HomeProductsBare Metal

Bare Metal

The whole machine to a single tenant: no container layer, no neighbours, all of the hardware is yours. Not something everyone needs — but for the people who do need it, there is no other option. Not live today.

Soon Depends on the Verified tier · Phase 3 Today: container-based pods

The email address is a placeholder; the mailbox opens soon.

The difference

The real difference between a pod and bare metal.

On a pod you share the machine, but the container separates you. On bare metal there is nobody to share with — and no layer doing the separating either.

GPU Pod (today)

You run inside a container, the GPU is assigned to you, and your secrets never land on the host disk. It starts in seconds, you pay per second, and you stop it whenever you want. You do not have direct control over the machine's kernel, driver version and other hardware.

Bare Metal (planned)

The entire machine is reserved for a single tenant. There is no container layer; you install the operating system, kernel, driver and storage layout yourself. In return, startup takes minutes rather than seconds, and even though the rental is per-second, the machine is not handed to anyone else until you release it.

Who wants it

Three concrete reasons.

Compliance

Some audit frameworks rule out shared hardware outright; they want tenant separation at the physical machine level, not the container level. In healthcare, finance and public-sector work this arrives as a requirement, not a preference. Together with region pinning, it completes the answer you give your compliance team.

Custom kernel and driver

Loading your own kernel module, pinning a driver version, changing kernel parameters for low latency, setting up a special filesystem. These are jobs that cannot be done from inside a container. Teams profiling the hardware to chase the last ten percent belong in this group too.

Long training runs

On a training run lasting weeks, it matters that the machine stays put, that a neighbouring workload does not tie up the disk and the network, and that performance is the same day after day. A long run buys predictability — the thing a spot marketplace naturally does not give you.

The honest status

Why does it depend on the Verified tier?

Bare metal asks for the exact opposite of the architecture we built on an untrusted-host assumption. So it is tied to the audited tier rather than to the marketplace at large.

Take away the container and you take away the isolation

What keeps customer secrets off the host disk today is the container boundary and encryption. When we hand over the bare machine, that boundary is gone. The only thing that can take its place is that the party operating the machine has been audited — that is, Verified.

Wipe and handover safety has to be measurable

Moving from one tenant to the next, you need to be able to prove that the disk was genuinely wiped, that the firmware was not tampered with, and that the machine returned to a known state. Without an audit and verification process, that proof stays a promise; we are not selling promises.

The compliance package is not finished yet

What a customer asking for bare metal usually really wants is paperwork: region pinning, audit trails and formal frameworks. Some of that exists today, some of it is in progress. SOC 2 Type I has not been obtained by us; it is in progress, and we do not write as if it were done.

Phase 0 — Container-based GPU podsWorking today
Phase 1 — Our own host network and the scorecardAudit data accumulates here
Phase 3 — Verified tier and sovereignty packageAudited data centres, SLA
After that — Bare metalOn top of the Verified tier

The phase order comes from our technical plan and is a plan, not a commitment. We are not giving dates; if it slips we will write it in the changelog. The compliance commitments that hold today, and which document sits at which stage, are written out separately on the sovereignty and security pages.

In the meantime

How far can you get today?

Multiple GPUs in one machine can be rented today — we wrote the limit on the clusters page.
Your own image works: everything in the stack above the kernel is yours to decide.
Region pinning is enforced today as well: the data stays in whichever country it is meant to stay in.
If you have your own hardware you can add it to the pool — become a host.

Let's talk

Why do you need a bare machine?

Compliance, the kernel, a long run — write down the reason. Your answers will decide who we build bare metal for and under which audit conditions.

The mailbox opens soon.