ISO 27001 certified

As private as on-prem. As simple as an API.

Liquify Enclave runs AI inference on your most sensitive data inside confidential, attested hardware - encrypted in transit, at rest, and in use. Your data is never readable by anyone. Not even us.

End-to-end encryptedConfidential compute100% cryptographically verifiable
Why Enclave

Verification before inference.

The client SDK verifies signed attestation evidence against the release manifest before data moves. Only then is the request sealed for the enclave and returned as an encrypted response.

End-to-end encryption

Inbound data is encrypted client-side by the SDK before it passes through the gateway. Output is re-encrypted inside the TEE before it returns to the client.

Confidential compute

Models run inside hardware-isolated secure enclaves. Memory is encrypted in use, with remote attestation you can verify.

Model agnostic

Run any open-source model that fits your workload, then adapt it with LoRA adapters so inference can be tailored to your specific dataset and domain.

Plugin marketplace

Connect CRM, notes, decks, docs, analytics and support tools in a click. Every connector is encrypted and least-privilege scoped.

Encrypted logs, BYOK

By default, prompts, responses and logs are stored encrypted on the user's device. Encrypted server-side storage is available for cross-device access, but only as an opt-in.

SDK and OpenAPI surface

Build your own applications with the Enclave SDK and OpenAPI-compatible interface, so private inference can live inside your own product workflows.

Plugin marketplace

Connect the tools your data already lives in.

Encrypted connectors for the systems your team uses every day. Enclave reads only what you scope, and every byte stays encrypted through the enclave.

CRM

Accounts, deals, and customer records.

Notes

Meeting notes, transcripts, and wikis.

Presentations

Decks, pitches, and board materials.

Documents

Contracts, PDFs, and shared files.

Analytics

Dashboards, warehouses, and metrics.

Support

Tickets, live chat, and help centers.

How it works

Attest, seal, compute, return.

The client SDK verifies the enclave before sending data, seals the request as ciphertext, and only opens the encrypted response back on the user's device.

01Attest

Request attestation

The client SDK asks the enclave for a fresh attestation nonce and receives signed evidence, including the quote and enclave key.

02Verify

Verify before sending

The SDK checks the evidence against the signed manifest. If the measurement or policy does not match, the request stops before data moves.

03Seal

Send sealed prompt

The prompt is encrypted client-side and travels through the gateway as ciphertext, so routing and metering stay content-blind.

04Infer

Run inside the TEE

The enclave decrypts inside the TEE, calls the model over local loopback, then re-encrypts the completion before it leaves the enclave.

05Open

Open on the client

The sealed response returns to the SDK. Plaintext is recovered only on the user's device, with encrypted logs kept locally by default.

Frequently asked questions

Questions,
answered plainly.

Still deciding whether Enclave fits your compliance posture? These are the questions teams usually ask first.

What exactly is a confidential compute enclave?

A confidential compute enclave is a hardware-isolated execution environment where memory is encrypted while in use. Enclave uses that boundary so sensitive prompts, context, and model outputs are processed away from the host system.

Join the waitlist

Get Enclave updates as private beta opens.

Join the waitlist for availability updates, rollout notes, and early cohort announcements.

We respect your privacy and will not share your e-mail address with any third party. Your personal data will be processed in accordance with our Privacy Policy.