As private as on-prem. As simple as an API.
Liquify Enclave runs AI inference on your most sensitive data inside confidential, attested hardware - encrypted in transit, at rest, and in use. Your data is never readable by anyone. Not even us.
Verification before inference.
The client SDK verifies signed attestation evidence against the release manifest before data moves. Only then is the request sealed for the enclave and returned as an encrypted response.
End-to-end encryption
Inbound data is encrypted client-side by the SDK before it passes through the gateway. Output is re-encrypted inside the TEE before it returns to the client.
Confidential compute
Models run inside hardware-isolated secure enclaves. Memory is encrypted in use, with remote attestation you can verify.
Model agnostic
Run any open-source model that fits your workload, then adapt it with LoRA adapters so inference can be tailored to your specific dataset and domain.
Plugin marketplace
Connect CRM, notes, decks, docs, analytics and support tools in a click. Every connector is encrypted and least-privilege scoped.
Encrypted logs, BYOK
By default, prompts, responses and logs are stored encrypted on the user's device. Encrypted server-side storage is available for cross-device access, but only as an opt-in.
SDK and OpenAPI surface
Build your own applications with the Enclave SDK and OpenAPI-compatible interface, so private inference can live inside your own product workflows.
Connect the tools your data already lives in.
Encrypted connectors for the systems your team uses every day. Enclave reads only what you scope, and every byte stays encrypted through the enclave.
CRM
Accounts, deals, and customer records.
Notes
Meeting notes, transcripts, and wikis.
Presentations
Decks, pitches, and board materials.
Documents
Contracts, PDFs, and shared files.
Analytics
Dashboards, warehouses, and metrics.
Support
Tickets, live chat, and help centers.
Attest, seal,
compute, return.
The client SDK verifies the enclave before sending data, seals the request as ciphertext, and only opens the encrypted response back on the user's device.
Request attestation
The client SDK asks the enclave for a fresh attestation nonce and receives signed evidence, including the quote and enclave key.
Verify before sending
The SDK checks the evidence against the signed manifest. If the measurement or policy does not match, the request stops before data moves.
Send sealed prompt
The prompt is encrypted client-side and travels through the gateway as ciphertext, so routing and metering stay content-blind.
Run inside the TEE
The enclave decrypts inside the TEE, calls the model over local loopback, then re-encrypts the completion before it leaves the enclave.
Open on the client
The sealed response returns to the SDK. Plaintext is recovered only on the user's device, with encrypted logs kept locally by default.
Questions,
answered plainly.
Still deciding whether Enclave fits your compliance posture? These are the questions teams usually ask first.
A confidential compute enclave is a hardware-isolated execution environment where memory is encrypted while in use. Enclave uses that boundary so sensitive prompts, context, and model outputs are processed away from the host system.
No. Data is ciphertext on both sides of the enclave and is only opened inside the verified TEE for inference before being re-sealed. Liquify operates the infrastructure, but operators see encrypted traffic and operational metadata rather than prompt or output content.
Enclave is model agnostic and can run open-source models that fit the workload. Models can also be adapted with LoRA adapters so inference is tailored to your specific dataset, domain, latency, and GPU requirements.
Each connector is scoped to least privilege. Credentials are sealed, connector access can be revoked, and data pulled from tools such as CRMs, documents, analytics, and support systems remains encrypted through the enclave workflow.
Enclave is intended for teams with regulated or high-sensitivity data needs where GDPR and ISO 27001 alignment matter. Final compliance scope is confirmed during onboarding.
Pricing can be scoped around token-based usage or dedicated GPU reservations. During private beta, Liquify sizes the proposal around your model choice, workload, expected volume, and compliance requirements.
By default, prompts and outputs are stored encrypted on the user's device. If you need access across a number of devices, encrypted server-side storage can be enabled as an opt-in.
Enclave is in private beta. Submit the request access form with your stack, model, and compliance needs, and the Liquify team will follow up to scope the environment.
Get Enclave updates as private beta opens.
Join the waitlist for availability updates, rollout notes, and early cohort announcements.
We respect your privacy and will not share your e-mail address with any third party. Your personal data will be processed in accordance with our Privacy Policy.