Including what the receipt does not prove, and what our own servers can still see.
Open-weight models up to 122B parameters, served on attested Intel TDX hardware with NVIDIA H100 GPUs. You pick one, or let Amnesia AI® pick. There is no route out to a provider that could read your work: the endpoint allowlist rejects anything that is not an attested enclave.
Your messages are encrypted to the enclave, so our gateway relays them without being able to read them. What it does see is the work your agent does around them: tool calls and their arguments, the file paths and URLs it touches, images, and message sizes and timing. We publish that list in full rather than describing ourselves as private.
No. The enclave runs in the cloud and you run a normal app on a normal laptop. That is the point: confidentiality closer to a local model, with compute a laptop cannot reach.
Open any attested reply and export its signed report as JSON. It contains the Intel TDX quote, the NVIDIA GPU evidence and the TLS binding, and it can be checked against Intel and NVIDIA directly, by someone who has never run Amnesia AI®.
Which exact model weights ran, which is still the provider's word rather than a measurement. And it is not a claim that nothing about a turn is visible: tool calls, the file paths and URLs your agent touched, sizes and timing all stay outside the encrypted content. The app says the same thing on every receipt.
Usage is pay-as-you-go in US dollars of credit, on every plan. You are charged the model provider's raw cost plus a flat 30% convenience fee, which covers operations and payment processing. The same fee applies on every plan: there is no tiered markup and no per-message charge. Your subscription buys a monthly credit grant; anything beyond it draws on credit you top up.
It depends on the model and the length of the work, which is why we bill the real number instead of an invented unit. The app shows your remaining credit and this month's token count in the account menu, and transcription is billed per second of audio rather than per token.
All of them, on every plan including Free. Amnesia AI® serves open-weight models up to 122B parameters, each on its own attested enclave endpoint. Models are not a tier gate; credit is.
The app shows it as unverified rather than quietly passing it off as attested. The shield in the toolbar reflects the whole conversation, so one reply without evidence is visible immediately.
A Recovery Kit is issued at setup. We cannot reset it for you: that is the point.
Encrypted export is free forever, on every plan, with a standalone verifier binary that runs without Amnesia AI®. Your data leaves with you.
Still unanswered? support@amnesia.ai
Start free, attach a real document, and open the report on the reply it produces.
Experience confidential AI