Confidential GPU cloud and bare-metal capacity
Find GPU capacity that can be evaluated for confidential AI. The marketplace separates supported hardware, verified public listings, provider enablement, and deployment evidence.
Dataset checked 2026-09-08. Prices and availability may change.
Current public offers
Source-linked records with the published billing context preserved.
| Provider and node | Region | Term | Normalized price | Source |
|---|---|---|---|---|
| Latitude.sh1x H100 80GB (g3.h100.small) | Not published | no commitment | $1.68/GPU-hr$1.68/hr ($1,230/mo) | Provider source ↗Checked 2026-08-20 |
| Cirrascale8x RTX PRO 6000 (Server Edition) | US | 1-mo min | $1.71/GPU-hr$9,999/mo (annual commit $7,999/mo) | Provider source ↗Checked 2026-08-20 |
| Qubrid AI8x H100 80GB bare-metal server | Not published | 12 months | $1.90/GPU-hr133414.80 | Provider source ↗Checked 2026-08-23 |
| HetznerGEX131: 1x RTX PRO 6000 Blackwell Max-Q 96GB | Germany / Finland | monthly | $1.92/GPU-hr1197.30 | Provider source ↗Checked 2026-08-23 |
| Voltage Park8x HGX H100 SXM | Not published | no commitment | $1.99/GPU-hrFrom $1.99/GPU/hr (no contract) | Provider source ↗Checked 2026-08-20 |
| Leaseweb4x H100 (HP DL385 G11) | London | term not stated | $2.02/GPU-hr£4,337.86/mo | Provider source ↗Checked 2026-08-20 |
| Tscalebm-h100-8x-sxm5 | Lagos, Nigeria | 1 month | $2.05/GPU-hr1-year reserve effective rate | Provider source ↗Checked 2026-08-23 |
| Vultr8x H100 80GB SXM (HGX H100) | Not published | term not published | $2.30/GPU-hr$2.300/GPU/hr (pre-paid contract) | Provider source ↗Checked 2026-08-20 |
| FluidCore8x H100 80GB bare-metal node | Not published | hourly | $2.36/GPU-hr18.88 | Provider source ↗Checked 2026-08-23 |
| CoreWeave8x RTX PRO 6000 Blackwell bare-metal GPU node | North America / Europe | on-demand | $2.50/GPU-hr20.00 | Provider source ↗Checked 2026-08-23 |
| FluidCore8x H200 141GB bare-metal node | Not published | hourly | $2.51/GPU-hr20.08 | Provider source ↗Checked 2026-08-23 |
| Clore.ai8x H200 Colorado bare-metal node | Colorado, USA | 360 days | $2.59/GPU-hr179020.80 | Provider source ↗Checked 2026-08-23 |
| Taiga Cloud8x H100 SXM | UK / PT / SE / NO | hourly | $2.60/GPU-hrFrom $2.60/GPU/hr (bare-metal tier) | Provider source ↗Checked 2026-09-04 |
| Leaseweb1x H100 (HP DL385 G11) | Frankfurt | term not stated | $2.61/GPU-hr€1,638.57/mo | Provider source ↗Checked 2026-08-20 |
| Gcore8x H100 SXM (bm3-ai-1xlarge-h100-80-8) | Not published | hourly | $2.64/GPU-hr18.16 | Provider source ↗Checked 2026-09-04 |
| ScalewayEM-T620E-H100: 2x H100 80GB | PAR-2 | monthly | $2.78/GPU-hr3499.99 | Provider source ↗Checked 2026-09-08 |
| Leaseweb1x H200 (HP DL385 G11) | London | term not stated | $2.80/GPU-hr£1,503.02/mo | Provider source ↗Checked 2026-08-20 |
| Taiga Cloud8x H200 SXM | Chester, UK | hourly | $3.00/GPU-hrFrom $3.00/GPU/hr (bare-metal tier) | Provider source ↗Checked 2026-09-04 |
| Qubrid AI8x H200 141GB bare-metal server | Not published | 12 months | $3.00/GPU-hr210240.00 | Provider source ↗Checked 2026-08-23 |
| Latitude.sh8x RTX PRO 6000 (g4.rtx6kpro.large) | Not published | no commitment | $3.00/GPU-hr$24.00/hr ($17,520/mo) | Provider source ↗Checked 2026-08-20 |
| DataPacket8x H200 NVL | Not published | 3–6-mo prepay typ. | $3.06/GPU-hr15368 | Provider source ↗Checked 2026-09-08 |
| Gcore8x H200 | Not published | hourly | $3.17/GPU-hr21.84 | Provider source ↗Checked 2026-09-04 |
| Hostrunway1x H100 (GPU Montreal 5) | Montreal | no lock-in | $3.25/GPU-hr$2,370/mo | Provider source ↗Checked 2026-08-20 |
| Hostrunway1x H100 dedicated GPU server (dual EPYC 7543) | Montreal | no lock-in; 15% discount at 12 months | $3.42/GPU-hr2496.00 | Provider source ↗Checked 2026-08-29 |
Showing 24 of 79 matching records. Browse all listings.
Define the complete protected system
Confidential GPU infrastructure combines a supported CPU trusted execution environment, a supported GPU in the required confidential mode, protected CPU–GPU communication, evidence verification, and controlled key release. The provider must operate the full path.
- Exact CPU TEE and host platform
- Exact GPU SKU, form factor, count, and topology
- Firmware, VBIOS, driver, and confidential mode
- CPU and per-GPU attestation evidence
- Verifier policy and key-release failure behavior
Procure capacity with evidence
Ask suppliers to separate hardware capability from an enabled service. Record the responsible verifier, evidence format, freshness checks, reference measurements, debug-mode policy, network and storage boundary, and the procedure for upgrades or replacement devices.
Questions buyers ask
What is a confidential GPU cloud?
It is a service that combines a supported CPU TEE with supported GPU confidential-computing mode and an attestation and key-release workflow operated for customer workloads.
Is dedicated bare metal automatically confidential?
No. Dedicated hardware can reduce tenancy risk, but confidential computing requires a supported protected mode and independently verifiable evidence.
Which GPUs should buyers evaluate?
Support is SKU- and platform-specific. Current planning commonly begins with named NVIDIA H100, H200, B200, B300, or RTX PRO 6000 Server Edition configurations and the vendor compatibility matrix.
