Integrate

Where the card sits. Where plaintext stops.

Four patterns. Each names input, compute, output, and the plaintext boundary. Screenshot this page for your own team.

Card in your own server

In

U100 in an existing 2U host. Customer encrypts at the edge.

Runs

RainDB or SDK against an encrypted store. Host memory holds ciphertext.

Out

Encrypted results return to the key domain. Decrypt only where the customer holds keys.

Plaintext boundary

Plaintext exists at the client encrypt/decrypt step. Not on the host. Not on the card during compute.

Encrypted inference tier

In

Multi-card pack beside existing GPUs. Prompts enter encrypted.

Runs

ZChat on Umbra. Optional GPUs in a mixed pack are a separate trust domain.

Out

Encrypted completions. Customer decrypts in custody.

Plaintext boundary

Umbra cards do not see plaintext. If a mixed pack uses GPUs for unencrypted stages, those GPUs see plaintext. State that in the design review: do not assume the whole rack is ciphertext.

Node deployment

In

N4 or N8 as a finished 4U system in an accredited rack.

Runs

ZipLogic owns thermals, burn-in, and acceptance. Same runtime as the card.

Out

Same encrypted results. Node throughput is estimated until end-to-end measurement completes.

Plaintext boundary

Same as the card: plaintext at customer key custody only. Host-attached; no on-card network.

Multi-party

In

Two parties, two key domains, one compute node.

Runs

Each party contributes ciphertext. Correlation runs on Umbra.

Out

Policy-governed aggregates only. Source holdings never open on the shared fabric.

Plaintext boundary

Plaintext, if any, is at each party’s encrypt step and at authorised release: not at the shared node.

Evaluation to production is a path, not a leap.