Stealthium
Stealthium provides a cloud-based runtime security and observability platform for GPU-accelerated AI workloads, using eBPF-based introspection of NVIDIA drivers and CUDA APIs to detect GPU-specific threats and deliver telemetry to enterprises operating multi-tenant GPU clusters.
- Company typePrivate
- Founded2024
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Stealthium does
Stealthium, Inc. is a private cybersecurity company headquartered in San Francisco, California, that builds a cloud-based runtime security and observability platform for GPU-accelerated AI workloads. The company's core product, the Stealthium GPU Observability Platform, is built on eBPF-based introspection of the NVIDIA kernel driver and CUDA Driver API, capturing ioctl traffic (e.g., NV_ESC_ATTACH_GPUS_TO_FD, NV_ESC_WAIT_OPEN_COMPLETE), UVM allocation and eviction events, and CUDA binary fatbin loading at the kernel boundary. A proprietary monitoring layer, Stealthium GPU Monitor, replaces NVML internally and benchmarks 5.9x faster initialization and up to 899x faster telemetry queries against NVML with a 19-20MB lower memory footprint. Layered on top of the telemetry pipeline are Hyperprints — an abstraction that converts raw kernel traces and metrics into unified insights — and runtime security features including detection for GPUBreach-class attacks, NVIDIA driver CVEs (CVE-2025-23282, CVE-2025-23332), and CUDA binary introspection for architecture-specific malicious payloads.
Stealthium targets large organizations running multi-tenant GPU clusters — including financial services, healthcare, Fortune 500s, and government / public sector entities — as well as cloud providers operating shared NVIDIA GPU infrastructure. The platform supports PyTorch, TensorFlow, and Ollama AI workloads and is integrated with Substrate AI's sovereign cloud offering for European compliance markets (GDPR, ENS, EU AI Act). Go-to-market is a direct enterprise field-sales motion with demo-based outreach and proof-of-concept engagements into customer GPU environments, structured as subscription-based recurring software licensing, though specific pricing is not publicly disclosed. The company is a member of the NVIDIA Inception Program and participates in industry conferences including GTC and RSA. Headcount sits in the 11-50 range, and no funding rounds are publicly disclosed.
Stealthium firmographics
Firmographics- Name
- Stealthium
- Legal name
- Stealthium, Inc.
- Website
- https://stealthium.io
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Stealthium provides a cloud-based runtime security and observability platform for GPU-accelerated AI workloads, using eBPF-based introspection of NVIDIA drivers and CUDA APIs to detect GPU-specific threats and deliver telemetry to enterprises operating multi-tenant GPU clusters.
- Ownership category
- akta.pro rank
Stealthium industry classification
Industry- Product category
- GPU Security and Observability Software
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (51821), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH)
- akta.pro secondary industries
- AI Compute Virtualization & Scheduling (GPU virtualization, cluster schedulers) (HDAAAAAG), Serverless & PaaS Security (Function/App Service Runtime) (HDADADAL)
Keywords
Where Stealthium is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Stealthium business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Runtime Security and Observability Platform: Enterprise software platform providing runtime security and behavioral monitoring for cloud workloads, virtualization environments, and AI model infrastructure. Services include software agents, APIs, dashboards, and monitoring tools. Likely structured as subscription-based SaaS with enterprise contracts, though specific pricing is not publicly disclosed.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
Stealthium product offering
Product offeringCore offering
Stealthium provides a cloud-based observability and security platform that delivers runtime visibility into NVIDIA GPU workloads using eBPF-based introspection of GPU drivers. The platform monitors CUDA kernel execution, VRAM allocation, UVM events, and driver-level ioctl calls to detect GPU-specific threats including GPUBreach, NVIDIA driver vulnerabilities, and cross-tenant isolation failures. It is deployed as software agents, APIs, and dashboards across single-node to multi-cluster GPU environments, targeting enterprises running AI training and inference workloads.
Product overview
Stealthium is a GPU-Powered Security Intelligence platform that provides runtime security and observability for AI infrastructure built on NVIDIA GPUs. The platform consists of the Stealthium GPU Observability Platform as the core product, with Stealthium GPU Monitor (proprietary monitoring layer replacing NVML) powering Hyperprints and Runtime Security features. The platform delivers multi-layer visibility from single-node to multi-cluster GPU environments, transforming raw GPU telemetry into actionable insights. Stealthium's technology stack includes eBPF-based instrumentation for CUDA API interception (cuModuleLoadData), GPUBreach and NVIDIA driver vulnerability detection, and CUDA binary introspection. The platform integrates with Substrate AI's sovereign cloud platform and supports PyTorch, TensorFlow, and Ollama AI frameworks.
