Imagine hiring someone to mind your house, then discovering that the job comes with permission to read your diary. Computing has long tolerated a version of that arrangement. The administrator maintains the machine. The machine handles the secrets. The boundary between those responsibilities can be surprisingly thin.
Fortanix makes that boundary its business. The company sells tools for controlling encryption keys, finding weak cryptographic arrangements and protecting sensitive work while it runs. The last part is the intriguing one. A locked file is easy to picture. A locked file that remains protected while an application uses it requires a different mental model.
- Keep custody: centralize the keys that let applications decrypt sensitive information.
- Check the room: verify a protected computing environment before releasing secrets.
- Use the data: support analytics and AI without granting the infrastructure operator ordinary access to the contents.
- Read the small print: hardware, application design and access policies determine what protection you actually get.
01 / The secret has to go to work
Encryption protects information in several distinct situations. Stored records can be encrypted on disk. Network traffic can be protected in transit. But an application must eventually work with usable information. Protecting the file cabinet and the delivery van leaves a question about the desk where the paperwork gets opened.
Confidential computing addresses that desk. Hardware creates a trusted execution environment, or TEE, that isolates a workload from parts of the surrounding system. In Fortanix’s early architecture, Intel SGX supplied the enclave boundary. Its current Confidential Computing Manager also manages supported confidential CPU and GPU environments.
The distinction matters: this is hardware-enforced isolation, with encryption protecting memory and data movement according to the platform. It is not a claim that ordinary software somehow performs every operation on ciphertext. Usable data exists inside the protected environment. The ambition is to keep it inaccessible outside that boundary.
Fortanix adds a second question: how do you know the remote room is really protected? Attestation provides cryptographic evidence about the environment. A policy can then permit key release to a verified workload. An operator’s promise becomes a condition the system can check.
02 / A fine theory meets a bank tender
Ambuj Kumar and Anand Kashyap founded Fortanix in 2016. They had been undergraduate classmates, then reconnected in the Bay Area after working in different parts of security. Foundation Capital incubated the business in its Menlo Park offices. The investor’s recollection places the company’s beginnings in that rather modest setting.
In a 2022 company interview, Kashyap describes a cold email reaching a bank CISO during a procurement process. Fortanix’s product initially missed much of the tender’s requirements. The team implemented features in days, presented its vision and won the account, according to his account. The theory survived by becoming a product a buyer could actually use.

This is a useful detail because cryptography can seduce an engineer into thinking the hard part is finished when the mechanism works. A bank buys an operating system of responsibilities: access rules, integration, administration, continuity. The practical lesson is an editorial inference from the tender story: give the mechanism a demanding real workflow early enough for the workflow to change the product.
03 / The keys are an enterprise of their own
Fortanix’s Data Security Manager, or DSM, is the commercial machinery around key custody. It generates, stores and manages cryptographic keys; handles secrets such as credentials; and supports tokenization, database encryption integrations and code signing. Organizations can adopt SaaS or appliance deployment options rather than treating every cloud and database as a separate island.
A key has a life. Someone creates it. Applications depend on it. Permissions change. It rotates or expires. Eventually, it must be retired without destroying information the organization still needs. The mathematical object may be small; its administrative consequences are not.
In August 2024, Fortanix added file-system encryption to DSM, including policies governing which users and processes can access plaintext. Quorum approvals can require multiple people to authorize sensitive actions. That is a recognizably human answer to a technical risk: some decisions should be inconvenient for one person to make alone.
“Funding is just a pitstop.”Anand Kashyap, co-founder, in Fortanix’s 2022 retrospective
Before fixing cryptography, there is the awkward task of finding it. Key Insight inventories keys and related data services across supported environments, flags risks and helps prioritize remediation. Think of it as answering which cupboard holds which key, and whether that key still opens a door anyone should be using.
Fortanix sells to enterprise security and technology teams, particularly those with sensitive information and regulatory obligations. Its business includes software, subscriptions, appliances and services. The public trial offering advertises 30 days for DSM, Key Insight and Confidential Computing Manager. A trial is a useful place to measure integration work; it is not a budget for a production deployment.
04 / Two owners, neither eager to share
Healthcare makes the problem unusually clear. A hospital holds records it must protect. An AI developer owns a model it would rather not reveal. Each party has something the other needs. Neither party is being unreasonable by withholding it.
Fortanix’s BeeKeeperAI case study describes using confidential computing and DSM to protect patient information and algorithm intellectual property. Data stewards can verify an application’s enclave before supplying protected data. The application gets to work on the records without making those records generally available to its owner or the infrastructure administrator.
The relationship has a dated public beginning: in October 2020, UCSF, Fortanix, Intel and Microsoft Azure announced a collaboration to establish privacy-preserving clinical AI workflows. Microsoft also lists Fortanix among confidential AI partners. The use case is more illuminating than a customer-logo parade: it shows why two cautious organizations might want the same protected room.
- 01PackageEncrypt the data and model artifacts.
- 02VerifyCheck the hardware and workload evidence.
- 03ReleaseSupply keys only when policy permits.
- 04ComputeRun the authorized workload inside the protected environment.
05 / The AI factory needs a key desk
That same arrangement now extends to GPU infrastructure. In October 2025, Fortanix announced a joint solution with NVIDIA for secure and sovereign agentic AI. Its design combines a confidential AI pipeline, CPU and GPU attestation, and key release controlled by an HSM. Proprietary model weights join patient records and financial information on the list of things worth protecting.
Armet AI packages an enterprise AI platform with governance and guardrails alongside confidential computing. This is an expansion of the original premise into a new workload: keep control of valuable material when useful computation requires placing it on complicated infrastructure.

There is also a longer clock to watch. Fortanix’s February 2025 cryptographic update included support for ML-KEM and ML-DSA. Quantum readiness requires knowing where cryptography is used and planning transitions across dependent systems. Adding algorithm support is one part of that work, not proof that every connected application has migrated.
06 / What the money buys, and what it cannot
Fortanix announced an $8 million Series A in June 2017, a $23 million Series B in January 2019 and a $90 million Series C in September 2022. The last announcement put total funding above $122 million. Goldman Sachs Asset Management’s Growth Equity business led that round. These are dated financing figures, not software prices or a current valuation.
Round size, not revenue. The Series C announcement reported total funding above $122m.
The competitive comparison is less tidy than a startup pitch. Thales CipherTrust also centralizes enterprise keys and policies. Other suppliers offer confidential computing platforms. Fortanix’s distinguishing proposition is the combination of hardware-backed key custody, cryptographic risk visibility and management of protected computation. A buyer should test that combination against an actual workload, rather than assume a category name settles the choice.
In September 2026, Fortanix reported appearing as a Sample Vendor in five Gartner Hype Cycle reports. That indicates recognition across several technology discussions; it is not an endorsement or a measured result from a customer deployment.
The practical limits belong in the buying conversation. Hardware and software must support the chosen protection. Key-service availability becomes part of application availability. A verified environment can still run an application with bad permissions or produce an overly revealing answer. Isolation does not decide whether a person should have asked the question.
What can a reader copy? Start with one sensitive workflow. Identify its data, keys, administrators and authorized outputs. Specify what the infrastructure operator must be unable to see. Then measure the proposed system against those requirements, including failure and recovery. Fortanix makes a business out of that exercise. The exercise itself is useful before anyone signs a contract.
Fortanix website ↗ · Company blog ↗ · News ↗ · LinkedIn ↗ · X ↗ · Facebook ↗ · GitHub ↗ · YouTube videos ↗