Attestal3 slotsRequest access
OSS · bring-your-own-cloud · independently verified

Fine-tune inside your own cloud, with every claim about the result independently verified.

Attestal runs LLM fine-tuning pipelines in your AWS, GCP, or Azure account — your data and weights never leave it — and hands back a signed, immutable record of what was checked and whether it passed. Not a status flag. Proof.

Train in the open for free · train in a private enclave for money — you pay for privacy, not for the rigor. The rigor is standard.

The problem

Regulated teams can't fine-tune where they're allowed to, or trust where they can.

Hosted fine-tuning is the wrong trust boundary

OpenAI, Bedrock, Azure customization — they process your proprietary data on the vendor's shared infrastructure. "We don't retain it" is a contract term, not an architecture. Compliance teams say no.

In-house pipelines are a multi-week bug hunt

Provisioning, orchestration, live monitoring, cost control, eval-gated publishing — building it yourself is real engineering. Our own reference run took ~24 hours and eight relaunches to finish once, cleanly.

Enclave vendors sell compute trust, not pipeline trust

Attestation and confidential compute prove the box is sealed. They don't tell you why a run failed, whether the model is actually good, or catch the silent regressions that produce a plausible-but-broken model.

How it works

Two guarantees, sold together — one architectural, one empirical.

01

Data sovereignty BYOC

The control plane only orchestrates. Compute runs and data lives in your cloud tenancy, reached through a scoped credential you grant and revoke. We never hold your data or your trained weights — we structurally can't.

  • Scoped IAM role / API key — not your root credentials.
  • Weights stay in your account's storage.
  • Runaway-spend protection on your bill, auto-stop on done or crash.
02

Verified rigor audited

Every run produces a signed, immutable audit record — what was checked, against what thresholds, with what result — and the platform actively hunts the failure modes that quietly produce a plausible-but-broken model.

  • Train/eval format mismatches, caught and measured.
  • Silently-overridden config defaults, flagged before the spend.
  • Software provenance: content-addressed builds, cryptographically signed.
Proof, not claims

The moat isn't the GPUs. It's four things that already went wrong — and got caught.

Every enclave vendor can claim rigor. Ours is a log. These are real incidents from the reference pipeline this product is built on — each one a failure that a status flag would have hidden.

01bad host, not a status flag

A rented GPU host reported status: success, running over its API while SSH was refused for the entire wait window — twice. Caught by testing reachability directly, not by trusting the provider's own health flag.

We verify the machine, not the machine's claim about itself.

02a format mismatch, measured

A regression (bfcl 0.275, humaneval −13.4%) was root-caused to a train/eval prompt-format mismatch — not written off as "the model is just bad." Fixed, and the fix's own effect was measured (bfcl → 0.375), not assumed.

A fix isn't done until its effect shows up in the numbers.

03a default silently overridden

A safety default was corrected in one file and silently re-broken by a duplicate hardcoded default in a second. Caught at $1.50 and 12 minutes into a relaunch — not after another full, expensive run.

The second copy of a config is a lie waiting to happen. We hunt for it.

04a compression trick that didn't work

A "quantum-inspired" compression technique was built, unit-tested, and then empirically shown not to help — both variants, with real numbers — before it ever shipped.

"It should work" is not a result. Shipped means measured.

None of this is unique algorithmically. It's operational rigor — exactly what a compliance-minded buyer is actually purchasing, and exactly what's hard to fake in a demo the way a data-locality checkbox is easy to claim.

Two ways in

Same pipeline. Same verification. The only difference is who can see it.

Open

Free

Train in the open.

  • 3 training slots on our 3×H200 — real, verified SFT runs.
  • The same signed audit record as the paid tier.
  • The honest catch: your dataset and the resulting weights are saved and may be published to the open corpus. Public by design.
  • Your run appears in the live feed — transparency is the point.
  • No support — thorough guidance docs instead.
Join the free-tier waitlist

Enclave

You pay for privacy

Train in private.

  • Bring your own cloud. Runs in your AWS/GCP/Azure — we never see data or weights.
  • The same verification, plus a signed, exportable compliance record (HIPAA / SOC2-ready).
  • Private by architecture — the whole compliance story, not a promise.
  • Support + solutions engineering over a shared Slack Connect channel.
  • Credential broker, runaway-spend protection, provenance signing.
Request access

A regulated enterprise cannot use the free tier — their data can't be public. That's the point: the tiers are separated by your own compliance boundary, not a feature gate.

Live training

What's training right now

Free tier launching with our first design partners.

slot 1 opening soon
Reserved for the first public runs.
slot 2 opening soon
Reserved for the first public runs.
slot 3 opening soon
Reserved for the first public runs.

Waitlist open · one of 3 H200 slots ·need it private? →

Get started

We're onboarding 2–3 design partners by hand.

This is a sales-led, high-touch motion on purpose — we want to learn your cloud's real failure modes with you, not behind a signup wall. Tell us what you'd fine-tune and where, and we'll set up a call.

No self-serve console yet. No signup flow. A person reads every one of these.