Phala
Phala runs AI inference, training, and autonomous agents inside Intel TDX and NVIDIA GPU Confidential Computing, providing hardware-attested privacy for developers, enterprises, and Web3 platforms.
- Company typePrivate
- Founded2018
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Phala does
Phala (legal entity Hashforest Technology) operates a confidential AI cloud platform that runs AI inference, training, and autonomous agent workloads inside hardware-backed Trusted Execution Environments (TEEs). The platform combines Intel TDX CPU isolation with NVIDIA GPU Confidential Computing (H100, H200, B300) and emits cryptographic dual-attestation receipts proving what code ran. Core product surfaces include Confidential VM (Docker-native TDX-backed VMs), GPU TEE Cloud (TEE-ready GPU capacity with on-demand, reserved, and dedicated-cluster pricing), Confidential AI Models (OpenAI-compatible private LLM endpoints serving 30 third-party and proprietary models with cryptographic receipts), and dstack — an open-source Linux Foundation TEE runtime providing Docker-native deployment, RA-TLS key management, and Ethereum smart contract governance via DstackApp. Layered solutions include an Agent Sandbox with compose-hash permissioning, Private AI Training (SFT/DPO/RLHF/LoRA on sealed data), and a Compute-to-Data pattern for multi-party analysis where data never leaves its silo.
The business model is usage-based with reserved and dedicated-cluster enterprise tiers. GPU TEE prices range from $2.38 to $6.50 per GPU-hour depending on hardware tier and commitment; CVM instances price from $0.06 to $0.23 per hour; LLM inference is $0.10-$1.50 per million input tokens with no privacy premium versus open routes; persistent storage is $0.000139 per GB-hour. Distribution combines self-serve Phala Cloud (CLI + dashboard, $20 verified-account credits, $1,000 startup-program credits), the OpenRouter marketplace, self-hosted dstack deployments on AWS/GCP, and direct enterprise sales for dedicated clusters. Customer segments span financial services, healthcare research, enterprise AI SaaS, and decentralized AI/Web3, with named deployments including OpenRouter (18B+ tokens routed), NEAR AI (on-chain verifiable agents), OODA AI (Nasdaq-listed, 12M tokens/day), Venice AI, and ElizaOS (1,585 deployed agents). The company holds SOC 2 Type I and HIPAA certifications with ISO 27001 in progress, and migrated its network from Polkadot to Ethereum L2 in November 2025 to access deeper liquidity and enterprise tooling.
Phala firmographics
Firmographics- Name
- Phala
- Legal name
- Hashforest Technology
- Website
- https://phala.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Phala runs AI inference, training, and autonomous agents inside Intel TDX and NVIDIA GPU Confidential Computing, providing hardware-attested privacy for developers, enterprises, and Web3 platforms.
- Ownership category
- akta.pro rank
Phala industry classification
Industry- Product category
- Confidential AI Cloud Infrastructure
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182), Computer Facilities Management Services (541513), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Confidential Computing & Hardware-backed Protection (TEE/HSM) (HDADAFAJ)
- akta.pro secondary industries
- AI Compute Virtualization & Scheduling (GPU virtualization, cluster schedulers) (HDAAAAAG), Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG), Industry/Vertical Cloud Platforms (e.g., Gov/Healthcare/Financial Cloud Regions) (HDABAAAL)
Keywords
Where Phala is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Phala business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Infrastructure, Personnel, Marketing or Sales, Operations
Revenue model
- GPU TEE Compute: Hourly billing for TEE-ready GPU capacity (H100, H200, B300) with on-demand, reserved slot, and dedicated cluster options. GPU TEE operations and attestation included in pricing.
- Confidential VM (CVM) Compute: Hourly billing for TDX-backed CVM instances with tiered options (small, medium, large). Compute stops when VM is stopped but storage persists until deletion.
- Confidential AI Model API: Pay-per-token pricing for private LLM inference via OpenAI-compatible endpoints. Models from various providers (DeepSeek, Qwen, Google, Meta, OpenAI OSS) with TEE-backed execution and verification receipts.
- Storage: Persistent CVM disk storage billed per GB-hour while the CVM exists, whether running or stopped.
