For neoclouds and GPU providers
Show a lab what stops cross-tenant weight theft.
Hilt detects cross-tenant weight theft on GPU fabric. The most valuable thing on your fabric is a customer's weights, and SOC 2 plus a runtime agent cannot show a lab what stops one tenant taking another's. Hilt watches weight movement at the kernel, off the serving path, without reading the weights.
The cell nobody fills
The most valuable thing on your fabric is a customer's weights, and you cannot show a lab what stops one tenant taking another's. SOC 2 Type II plus Falco across the estate is isolation plus runtime. It still leaves that cell empty.
Why isolation and runtime tooling do not close it
- Posture tools show where the weights sit and who could reach them, agentless and hostless. They are blind to a process reading a weight file and shipping it over an SSH tunnel.
- Cloud audit logs reconstruct the move in the post-mortem. CloudTrail-based detection lags 5 to 15 minutes and never sees the in-VM weight read, where it actually happens.
- Syscall runtime agents fire single-event heuristics:
scplaunched,/etc/shadowread. No data semantics, no read-then-send, no identity. The technique, not the weights leaving. - Isolation and attestation wall off the escape and attest the controls exist: a wall, not a tripwire behind it. NVIDIAScape is the CVE that defeats the wall, and the attestation is point-in-time, not a detector.
Hilt is the tripwire behind the wall. Kernel-level, identity-resolved, off the serving path, and it never reads the weights.
The proof runs on your hardware. Bring your kernel and we will bring the teardown.