Hosted in the EU
Hardware-enforced confidentiality
Verifiable through remote attestation
No operator access by design

Sovereign AI
without the trade-off.

Leading open models, run in the EU, with your data encrypted in memory
even during processing, enforced by hardware rather than by contract.

Why Confidential AI
Digital sovereignty

Where the data sits is one question.
Who can read it is another.

A location is not a guarantee

Moving AI workloads to a European data center changes the jurisdiction and the network path. It does not change who holds the plaintext. In a conventional setup, the operator of the machine can read prompts, files, and responses while they are being processed, wherever that machine stands. Sovereignty that stops at the hosting location leaves the decisive question open.

Enforced by hardware, not by policy

Privatemode processes your data inside hardware-isolated environments whose memory stays encrypted. By design, neither the infrastructure provider nor Privatemode can access the content.

Checkable, not just promised

The client requests an attestation report from the hardware and verifies it against expected measurements before it sends any data. This happens on every session, automatically.

Use cases

What sovereignty-bound teams do with Privatemode

Document and case work

Summarize files, contracts, and reports, and draft responses with the full context, without handing that context to a foreign AI provider.

Coding assistance

Give engineering teams a coding assistant through an OpenAI-compatible API, so source code and configuration stay confidential.

Translation and plain language

Translate documents and rewrite them in plain language, including material that must not leave your control.

Products for regulated customers

Build AI features into software for public agencies, defense, energy, and finance, and answer the confidentiality question with a mechanism rather than a clause.

Comparison

Privatemode: control without
giving up model quality.

 

  • Model quality
  • Plaintext access
  • Verifiability
  • Setup time

Privatemode

Leading open models, run in the EU, with confidentiality enforced by confidential computing and open to remote verification.

  • Leading open models
  • Excluded by design
  • Remote attestation
  • Minutes

Foreign frontier AI

The strongest models, but prompts and files are processed in plaintext on the provider's servers, under a foreign jurisdiction.

  • Frontier models
  • Provider holds it
  • Contractual only
  • Minutes

Air-gapped or self-hosted

Full control over the machine, paid for with hardware, operations staff, and a narrower choice of models.

  • Limited by your hardware
  • Stays with you
  • You have to build it
  • Weeks to months
FAQ

Frequently asked questions about sovereign AI

EU hosting settles the jurisdiction and the network path, and for many organizations it is a requirement. It does not settle who can read the data while it is being processed. In a conventional deployment, the operator of the machine can. Privatemode runs in the EU and removes that access on top. Processing happens inside hardware-isolated environments whose memory stays encrypted, so by design the plaintext is not available to the infrastructure provider or to Privatemode (Edgeless Systems).

Want to see Privatemode in action?

We're happy to show you around and give an overview of what's possible.