Envelope encryption
SoftwareKMS-backed envelope encryption protects .tic artifacts at rest and in transit. Content is encrypted under envelope keys so artifacts stay protected outside your trust boundary until policy allows release.
Product
Performance
Representative results from scoped evaluations.
30%
Lower memory traffic on BF16 LLM workloads
Exact
Model output preserved bit for bit (no quantization)
Up to 2×
Lower latency vs cuBLAS baseline (evaluated workloads)
Overview
ISIRO Runtime sits between models and the existing inference stack. Compile your model once into a compact, execution-native .tic representation, then deploy through ISIRO Runtime, which integrates the inference frameworks you already use as targets.
TIC Shield™ adds security and control for protected deployments.
A dashboard and an OpenAI-compatible API with ISIRO observability built in provide visibility into performance, resource utilization, and TIC Shield status.
Supported today
ISIRO Runtime supports BF16 vLLM workloads on NVIDIA GPUs in on-prem and cloud deployments today. Support for additional inference frameworks and hardware platforms is on the roadmap.
Add-on
Security and control of .tic artifacts. KMS-gated cryptographic protection and execution-time control.
KMS-backed envelope encryption protects .tic artifacts at rest and in transit. Content is encrypted under envelope keys so artifacts stay protected outside your trust boundary until policy allows release.
Models are signed with KMS-backed keys so ISIRO Runtime can verify integrity and provenance before load.
TIC Lock™ binds the model's in-memory representation to each deployment, with a dedicated KMS lock key ID on record, so GPU memory is not a portable checkpoint across environments. Optional hardware-backed confidential computing stacks on top where you require it.
When hardware isolation is required, TIC Shield supports attestation-gated key release from your KMS and integration with confidential-computing environments. Supported today: NVIDIA Confidential Computing and KMS attestation-gated key release. Additional TEE platforms on our roadmap.
SoftwareSoftware: Built-in software-based protections. No inference speed penalty when activated.
Run in cloud or on-prem environment without sharing your model. Compare exact output, performance, and cost indicators against your baseline.
Prefer email? hello@isiro.ai