Fine-tune inside your own cloud, with every claim about the result independently verified.
Attestal runs LLM fine-tuning pipelines in your AWS, GCP, or Azure account — your data and weights never leave it — and hands back a signed, immutable record of what was checked and whether it passed. Not a status flag. Proof.
Train in the open for free · train in a private enclave for money — you pay for privacy, not for the rigor. The rigor is standard.
Regulated teams can't fine-tune where they're allowed to, or trust where they can.
Hosted fine-tuning is the wrong trust boundary
OpenAI, Bedrock, Azure customization — they process your proprietary data on the vendor's shared infrastructure. "We don't retain it" is a contract term, not an architecture. Compliance teams say no.
In-house pipelines are a multi-week bug hunt
Provisioning, orchestration, live monitoring, cost control, eval-gated publishing — building it yourself is real engineering. Our own reference run took ~24 hours and eight relaunches to finish once, cleanly.
Enclave vendors sell compute trust, not pipeline trust
Attestation and confidential compute prove the box is sealed. They don't tell you why a run failed, whether the model is actually good, or catch the silent regressions that produce a plausible-but-broken model.
Two guarantees, sold together — one architectural, one empirical.
Data sovereignty BYOC
The control plane only orchestrates. Compute runs and data lives in your cloud tenancy, reached through a scoped credential you grant and revoke. We never hold your data or your trained weights — we structurally can't.
- Scoped IAM role / API key — not your root credentials.
- Weights stay in your account's storage.
- Runaway-spend protection on your bill, auto-stop on done or crash.
Verified rigor audited
Every run produces a signed, immutable audit record — what was checked, against what thresholds, with what result — and the platform actively hunts the failure modes that quietly produce a plausible-but-broken model.
- Train/eval format mismatches, caught and measured.
- Silently-overridden config defaults, flagged before the spend.
- Software provenance: content-addressed builds, cryptographically signed.
The moat isn't the GPUs. It's four things that already went wrong — and got caught.
Every enclave vendor can claim rigor. Ours is a log. These are real incidents from the reference pipeline this product is built on — each one a failure that a status flag would have hidden.
A rented GPU host reported status: success, running over its API while SSH was refused for the entire wait window — twice. Caught by testing reachability directly, not by trusting the provider's own health flag.
→ We verify the machine, not the machine's claim about itself.
A regression (bfcl 0.275, humaneval −13.4%) was root-caused to a train/eval prompt-format mismatch — not written off as "the model is just bad." Fixed, and the fix's own effect was measured (bfcl → 0.375), not assumed.
→ A fix isn't done until its effect shows up in the numbers.
A safety default was corrected in one file and silently re-broken by a duplicate hardcoded default in a second. Caught at $1.50 and 12 minutes into a relaunch — not after another full, expensive run.
→ The second copy of a config is a lie waiting to happen. We hunt for it.
A "quantum-inspired" compression technique was built, unit-tested, and then empirically shown not to help — both variants, with real numbers — before it ever shipped.
→ "It should work" is not a result. Shipped means measured.
None of this is unique algorithmically. It's operational rigor — exactly what a compliance-minded buyer is actually purchasing, and exactly what's hard to fake in a demo the way a data-locality checkbox is easy to claim.
Same pipeline. Same verification. The only difference is who can see it.
Open
FreeTrain in the open.
- 3 training slots on our 3×H200 — real, verified SFT runs.
- The same signed audit record as the paid tier.
- The honest catch: your dataset and the resulting weights are saved and may be published to the open corpus. Public by design.
- Your run appears in the live feed — transparency is the point.
- No support — thorough guidance docs instead.
Enclave
You pay for privacyTrain in private.
- Bring your own cloud. Runs in your AWS/GCP/Azure — we never see data or weights.
- The same verification, plus a signed, exportable compliance record (HIPAA / SOC2-ready).
- Private by architecture — the whole compliance story, not a promise.
- Support + solutions engineering over a shared Slack Connect channel.
- Credential broker, runaway-spend protection, provenance signing.
A regulated enterprise cannot use the free tier — their data can't be public. That's the point: the tiers are separated by your own compliance boundary, not a feature gate.
What's training right now
Free tier launching with our first design partners.
Waitlist open · one of 3 H200 slots ·need it private? →
We're onboarding 2–3 design partners by hand.
This is a sales-led, high-touch motion on purpose — we want to learn your cloud's real failure modes with you, not behind a signup wall. Tell us what you'd fine-tune and where, and we'll set up a call.
No self-serve console yet. No signup flow. A person reads every one of these.