firmware state via TPM attestation before a workload is scheduled onto it.

Append-only audit

Every provision, access, and payout is written to a tamper-evident, append-only log. Exportable for your own compliance.

Encryption everywhere

AES-256 at rest, TLS 1.3 + mTLS in transit. Datasets and checkpoints are encrypted with keys you can bring yourself (BYOK).

Least-privilege access

SSO, scoped API tokens, and role-based access control so people and services only ever touch what they need.

Single-tenant GPUs

Your job gets dedicated, attested hardware. Never oversubscribed, never sharing VRAM with another tenant. The device is wiped between renters.

Vetted both sides

Provider listings should pass identity and automated checks before reaching paid demand; renter access remains constrained by platform controls.

Tenant isolation

How a shared host stays private

Watch a job land on an attested host and get sealed into its own encrypted sandbox. While the neighbors stay completely walled off.

host · h100-us-east-01 attested
GPU 0tenant
GPU 1tenant
GPU 2tenant
GPU 3you
GPU 4tenant
GPU 5tenant
GPU 6tenant
GPU 7tenant
your sandbox walled-off tenants
attest.logprovisioning

Encryption in action

Encrypted end to end. With keys you control

Hover a line to watch it resolve. Your data is sealed at rest and in transit; bring your own keys and we never hold them in the clear.

Dataset at rest
9F3A2C7E11B8D4A0 · AES-256-GCM
In transit
TLS 1.3 · mTLS · A1B2C3D4E5F6
Your key (BYOK)
kms://you · sealed · 7C4E9A02

Shared responsibility

Who secures what

Security is a partnership. We lock down the platform and the hardware underneath your workloads. You stay in control of your data and who can touch it. No grey areas.

Kracht secures

The platform & the hardware

  • Physical data-center and host security
  • Hardware (TPM) attestation before scheduling
  • Single-tenant GPU & encrypted-sandbox isolation
  • Network encryption. TLS 1.3 + mTLS, egress allowlists
  • Secure device wipe and re-attestation between renters
  • Platform monitoring, abuse controls, and DDoS protection

You control

Your data & your access

  • Your code, models, and datasets
  • Encryption keys, if you bring your own (BYOK)
  • Team access. SSO, roles (RBAC), and API token scopes
  • Which regions and host classes your jobs run on
  • What you choose to expose on a public endpoint
  • Exporting and retaining your own audit logs

Compliance

Compliance status, clearly labeled

We track the standards enterprises ask about, and label what is complete, in flight, planned, or still under review.

SOC 2 Type IIIn progress
ISO 27001Roadmap
GDPRReview needed
HIPAAReview needed
CCPAReview needed

Everyday practices

  • Encryption at rest (AES-256) and in transit (TLS 1.3 + mTLS)
  • Bring-your-own-key (BYOK) for datasets and checkpoints
  • Hardware wiped and re-attested between every renter
  • Independent third-party penetration tests, annually
  • Coordinated disclosure program for security researchers

Two sides, one marketplace

Spin up the GPUs you need - or earn from the ones you already own

Rent on-demand compute by the second, or list idle hardware and let it pay for itself. Same marketplace, both directions.

Join 12,000+ builders / $5 free credit / no card required

Stay in the loop

Product updates and early access to new GPU classes. No spam.