- Enterprise Custom Deals: Dedicated clusters, reserved GPU slots, and custom network requirements quoted through sales for enterprise accounts requiring committed capacity.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Usage-based | Pay-as-you-go | tdx.small - Small TDX Instance for lightweight workloads |
| Usage-based | Pay-as-you-go | tdx.medium - Medium TDX Instance (default tier) |
| Usage-based | Pay-as-you-go | tdx.large - Large TDX Instance for heavier workloads |
| Usage-based | Pay-as-you-go | H100 GPU TEE - Trial and on-demand access |
| Usage-based | Pay-as-you-go | H200 GPU TEE - High-memory GPU capacity |
| Usage-based | Pay-as-you-go | B300 GPU TEE - Blackwell Ultra confidential capacity |
| Usage-based | Pay-as-you-go | CVM Storage |
| Freemium | Monthly | Startup Program Credits |
| Usage-based | Pay-as-you-go | Confidential AI Model API pricing varies by model |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels8 records
Phala product offering
Product offeringCore offering
Phala operates a confidential AI cloud platform built on Trusted Execution Environment (TEE) hardware (Intel TDX CPUs and NVIDIA H100/H200/B300 GPUs). It delivers Confidential VMs that run Docker workloads inside attested enclaves, OpenAI-compatible private LLM inference endpoints, and a GPU marketplace for confidential AI training, inference, and agent execution with cryptographic receipts.
Product overview
Phala Network is a confidential AI cloud platform offering verifiable private computation for AI workloads. The product portfolio centers on Phala Cloud — a managed platform comprising Confidential VM (hardware-backed TEE virtual machines), GPU TEE Cloud (H100/H200/B300 NVIDIA GPU capacity with dual Intel TDX + NVIDIA CC attestation), and Confidential AI Models (OpenAI-compatible private LLM API). These core products share a unified trust model built on dstack, Phala's open-source Linux Foundation TEE runtime that provides Docker-native deployment, RA-TLS key management, and on-chain smart contract governance via DstackApp. Layered atop the infrastructure are AI solutions: Private AI Inference (attested LLM serving), Private AI Training (sealed fine-tuning), Private AI Data/Compute-to-Data (cross-silo cohort analysis), and Agent Sandbox (sealed autonomous agents). A Trust Center provides public attestation inspection, and a Startup Program offers GPU credits to early-stage AI builders. The platform processes over 2.2 billion tokens per day and has 5,000+ users across 17 TDX nodes and 8 GPU TEE teepods globally.
Differentiator
Problem solved
Functional benefit
Products and services
- Confidential VM Hardware-backed confidential virtual machine service running Docker workloads inside Intel TDX (and AMD SEV-SNP) trusted execution environments, providing sealed private memory, cryptographic attestation, encrypted secrets injection, and verifiable runtime state.
- GPU TEE Cloud Confidential GPU cloud offering TEE-ready NVIDIA H100, H200, and B300 (Blackwell Ultra) capacity with dual attestation (Intel TDX plus NVIDIA Confidential Computing), CVM runtime, and GPU-CC mode delivered through on-demand trials, reserved slots, and dedicated enterprise clusters.
- Confidential AI Models OpenAI-compatible private LLM API endpoint (inference.phala.com/v1) serving frontier models (DeepSeek, Qwen, Llama, GPT OSS, Claude Sonnet, Gemini, GLM, Kimi) inside TEE-backed enclaves with cryptographic attestation and per-response x-receipt-id.
- dstack Open-source TEE runtime infrastructure project (Linux Foundation) providing Docker-native confidential compute, automatic attestation, per-app key derivation via RA-TLS, smart contract governance (DstackApp.sol), and GPU support.
- Phala Cloud Managed confidential compute cloud platform providing CVM deployment, GPU TEE capacity, private LLM APIs, attestation verification, and cloud operations through a unified dashboard and CLI.
- Private AI Inference Confidential inference solution enabling OpenAI-compatible LLM calls where prompts, outputs, and customer context are encrypted-in-use via TEE with TDX plus NVIDIA GPU TEE attestation and no-log-by-construction policy.
- Private AI Training Sealed model training solution supporting SFT, DPO, RLHF, LoRA/QLoRA PEFT, and continued pre-training on proprietary datasets that never leave their silos, with training manifests signed and bound to on-chain compose-hash.
- Private AI Data (Compute-to-Data) Cross-silo data collaboration solution where datasets are sealed at source using HKDF-derived wrap keys, analysis runs inside TEE-gated CVMs, and only pre-approved aggregate outputs are released via multi-sig DstackApp on-chain authorization.
- H100 GPU TEE TEE-ready NVIDIA H100 instance with 80GB HBM3 memory, 3.35 TB/s bandwidth, Intel TDX plus NVIDIA CC mode, starting at $3.08/GPU/hr on-demand in US-West.
