Home›Products›Bare Metal
The whole machine to a single tenant: no container layer, no neighbours, all of the hardware is yours. Not something everyone needs — but for the people who do need it, there is no other option. Not live today.
The email address is a placeholder; the mailbox opens soon.
The difference
On a pod you share the machine, but the container separates you. On bare metal there is nobody to share with — and no layer doing the separating either.
You run inside a container, the GPU is assigned to you, and your secrets never land on the host disk. It starts in seconds, you pay per second, and you stop it whenever you want. You do not have direct control over the machine's kernel, driver version and other hardware.
The entire machine is reserved for a single tenant. There is no container layer; you install the operating system, kernel, driver and storage layout yourself. In return, startup takes minutes rather than seconds, and even though the rental is per-second, the machine is not handed to anyone else until you release it.
Who wants it
Some audit frameworks rule out shared hardware outright; they want tenant separation at the physical machine level, not the container level. In healthcare, finance and public-sector work this arrives as a requirement, not a preference. Together with region pinning, it completes the answer you give your compliance team.
Loading your own kernel module, pinning a driver version, changing kernel parameters for low latency, setting up a special filesystem. These are jobs that cannot be done from inside a container. Teams profiling the hardware to chase the last ten percent belong in this group too.
On a training run lasting weeks, it matters that the machine stays put, that a neighbouring workload does not tie up the disk and the network, and that performance is the same day after day. A long run buys predictability — the thing a spot marketplace naturally does not give you.
The honest status
Bare metal asks for the exact opposite of the architecture we built on an untrusted-host assumption. So it is tied to the audited tier rather than to the marketplace at large.
What keeps customer secrets off the host disk today is the container boundary and encryption. When we hand over the bare machine, that boundary is gone. The only thing that can take its place is that the party operating the machine has been audited — that is, Verified.
Moving from one tenant to the next, you need to be able to prove that the disk was genuinely wiped, that the firmware was not tampered with, and that the machine returned to a known state. Without an audit and verification process, that proof stays a promise; we are not selling promises.
What a customer asking for bare metal usually really wants is paperwork: region pinning, audit trails and formal frameworks. Some of that exists today, some of it is in progress. SOC 2 Type I has not been obtained by us; it is in progress, and we do not write as if it were done.
The phase order comes from our technical plan and is a plan, not a commitment. We are not giving dates; if it slips we will write it in the changelog. The compliance commitments that hold today, and which document sits at which stage, are written out separately on the sovereignty and security pages.
In the meantime
Let's talk
Compliance, the kernel, a long run — write down the reason. Your answers will decide who we build bare metal for and under which audit conditions.
The mailbox opens soon.