Fortanix Confidential AI Protects Proprietary Model IP and Data for Secure AI Inference in Enterprise AI Factories.

Learn More

Securing the Open AI Stack: Fortanix Joins NVIDIA's Open Secure AI Alliance

Anuj Jaiswal
Anuj Jaiswal
Aug 3, 2026
2mins
Fortanix-joins-secure-ai-alliance-team

Fortanix joins NVIDIA and industry leaders in the Open Secure AI Alliance, bringing attestation-gated proof to the open tools the alliance is building. 

The pace of AI adoption has outrun the pace at which most organizations can secure it. Models are moving into production faster than security teams can inspect them, agents are taking actions on live data, and the infrastructure underneath all of it is being assembled from open and proprietary parts that no single vendor controls. Securing that reality is not something any one company can do alone. 

That is why Fortanix has joined the Open Secure AI Alliance, the industry effort led by NVIDIA to develop and share open technologies, techniques, and tools for protecting the entire AI stack, from the models themselves to the agent frameworks built on top of them. We're proud to stand alongside NVIDIA and dozens of leading technology and security companies committed to a simple principle: defenders should be able to inspect, adapt, and run advanced AI on their own infrastructure; not depend on trust they cannot verify. We'll be contributing our attestation and key-release architecture patterns to the alliance's shared work. 

Why an Open Approach to AI security Matters 

The alliance is built around an idea we've held since Fortanix was founded in 2016: security that can't be inspected can't be trusted. When defensive capabilities are locked inside opaque, proprietary systems, organizations are left to take security on faith, precisely when the stakes are highest. Open, inspectable tools give defenders the ability to study how something works, adapt it to their own environment, and deploy controls they actually understand. 

This is especially true in the regulated industries where Fortanix does much of its work. Healthcare, financial services, and government don't just need AI that performs well. They need AI that they can prove is secure to auditors, to regulators, and to their own boards. That proof has a name: HIPAA, FedRAMP, and SOC 2. These aren’t frameworks that accept "trust us" as an answer. The assurance has to come from evidence, not a promise. And evidence requires openness and verifiability at every layer of the stack. 

The Open Secure AI Alliance advances that goal by pooling research and building shared, open infrastructure across a multi-vendor ecosystem, so that no organization is forced to choose between innovation and control, and no critical capability sits behind a single point of failure. 

Where Fortanix Fits: From Open to Provable 

Openness answers one question — can I inspect it? The harder question in AI security is can I prove what actually ran? That's the gap Fortanix was built to close. 

Traditional security protects data at rest and in transit. But the moment an AI model actively processes data in memory, on a GPU, that data is exposed. It's the open window that attackers and even privileged insiders target. Confidential AI closes that window by applying hardware-enforced Trusted Execution Environments to the entire AI lifecycle, so data and models stay encrypted even while they're being used. 

Fortanix brings a specific and complementary strength to the alliance: turning open, inspectable systems into provable ones. Our platform delivers composite attestation cryptographically verifying both the CPU and the GPU together as a single trust decision before any data or model is released.  

Encryption keys, held in our FIPS 140-2 Level 3 certified Data Security Manager, are only released once that verification succeeds. No attestation, no keys, no access. The result is not a claim that a workload is trustworthy, but cryptographic proof of exactly what code ran, on what hardware, and who touched it. 

This work sits directly on top of our collaboration with NVIDIA. Fortanix already extends Confidential AI to NVIDIA's confidential-computing GPUs, including the latest Hopper and Blackwell architectures, so that organizations can run sensitive and agentic AI workloads with security that is enforced by hardware and verified by attestation, not assumed. 

Joining the Open Secure AI Alliance is a natural extension of that partnership: a way to bring provable, attestation-gated trust to the open tools and shared infrastructure the alliance is building. 

We're already extending this same attestation-gated model through our work with Dell, HPE, Cisco, SuperMicro, RedHat, CrowdStrike Secure AI Factory with NVIDIA, proof that this isn't a theoretical architecture, but one already running in production enterprise environments. 

Building a Défense Layer the Whole Industry Can Rely On 

The threats facing AI models and IP theft, data leakage during inference, tampered or poisoned workloads, and compromised infrastructure don't respect vendor boundaries. Neither should the defenses. Collective, open work will always outpace fragmented, siloed effort, and that's the wager the alliance is making. 

Fortanix is joining because this is the work we've been doing all along, now with more partners pulling in the same direction. Open tools make AI security inspectable. Confidential AI makes it provable. Together, they give defenders something they've been missing: the ability to adopt AI on their most sensitive data without giving up control, visibility, or proof. 

We're glad to be part of it, and we're just getting started. 

To learn more about how Fortanix Confidential AI protects data and models in use, visit fortanix.com.

Share this post:
Fortanix-logo
ASK AI ABOUT FORTANIX

4.6

star-ratingsgartner-logo

As of January 2026

SOCISOPCI DSS CompliantFIPSGartner Logo

US

Europe

India

Singapore

4500 Great America Parkway, Ste. 270
Santa Clara, CA 95054

+1 408-214 - 4760|info@fortanix.com

High Tech Campus 5,
5656 AE Eindhoven, The Netherlands

+31850608282

UrbanVault 460,First Floor,C S TOWERS,17th Cross Rd, 4th Sector,HSR Layout, Bengaluru,Karnataka 560102

+91 080-41749241

T30 Cecil St. #19-08 Prudential Tower,Singapore 049712