One tenant, one machine
A machine serves one renter at a time. Your container gets root and the machine's GPU, CPU and memory. It does not get privileged mode, and the host's own Docker socket is not mounted into it.
An encrypted volume per rental
All of your data is kept on a separate LUKS-encrypted volume. A new random key is generated for every rental and held only in memory. When you delete the instance, the key is destroyed and the volume is rebuilt. Only a machine whose wipe succeeded returns to the available pool; a failed wipe takes the machine offline.
What this means for you
- There is no persistent storage between rentals. Copy results out before you delete.
- Nobody else can read your volume after you delete it, including the next renter.
- Your data is on the machine while the instance runs. If your work needs protection beyond that, encrypt it yourself as well.
What we cannot promise
Running Docker inside your container, and giving containers direct access to the high-speed network cards on multi-node sizes, depend on runtime support that we are still validating on the hardware. Do not plan work that needs either until the console lists it for your size.
Frequently asked questions
Can the next renter recover my files?
No. The key for your volume exists only in memory during your rental and is destroyed when you delete the instance.
Can I keep my data between rentals?
No. Copy anything you need to your own storage before deleting.