Research Cluster · Free for verification work

VCF is providing free bare-metal infrastructure for verification research.

Hardware verification, side-channel analysis, TEE research, and network inspection need physical, bare-metal access to datacenter-grade GPUs that no cloud provider offers. So the Verifiable Compute Foundation, an independent nonprofit, is providing it — the Foundation's cluster opens to the community in November, with the Foundation making all access decisions and Lucid building and operating the machines on its behalf. Verification architectures developed here graduate to the red-team cluster, where they are attacked.

◷ OPENING NOVEMBER · A VERIFIABLE COMPUTE FOUNDATION CLUSTER · BUILT & OPERATED BY LUCID

The deepest questions in AI verification live below the OS, and no cloud will hand you the machine.

01

Physical, supervised access to frontier silicon: the root of the machine, not a virtualized slice of it.

02

Reconfigurable to your experiment. Need a different setup? We rebuild the rig to spec.

03

Free for qualifying safety & verification research. Access is decided by the Verifiable Compute Foundation.

01 — Machines

Frontier silicon, multi-vendor by design.

Ten accelerators across five SKUs, because real verification can't assume one vendor's chip. Bare-metal, with root access to every one.

10

Accelerators

5

SKUs

2

Vendors

Every machine is bare-metal, with BIOS/UEFI and BMC-level root access: NVIDIA B300, H200, H100, A100 and AMD Instinct MI355X.

02 — Frontiers

Five layers down the machine.

We don't hand you a bag of instruments. We open the whole stack, from what a workload reveals at the top to the silicon at the bottom. Each layer is a research frontier a cloud keeps sealed.

LAYER 00

Workload Forensics

Read what a GPU is doing from how it behaves. Side-channel analysis of workload behavior (distinguishing training from inference, and fingerprinting the model on the accelerator) from power and emission signatures.

BEHAVIOR
LAYER 01

Trusted-Boundary Probing

Test the walls of the enclave. Probe TEE and confidential-computing boundaries under real datacenter conditions, where the guarantees either hold or leak, and only physical access can tell you which.

ENCLAVE
LAYER 02

Fabric & Interconnect

Watch and bend the network. Passive TAPs across the interconnect, NIC-level experiments, and controlled network manipulation: observe every packet, or inject conditions no production fabric would let you.

FABRIC
LAYER 03

Firmware & Root of Trust

Get beneath the operating system. Firmware instrumentation, boot-chain inspection, and BIOS/UEFI and BMC-level control: the ground truth every higher-level attestation ultimately rests on.

FIRMWARE
LAYER 04

Silicon In-Path

Put your own logic in the data path. Reconfigurable DPUs, FPGAs, and SmartNICs sit between the accelerator and the world, so you can build the observation (or enforcement) point your experiment needs, in silicon.

SILICON

Need a different setup? We reconfigure the cluster to meet your research needs.

03 — Access

Get access.

Free access

Fair-share

This is the Foundation's cluster: the Verifiable Compute Foundation provides the compute and decides who gets access, allocating it at no cost to qualifying groups through an open fair-share process. Lucid procures and operates the hardware on the Foundation's behalf, and takes no part in allocation decisions.

Dedicated capacity

On request

If your needs exceed the free allocation, dedicated remote capacity on the cluster is also available: reserved time and custom instrumentation for larger or confidential programs.

Weekly office hours

Join us every Tuesday, 10–11 AM Pacific, to talk through research and deployment possibilities.