Security FAQ
How we handle your data and what the contracts say about Texas.
Data and privacy
Does Texas Inference train on my data?
No. We never use Customer Content to train, fine tune, evaluate, or improve any model. We never sell it or share it. We never combine it with data from anyone else. Section 4.3 of the DPA.
Do you keep my prompts and outputs?
An ephemeral lane keeps nothing after a request is answered. A persistent lane keeps working state in encrypted memory only and never writes it to disk. It drops that state after one hour without requests, on release of the lane, or on your request. Our operational logs hold timings, sizes, error codes, and attestation results. They never hold prompts or outputs.
Can your staff read what I send?
No. Customer Content exists in plaintext only inside a confidential virtual machine. We have no route into it. No administrator console, log, or support tool exposes it. We act only on what we can see: billing records, traffic volumes, and attestation results.
What happens to a GPU rental's disk?
The rental's local disk is encrypted with a key you hold. We keep no backup and cannot recover it. If you lose the key or the rental ends before you copy your data off, the data is gone. When a rental ends we erase its memory and local storage before the GPUs serve anyone else.
Verification and attestation
How do I verify what you tell me?
Every lane session and every rental comes with an attestation report signed by the hardware. Intel signs the processor quote. NVIDIA signs the GPU report. You can check each one with its own tools without us.
See Proof.
What does attestation not tell me?
It tells you which hardware ran which software, as measured. It does not tell you the software has no bugs.
Compelled disclosure and legal
What do you do if a government demands my data?
We tell you before we respond unless the law forbids notice. We challenge a demand we believe is unlawful or too broad. We cannot produce Customer Content in plaintext. We hold no key to it. The response states that.
What could you hand over if a demand arrived?
Account records: names, work emails, titles, billing details, reservation records, signed documents, and support messages. Operational logs hold timings, sizes, error codes, and attestation results. Customer Content is not on that list. It exists in plaintext only inside the confidential virtual machine.
Do you sign a Business Associate Agreement?
Yes. Our standard one is published. Do not send protected health information until both parties have signed it.
Subprocessors and trust boundaries
Who are your subprocessors?
Stripe for payments, Convex for the reservation database, Railway for the website, Notion for internal reservation records, and Google Workspace for email. None of them receives Customer Content.
See Subprocessors.
Is the data center operator a subprocessor?
No. The operator provides space, power and network. It has no logical access to any server and no access to Customer Content.
How do I learn of a new subprocessor?
We give at least 30 days' notice by email before adding or replacing one. You may object on data protection grounds in that time.
Retrieval and outside access
Can a lane reach the internet?
A lane has no internet access of its own. It runs a model on the prompts and files you send and returns the outputs.
Where is my content processed?
Only inside a confidential virtual machine in Texas. Sections 5.1 and 7.1 of the DPA.
Does any subprocessor get access to my content?
No. No subprocessor is ever given access to Customer Content in plaintext. Section 8.3 of the DPA.
See Subprocessors.
What about files I upload for the model to read?
Files are Customer Content. They follow the same retention rules as prompts. A persistent lane holds them in encrypted memory and drops them after one hour idle.
Supply chain and build integrity
How do I know the software inside the machine is the software you say?
Every change to the software inside the confidential environment is reviewed and shows up as a new measurement in the attestation report. If the measurement changes, you can see it.
Which models do lanes run?
Open weight models made by third parties. A lane runs Nemotron 3 Ultra from NVIDIA. You agree to follow each model's license. We provide it with your order.
Compliance
What certifications do you hold?
None. We hold no third-party audit report. We publish the DPA, the Business Associate Agreement, and the controls in Schedule 2 of the DPA.
Are you HIPAA compliant?
There is no HIPAA certification. We sign a Business Associate Agreement. The controls in Schedule 2 of the DPA apply under it. Your own HIPAA duties stay with you.
Is the DPA behind a form?
No. It is published in full and needs no request.
Who can I not serve?
Customers in or controlled from a comprehensive US embargo, customers on a US restricted party list, and uses that develop weapons of mass destruction or missile systems.
See Supported regions.
Operational failure modes
What if an attestation report fails my check?
Tell us. We fix the failure or suspend fees for the affected service until a report passes. That is your sole remedy for breach of the warranty in section 11.1 of the Terms.
See Terms of Service.
What if you run out of capacity?
We queue or decline the work. We never move it out of Texas to make room.
What if I lose my rental's disk key?
The data is gone. We keep no copy and cannot recover it.
What if there is a flaw in the hardware or firmware?
We notify you within 48 hours after we learn of a flaw that could expose Customer Content in a confidential environment.
Threat model and limitations
What does confidential computing protect?
Intel TDX encrypts the memory of the machine your work runs on. On Blackwell GPUs the GPU memory and the NVLink between GPUs are encrypted too. Together they keep your data out of reach of anyone with access to the host, including us.
See The B300.
What does it not protect?
Network metadata, physical attack on the hardware, side channels such as timing and power, and patterns in the size and shape of requests.
See DPA, section 5.4.
Can a bug expose my data?
Yes. A flaw in the hardware, the firmware, or our own software could. Confidential computing lowers risk and does not remove it. Section 5.4 of the DPA.
Jurisdiction
Which state is my data processed in?
Texas. We process and store Customer Content only in data centers in the State of Texas. Section 7.1 of the DPA and section 11.1 of the Terms.
Do you serve customers outside Texas?
Yes. Customers outside Texas use the same lanes and rentals. Their Customer Content is processed only in Texas. Section 2 of the supported regions page lists who we cannot serve.
See Supported regions.
What happens if you run out of capacity in Texas?
We queue or decline your work. We never move work outside Texas for capacity. Section 7.2 of the DPA.
Can I require contractually that my traffic never leaves the state?
Customer Content never leaves Texas. You need no special clause for it. Sections 7.1, 7.2 and 7.4 of the DPA.
Which subprocessors sit outside Texas, and what do they see?
Stripe, Convex, Railway, Notion, and Google Workspace are all in the United States. We do not claim any of them processes in Texas. None of them receives Customer Content. They see Account Data: names, work emails, billing details, and reservation records.
See Subprocessors.
Does my data cross a state line to reach you?
The DPA covers Customer Content from the moment it reaches us. TLS ends inside the confidential virtual machine in Texas. Customer Content is never stored or processed outside Texas.
Can I audit you?
Yes. You may audit us once a year at your own cost on 30 days' notice. We may instead give you a report from an independent assessor. Section 12.2 of the DPA.
What happens to my data if we terminate?
Nothing is left to return. Ephemeral lanes keep nothing. Persistent lane state is dropped. Rentals are erased. We delete Account Data within 30 days after the account closes. We keep billing, tax, signed documents, and dispute records for as long as the law requires.
Who at Texas Inference can physically reach the machine?
The server is in a secured facility that requires multi-factor authentication. If Texas Inference needs to access the server, it notifies the customers using that equipment.
What law governs?
Texas law. Section 15.2 of the DPA and section 15.1 of the Terms.