Differentiator
Problem solved
Functional benefit
Products and services
- Stealthium GPU Observability Platform Deep observability platform for single-node to multi-cluster GPU environments. Provides end-to-end GPU metrics, kernel traces, logs, and real-time health monitoring for AI workload performance analysis. Operates at the node level via the Stealthium Host agent and at the workload level via Stealthium Guest instrumentation. Targets security and infrastructure teams at enterprises deploying AI workloads on NVIDIA GPUs.
- Stealthium GPU Monitor Proprietary GPU monitoring layer that replaces NVML for deep observability at production scale. Delivers 5.9x faster initialization, up to 899x faster high-frequency telemetry queries, and 19–20MB lower memory footprint per process. Surfaces GPU data not accessible through NVML by querying the NVIDIA driver directly. Powers the observability layer inside the Stealthium platform and is used as the default monitoring path with NVML as fallback.
- Hyperprints High-level unified abstraction that transforms raw low-level GPU metrics and kernel traces into actionable insights. Delivers cross-layer context correlation across GPU metrics, traces, logs, and real-time health monitoring so customers understand what GPU metric changes mean for AI workload performance rather than just seeing raw metric drops.
- Runtime Security Active monitoring of AI workloads and GPUs for unusual usage patterns using advanced GPU-specific telemetry. Delivers runtime security for AI operations including detection of data exfiltration, model abuse, jailbreak attempts, GPU misuse, cross-tenant VRAM side-channel attacks, and cryptojacking. Full support for the NVIDIA software stack including drivers, CUDA, and major AI frameworks (PyTorch, TensorFlow, Ollama).
- GPUBreach Detection Detection capability for GPUBreach class attacks including Rowhammer-based privilege escalation and VRAM arbitrary read/write access. Monitors UVM allocation patterns (small-page vs 2MB), eviction cadence, elemCount anomalies in GSP RPC messaging, and Rowhammer precursor fingerprints to detect Phase 1 GPUBreach signatures before Phase 2 page table steering begins.
- NVIDIA Driver Vulnerability Detection Runtime detection for NVIDIA GPU kernel driver vulnerabilities including CVE-2025-23282 (race condition privilege escalation, CVSS 7.0) and CVE-2025-23332 (ZERO_SIZE_PTR denial of service, CVSS 5.0). Uses eBPF-based ioctl monitoring on /dev/nvidiactl to detect exploitation attempts and anomalous ioctl patterns in real time.
- CUDA Binary Introspection GPU code analysis using eBPF uprobes to intercept cuModuleLoadData() and parse fatbin structures. Captures complete fatbin binaries, hashes individual kernels (BLAKE3), extracts PTX and cubin entries for all architecture targets, detects compression methods, and enables cross-architecture validation to identify malicious payloads behaving differently on specific GPU types.
Quantifiable outcome
- Up to 899x faster clock domains queries and 385x faster process utilization sampling vs NVML in benchmark conditions
- +2 more outcomes
Companies that use Stealthium
Customer profileSegments3 records
Ideal customer profiles3 records
Stealthium technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability6 records
Feature6 records
Stealthium partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Substrate AIcoreStrategic partnership to deliver runtime security and observability for GPU-powered AI workloads. Stealthium provides specialized runtime security and observability layer for NVIDIA GPU-based AI environments operating at node and workload levels. Combined solution enables real-time visibility into which models run on which GPUs for which tenants, continuous detection of AI-specific threats (data exfiltration, model abuse, jailbreak attempts, crypto-mining, GPU misuse), zero-overhead protection for high-performance AI workloads, and automated audit trails for compliance with GDPR, ENS, and AI Act. The partnership addresses critical gaps in securing GPUs and AI workloads in real time for sovereign cloud and enterprise deployments.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Stealthium competitors and assessment
Company assessmentEmerging players
- TrojAI: TrojAI provides AI model and workload security including model scanning and red-teaming. It is an emerging player in the AI security space with a narrower model-layer focus compared to Stealthium's GPU runtime layer.
Direct peers
- HiddenLayer: HiddenLayer provides AI security posture management and model threat detection for ML models in production. It overlaps with Stealthium on the emerging AI security category, though Stealthium's wedge is deeper GPU runtime introspection.
