ENCLAVE LIVE FIG.01 · DOCTUS · v 0.1 · TUE · 10:36 UTC · TARGON SN4
§ 00 · OVERVIEW

PRIVATE ALPHA · CONFIDENTIAL FINE-TUNING · TARGON CONFIDENTIAL GPUs



Doctus fine-tunes inside a sealed hardware enclave on Intel TDX + NVIDIA H200 confidential compute. Your training data is decrypted only inside the room. The trained adapter is encrypted to a key only you hold. We hold ciphertext and nothing else.

MODELS TRAINED
— —
CIPHERTEXT BYTES IN
— —TB
PLAINTEXT BYTES READ
0B
ATTESTATIONS SIGNED
— —
— THESIS

Every other fine-tuning service sees your data.
This one cannot.

The privacy is not a policy. It is a property of the hardware: Intel TDX seals memory and CPU state; NVIDIA Protected PCIe encrypts the bus. Inside the room, the model trains on plaintext. Outside the room, there is only ciphertext.

We sit outside the room. We do not hold the key. We have nothing to hand over because nothing was ever ours to hold. The math, not the marketing, makes this true.

§ 01 · SEQUENCE

THE TRAINING PIPELINE

01 · DATASET your data encrypted to attested key X25519 → enclave 02 · ENCLAVE sealed room TDX + H200 CC LoRA r=16 · Qwen3-32B attest 0xc0fee1… verified live 03 · ADAPTER trained weights encrypted to your key downloaded · or deployed 04 · INFERENCE sealed serverless CNTR · OpenAI-compatible nothing observable from outside the room SEALED PERIMETER TDX · H200
§ 02 · PRINCIPLES

Three guarantees. Each one provable.

I · DATASETSHALL

The trainer cannot read the dataset.

Your data exists only as ciphertext on Doctus-operated systems. The plaintext is defined only inside the attested enclave.

D  =  ciphertext on our servers
plaintext(D)  =  defined only inside E
Doctus  ∉  E
II · ADAPTERSHALL

The trainer cannot read the adapter.

The trained weights are encrypted to your wallet's public key inside the enclave, before egress. We never hold your private key.

A  =  result of train(D)
egress(A)  =  enc(A, pubkey(you))
Doctus does not hold privkey(you)
III · PROMPTSSHALL

The host cannot read the prompts.

Inference runs in a second confidential enclave with no plaintext logging. End-user prompts and completions are sealed at rest and in motion.

P  =  user prompt
infer(P, A)  =  runs in CNTR enclave E′
Doctus  ∉  E′,  no logging in E′
§ 03 · PRICING

Priced like a spec.

No subscriptions, no seat fees, no idle GPU charges. Settle in TAO at oracle rate.

FIRST RUN
Free
First LoRA fine-tune, small dataset (≤ 100k examples).
STANDARD
$5
≤ 1M training tokens. Typical 1–4 h on a confidential H200.
EXTENDED
$25
≤ 10M training tokens. Typical 8–16 h on a confidential H200.
HOSTING
$0.50/M tok
Sealed serverless inference. Pay per token, no idle GPU charge.