- H200 GPU TEE TEE-ready NVIDIA H200 instance with 141GB HBM3e memory, 4.8 TB/s bandwidth, Intel TDX plus NVIDIA CC mode, starting at $4.80/GPU/hr on-demand in US-West and India regions.
- B300 GPU TEE TEE-ready NVIDIA B300 (Blackwell Ultra) instance with 288GB HBM3e memory, 8 TB/s bandwidth, Intel TDX plus NVIDIA CC mode, starting at $6.50/GPU/hr on-demand in US-East and US-West regions.
Quantifiable outcome
- Enterprise sales increased 300% for Fortune 500 clients requiring verifiable data protection
- +4 more outcomes
Companies that use Phala
Customer profileNamed customers11 records
Segments7 records
Ideal customer profiles5 records
Phala technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration24 records
AI capability9 records
Feature7 records
Phala partnerships and signals
Strategic signalPartnerships
14 partnerships are on record, tiered strategic, flagship, core and minor.
- OLLMstrategicOLLM partnered with Phala to integrate confidential AI models into OLLM AI Gateway, enabling private inference with cryptographic TEE attestation. Supports models like Llama 3.3, Gemma 3, DeepSeek, and GPT-oss for enterprise users needing strong data confidentiality.
- NVIDIAflagshipNVIDIA Inception Program partner providing GPU infrastructure. Phala uses NVIDIA H100, H200, and B300 GPUs with Confidential Computing mode for private AI workloads. Deep technical integration for GPU attestation and confidential computing support.
- IntelcoreIntel TDX (Trust Domain Extension) provides CPU-level confidential VM isolation. Intel Attestation Service supports TCB status verification. Deep partnership on TEE hardware and attestation infrastructure.
- OpenRoutercoreOpenRouter provides unified API for 100+ AI models. Phala serves as the enterprise tier provider for private inference routes. Drop-in OpenAI-compatible endpoint with verifiable, no-log routing. 18B+ tokens processed.
- NEARcoreNEAR AI brought by Near Foundation for distributed AI agent systems. Phala provides verifiable agent inference for autonomous, on-chain workflows. Deep integration for verifiable AI execution on NEAR blockchain.
- OPPOstrategicJoint paper on verifiable trust for cloud-native AI infrastructure (June 2026). OPPO explores private AI and device-side computing where trusted execution protects sensitive user context.
- Venice AIcorePrivate AI access for chat, image, and model workflows. Phala provides verifiable private execution for trust-sensitive inference. Deep integration for confidential AI deployment.
- Z.AIcoreZ.AI brings GLM models (including GLM-5.2 with 1M context) into production channels. Phala makes AI execution private and verifiable. GLM-5.2 available on Phala at $1.40/M input.
- OODA AIcoreNasdaq-listed AI company (Nasdaq First North Growth Market) with global operations. Phala provides decentralized GPU TEE with hardware attestation guarantees. 12M tokens/day processed.
- ElizaOScoreAI agent framework with 1,585 live character agents deployed on Phala since December 2024. Phala provides confidential execution environment for agent backends.
- Clawdi (OpenClaw)corePersonal computer-use AI agent with 193 live instances since January 2026. Sessions, calendars, inbox sealed in Phala CVM with compose-hash as permission scope.
- Agent Wallet (Coinbase)strategicERC-8004 + x402 payment integration with 1 live instance since May 2025. Wallet and on-chain agents binding spending scope to compose-hash.
- IO.NETminorDecentralized GPU compute network. Partnership for distributed compute and GPU capacity expansion.
- HyperbolicminorDecentralized GPU computing provider. Partnership for accessible, affordable GPU resources and AI services.
Scale indicators15 records
Recent moves7 records
Expansion highlights7 records
Phala competitors and assessment
Company assessmentEmerging players
- Inco Network: Confidential computing network using a combination of TEE and FHE for private on-chain computation. Inco and Phala both serve confidential compute use cases, with Inco emphasizing FHE and Phala emphasizing hardware-attested TEE; they intersect in the privacy-preserving AI/blockchain segment.
- Ritual: Decentralized AI infrastructure network with on-chain AI model hosting and inference. Ritual is a Phala partner (per partnerships list) and addresses overlapping private AI inference use cases, though with a different protocol architecture emphasizing open AI governance.
- io.net: Decentralized GPU compute network providing distributed GPU access for AI workloads. Listed as a Phala channel partner, io.net and Phala intersect in serving GPU capacity to AI developers, though Phala layers TEE attestation on top that io.net does not provide.