- Noma Security: Noma Security is an AI security and governance platform focused on AI applications, agents, and model risk. Comparable as a direct competitor in the AI security category that enterprises may evaluate alongside Stealthium.
- Robust Intelligence (Cisco): Robust Intelligence built AI security and model validation products (now part of Cisco) covering model firewalling, drift, and adversarial robustness. Direct peer in the AI workload security category where Stealthium competes, now backed by a major networking/security incumbent.
- Protect AI: Protect AI is an AI/ML security platform that secures the machine learning lifecycle including model scanning, supply chain, and runtime protection. It is the closest direct peer in the AI workload security category where Stealthium also competes.
Broad incumbents
- CrowdStrike: CrowdStrike's Falcon platform covers endpoint, cloud, and identity security and is actively adding AI workload protection features. As a broad incumbent with deep enterprise reach, it is the kind of vendor CISOs may favor over a standalone GPU security specialist.
- Wiz: Wiz is a leading cloud security (CNAPP) platform that already covers workloads, identities, and pipelines across major clouds. It is a broad incumbent that may extend native GPU/AI workload visibility into its platform, directly competing with Stealthium for cloud security budget.
- Datadog: Datadog is a leading observability platform with growing GPU monitoring capabilities (GPU metrics, traces) that overlap with Stealthium's observability layer. It is a broad incumbent whose installed base could substitute for a standalone GPU observability purchase.
- Palo Alto Networks (Prisma Cloud): Palo Alto Networks Prisma Cloud is a CNAPP platform with broad cloud and AI workload coverage. It competes with Stealthium at the platform-budget level and could absorb GPU-specific runtime telemetry into its existing portfolio.
Others
- NVIDIA (DCGM / NVAIE): NVIDIA ships DCGM, CUDA tooling, and NVAIE platform services that provide baseline GPU monitoring and are expanding into security and compliance. NVIDIA is the platform vendor and potential ecosystem partner, but also the single largest competitive threat if it ships first-party GPU security telemetry.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Stealthium social profiles
Digital presenceStealthium compliance and trust
Trust signalCompliance3 records
Stealthium financial estimates
Financial estimateRevenue estimate
Valuation estimate
Stealthium leadership team
Management profileNumber of profiles
Profiles8 records
Stealthium funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Stealthium M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Stealthium
What does Stealthium do?
Stealthium provides a cloud-based observability and security platform that delivers runtime visibility into NVIDIA GPU workloads using eBPF-based introspection of GPU drivers. The platform monitors CUDA kernel execution, VRAM allocation, UVM events, and driver-level ioctl calls to detect GPU-specific threats including GPUBreach, NVIDIA driver vulnerabilities, and cross-tenant isolation failures. It is deployed as software agents, APIs, and dashboards across single-node to multi-cluster GPU environments, targeting enterprises running AI training and inference workloads.
Is Stealthium a public or private company?
Stealthium is a private company. It is classified as unknown and is currently operating.
When was Stealthium founded?
Stealthium was founded in 2024. It employs 11 to 50 people.
Where is Stealthium based?
Stealthium is headquartered in San Francisco, United States, in the North America region.
How does Stealthium make money?
One revenue line is on record: runtime Security and Observability Platform.
Who are Stealthium's main competitors?
TrojAI is listed as an emerging player. Direct peers are HiddenLayer, Noma Security, Robust Intelligence (Cisco) and Protect AI. Broad incumbents are CrowdStrike, Wiz, Datadog and Palo Alto Networks (Prisma Cloud). NVIDIA (DCGM / NVAIE) is listed as an others.
Does Stealthium have an API?
Yes. Stealthium provides an API as part of its Services offering. The Terms of Service state that access to and use of the website, software, APIs, dashboards, agents, and related services are governed by the terms. The API is mentioned as a component of the Services, but no public API documentation URL, endpoint details, authentication methods, rate limits, or SDK availability are specified in the provided sources.
What industry is Stealthium in?
Stealthium's product category is GPU Security and Observability Software. Its primary akta.pro industry code is HDAAAKAH, Secure Model Deployment & Runtime Protection (sandboxing, isolation), with a secondary code of HDAAAAAG, AI Compute Virtualization & Scheduling (GPU virtualization, cluster schedulers). Its NAICS code is 51821 and its SIC code is 7372.