The Perfect Storm for Edge AI – And the Question Nobody Is Asking
May 11, 2026
A New Side-Channel Attack Can Reconstruct AI Models Through Walls
May 28, 2026

DataKrypto Integrates Intel® Trust Authority into FHEnom for AI™ to Deliver Verifiable Confidential AI from Silicon to Application

By Ravi Srivatsav, Co-Founder and CEO, DataKrypto  

Confidential AI depends on two properties holding at the same time: the environment that handles cryptographic material has to be the one it claims to be, and the data and model under computation are designed to remain encrypted during processing. Encrypted execution, implemented through FHEnom for AI™, addresses the second property by keeping prompts, embeddings, activations, and weights protected as ciphertext across CPU, bus, and GPU. The first property is the role of attestation, which must prove that the environment hosting key custody and tokenization is genuine, current, and unmodified. 

Today, DataKrypto is integrating Intel® Trust Authority into FHEnom for AI™ to provide that attestation across the full chain: the Intel® TDX hardware platform, the guest operating system, and the FHEnom for AI™ application itself.

The result is a verifiable trust path from silicon to application, evaluated independently of the cloud operator, before any session key is released. 

For enterprises in healthcare, financial services, defense, and other sensitive sectors, this changes what is possible. AI workloads that previously required air-gapped infrastructure can now run on cloud and multi-tenant environments, with cryptographic evidence they control and auditors can verify. 

“With this integration, we move from asserted trust to cryptographically verified trust. Enterprises can now verify, before any key is released, that their AI workloads are running on genuine Intel® TDX hardware with approved operating system and FHEnom for AI software measurements,” said Ravi Srivatsav, Co-Founder and CEO of DataKrypto. 

Encrypted AI Execution: Confidential Computing to Confidential AI 

Traditional confidential computing secures infrastructure boundaries. Confidential AI requires protecting the data, models, and inference pipeline themselves. 

FHEnom for AI™ builds on Intel’s TEE capabilities to enable continuously encrypted AI processing, keeping prompts, embeddings, model weights, and sensitive runtime operations protected as ciphertext throughout the AI lifecycle. Plaintext does not appear inside the guest OS or in VRAM. 

Computation operates directly on ciphertext, so prompts, embeddings, activations, and model weights remain protected across the CPU, memory bus, and GPU. Plaintext is designed not to appear  inside the guest OS or in VRAM under the expected operating model. 

Combining Intel® Trust Domain Extensions (TDX) with encrypted execution, DataKrypto enables enterprises to run sensitive and regulated AI workloads in cloud and multi-tenant environments with security properties designed to help replicate key confidentiality controls previously associated the air gapped on premises infrastructure. 

Intel® Trust Authority: Independent Verification at Scale 

Intel® Trust Authority is a SaaS-based, third-party remote attestation service that provides cryptographic verification of Trusted Execution Environments at cloud scale, independently of the cloud operator. It moves trust from an internal assumption to an externally verifiable control. 

Integrated into FHEnom for AI™, Intel® Trust Authority gates every session, verifying the full stack before any wrapped session key is released. 

Layered verification: From Silicon to Application 

The combined architecture integrates encrypted execution with attestation across each verified layer. Before any wrapped session key is released, Intel® Trust Authority verifies three layers:  

Layer 

What Is Verified 

What This Establishes 

Hardware and TDX module 

Genuine Intel CPU, TDX firmware version, Trust Domain launch measurements 

The enclave runs on real Intel TDX silicon, not an emulated or downgraded environment 

Guest operating system 

Boot integrity of guest OS image, kernel, and initramfs measurements 

No unauthorized OS, driver, or kernel module was loaded before key-management services started 

FHEnom for AI™ application 

Cryptographic identity of the key broker and tokenizer binaries 

The workload requesting the wrapped session key is the exact, unmodified FHEnom application 

If wrapped session key is not released, and the workload does not run. The design does not include a policy exception path or a manual override mechanism. The failure mode is structural. 

How a session begins: 

  1. The TDX-protected VM hosting the FHEnom for AI™ key broker boots. Hardware, TDX module, guest OS, and the FHEnom application produce measurements as they load. 
  2. The FHEnom application requests a wrapped session key from the customer’s key management system and presents an attestation quote covering the full chain. 
  3. The key management system forwards the quote to Intel® Trust Authority, which independently verifies that the quote was produced by genuine Intel TDX silicon and that measurements match the customer’s policy for hardware, OS, and application identity. 
  4. Intel® Trust Authority returns a signed attestation token. If the token passes policy evaluation, the key management system releases the session key, wrapped to a public key bound to the attested Trust Domain. 
  5. Inside the Trust Domain, FHEnom for AI™ unwraps the session key, performs encrypted tokenization at the trust boundary, and execution proceeds on ciphertext across the computation. Embeddings, weights, and activations remain encrypted across the bus and in VRAM. Plaintext is designed not  to appear inside the guest OS or on the GPU under the expected operating model.  

 Industry Applications 

DataKrypto serves organizations across sectors where both confidentiality and verifiability are requirements, not preferences: 

  • Government and Critical Infrastructure: Public-sector agencies require demonstrable assurance that sensitive AI workloads are designed to help protect against unauthorized access or tampering. The integrated platform enables independent cryptographic verification of the full execution environment, supporting zero-trust principles and auditability for defense and critical infrastructure use cases. 
  • Regulated AI Workloads: Healthcare, financial services, and life sciences organizations can run AI workloads, including training, fine-tuning, and production deployment on sensitive data, while maintaining strict confidentiality. 
  • Sovereign and Multi-Tenant Deployments: Enterprises and government organizations requiring data sovereignty can deploy AI on shared infrastructure while maintaining cryptographic isolation, encrypted execution, and independent verification of the environment processing their data. 
  • AI Model Builders Protecting IP: Organizations developing proprietary models can deploy on cloud infrastructure with cryptographic verification designed to help ensure model weights remain encrypted during execution and that the environment running them is verified before any wrapped session key is released. 

Conclusion 

Confidential AI is not delivered by any single technology. It is a chain of properties that must hold simultaneously: the silicon must be genuine, the operating system must be intact, the application must be the authorized one, the keys must be released only into that proven environment, and the data and model are designed to remain encrypted during computation.  A break in any link reduces the rest to assurance. 

With Intel® TDX and Intel® Trust Authority attesting the hardware, the operating system, and the FHEnom for AI™ application, and with FHEnom for AI™ keeping prompts, model weights, embeddings, and activations encrypted across CPU, bus, and GPU, that chain becomes verifiable at each attested layer. Enterprises can now deploy AI on shared, accelerator-based infrastructure with cryptographic evidence they control and auditors can verify. 

The environment is cryptographically verified before the key moves. The data is designed to remain encrypted after it is done.  

To learn more about FHEnom for AI™ visit datakrypto.ai/technology, or Intel® Trust Authority or contact DataKrypto directly at info@datakrypto.ai