- Nillion: Decentralized blind computation network combining nilDB (storage), nilAI (AI), and nilCC (compute) using MPC, TEE, and FHE. Nillion addresses similar private AI/agent use cases as Phala with a broader cryptographic toolset, representing an emerging player in the same confidential AI compute category.
Direct peers
- Secret Network: Privacy-preserving smart contract blockchain using TEE (Intel SGX) for encrypted computation. Secret Network and Phala both pioneer TEE-based confidential computing on blockchain rails, though Secret focuses on private DeFi/computation while Phala has pivoted to AI workload focus.
- Oasis Network: Confidential computing blockchain network using TEE-based secure enclaves (Intel SGX originally, expanding to TDX). Oasis competes with Phala in confidential smart contract execution and private compute on-chain, with overlapping Web3 confidential compute positioning.
- Tinfoil: Confidential AI inference platform also built on TEE hardware with attestation. Phala publishes a direct comparison page (compare/phala-vs-tinfoil), indicating Tinfoil is the closest direct competitor for attested private LLM serving with similar developer APIs.
Broad incumbents
- Google Cloud Confidential VMs: Google Cloud's confidential VM offering using AMD SEV-SNP and Intel TDX. Phala's comparison page targets GCP directly. GCP Confidential VM provides infrastructure but does not bundle GPU TEE with dual attestation or the open-source dstack control plane, leaving room for Phala in GPU-attested workloads.
- Microsoft Azure Confidential Computing: Azure's confidential computing portfolio including AMD SEV-SNP and Intel TDX VMs, plus Intel SGX enclaves. As a hyperscaler incumbent, Azure competes broadly for confidential AI workloads but has not released GPU CC mode at Phala's scale with dstack-equivalent open-source tooling.
- AWS Nitro Enclaves: AWS's confidential computing offering based on Nitro System hypervisor isolation. Phala explicitly publishes a comparison page vs. Nitro, indicating they compete for the same confidential AI workloads. As a hyperscaler incumbent, Nitro offers confidential VM primitives but lacks Phala's GPU CC mode and integrated attestation receipt model.
Market position
Strengths4 records
Weaknesses3 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
Phala social profiles
Digital presencePhala compliance and trust
Trust signalCompliance4 records
Phala financial estimates
Financial estimateRevenue estimate
Valuation estimate
Phala leadership team
Management profileNumber of profiles
Profiles7 records
Phala funding detail
Funding detailFunding overview
Funding rounds2 records
Investors10 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Phala M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Phala
What does Phala do?
Phala operates a confidential AI cloud platform built on Trusted Execution Environment (TEE) hardware (Intel TDX CPUs and NVIDIA H100/H200/B300 GPUs). It delivers Confidential VMs that run Docker workloads inside attested enclaves, OpenAI-compatible private LLM inference endpoints, and a GPU marketplace for confidential AI training, inference, and agent execution with cryptographic receipts.
Is Phala a public or private company?
Phala is a private company. It is classified as venture growth investor backed and is currently operating.
When was Phala founded?
Phala was founded in 2018. It employs 11 to 50 people.
Where is Phala based?
Phala is headquartered in San Francisco, United States, in the North America region.
How does Phala make money?
Five revenue lines are on record. GPU TEE Compute is the primary driver. The others are confidential VM (CVM) Compute, confidential AI Model API, storage and enterprise Custom Deals.
Who are Phala's main competitors?
Emerging players on record are Inco Network, Ritual, io.net and Nillion. Direct peers are Secret Network, Oasis Network and Tinfoil. Broad incumbents are Google Cloud Confidential VMs, Microsoft Azure Confidential Computing and AWS Nitro Enclaves.
Does Phala have an API?
Yes. OpenAI-compatible REST API for private LLM inference at inference.phala.com/v1/chat/completions. Supports bearer token authentication via PHALA_API_KEY, returns x-receipt-id per response for attestation verification, and streaming responses. Python SDK available via 'pip install openai' with base_url='https://inference.phala.com/v1'. CLI available via 'npm install -g phala'. API also exposes attestation endpoints (e.g., /attest/) for fetching TDX quotes, runtime measurements, and cryptographic proofs. Developer documentation is at docs.phala.com.
What industry is Phala in?
Phala's product category is Confidential AI Cloud Infrastructure. Its primary akta.pro industry code is HDADAFAJ, Confidential Computing & Hardware-backed Protection (TEE/HSM), with a secondary code of HDAAAAAG, AI Compute Virtualization & Scheduling (GPU virtualization, cluster schedulers). Its NAICS code is 5182 and its SIC code is 7373.