High-Performance Computing. Fully Secured.
Run Slurm batch jobs and GPU-accelerated AI training on your own infrastructure, with end-to-end encryption and zero admin access to your data. Scale across nodes, fine-tune models on regulated datasets, and keep your code, weights, and results inside a secure enclave assessed at CMMC Level 2.
[researcher@vm-secure ~]$ sbatch analysis.sh
Submitted batch job 48217[researcher@vm-secure ~]$ squeue --me
JOBID PARTITION NAME USER ST TIME NODES NODELIST(REASON)48217 secure analysis research R 0:42 4 node-[01-04]
48218 gpu train_mo research PD 0:00 8 (Resources)
[researcher@vm-secure ~]$ sacct -j 48215
JobID State Elapsed------------ ---------- ----------48215 COMPLETED 01:23:07
[researcher@vm-secure ~]$ How It Works
From sbatch to Results, Fully Encrypted
Same Slurm commands. Same workflow. Zero exposure to administrators. Batch jobs, MPI, and GPU training runs all follow the same path.
Submit
$ sbatch job.shSubmit jobs with the standard Slurm commands you already use. No proprietary APIs, no rewritten job scripts.
Schedule
queued -> partition: secureGlobal Slurm allocates resources across the cluster. It sees CPU, memory, and GPU requests, never your code or data.
Execute
RUNNING on node-01..04Encrypted worker VMs spin up as Slurm nodes, CPU or GPU. Your job, model weights, and data stay inside LUKS-encrypted storage on an isolated network.
Results
COMPLETED exit:0Output is written to encrypted project storage. Worker VMs are destroyed and their keys discarded.
Researchers use the same sbatch, srun, squeue, and sacct commands they already know. The security happens below the application layer. See how the split-instance architecture works.
The tiCrypt Platform
Your Data Is Restricted. Your Research Shouldn't Be.
Slurm-managed HPC clusters, GPU-backed AI workloads, encrypted virtual machines, and full CMMC/NIST compliance in a single platform.
Run Complex Workflows on Encrypted Clusters
tiCrypt separates scheduling from execution using multiple Slurm instances. A global instance handles resource allocation and accounting, while per-project local instances execute inside user-controlled secure VMs with access to sensitive data and code.
- Global Slurm handles resource allocation and accounting via a service account
- Local Slurm runs per project inside secure VMs with access to sensitive data
- Secure VMs become nodes integrated into the local Slurm cluster
- GPU partitions and job arrays for AI training and large parameter sweeps
- Scheduling and execution are separated so the global instance never sees user data
Coming from a shared computing cluster? Your Slurm concepts map directly onto tiCrypt, and your job scripts come with you. See the concept mapping
Who Uses tiCrypt
Built for the Most Demanding Research Environments
From computational research groups and AI labs to defense contractors and national labs, tiCrypt runs the workloads institutions cannot afford to expose.
Complex HPC Workflows. Fully Isolated.
Run multi-node Slurm jobs inside encrypted enclaves. Standard sbatch and srun commands, encrypted scratch storage, and ephemeral worker VMs destroyed after each job. Hardware-accelerated encryption adds single-digit percentage overhead on I/O.
- Native Slurm: sbatch, srun, squeue, sacct with encrypted execution
- Multi-node MPI jobs across an isolated Layer 2 network
- Ephemeral worker VMs with LUKS-encrypted drives
- Job arrays and GPU scheduling for large parameter sweeps
Train Models on Data You Could Not Use Before.
Regulated datasets are often the most valuable training data a research institution has, and the hardest to use. tiCrypt lets you train and fine-tune on CUI, ePHI, and genomic data in place, with weights and code never leaving the enclave or touching a third-party API.
- Fine-tune and serve self-hosted models with no external API calls
- Train on ePHI, CUI, and controlled-access genomic datasets
- Model weights and training code invisible to infrastructure operators
- GPU partitions and distributed training scheduled through Slurm
CMMC-Ready CUI Environment.
Satisfies data handling requirements for DoD (DFARS 252.204-7012), NSF, NIH, and DHS without additional infrastructure. Maps to NIST SP 800-171 controls.
- DoD-funded research (DFARS / CUI)
- NIH and NSF sensitive data compliance
- Multi-PI collaboration with data isolation
- NIST SP 800-171 control mapping
ITAR-Compatible. Audit-Ready.
All actions are logged to tiAudit, a separate system with independent authentication. Audit records are immutable from installation date onward. Project-level isolation enforces ITAR/EAR access boundaries.
- Immutable audit trail for contract reporting
- Every action is audited, no exceptions
- Per-project access control and data isolation
- Separate audit system with independent login
Why tiCrypt
Purpose-Built Secure HPC vs. Managed Cloud
Cloud batch services make you rewrite your workflows and trust someone else with your most sensitive research data. tiCrypt runs the Slurm commands you already know, on your infrastructure, without compromise.
What You Get Instead
The same four areas an assessor and a research computing team both care about, and what changes when the enclave is yours.
HPC & Infrastructure
- Native dual-Slurm architecture, not a proprietary batch service
- Standard sbatch, srun, squeue and sacct with no script rewrites
- Model training on regulated data with no external inference APIs
- Data never leaves your own data center
- Runs on any x86 hardware you already own
- Windows and Linux VMs in one deployment
Security
- AES-256 end to end, encrypted even during compute
- Administrators never hold decryption keys
- Digital signatures, no passwords stored on the server
- A dedicated encrypted VM per session, no shared tenancy
Compliance
- 110/110 on a first-pass C3PAO assessment, with templated SSPs
- FIPS 140-3 validated modules, keys held by the user
- A separate tamper-evident audit system with its own login
- HIPAA, ITAR, FERPA, CUI and CMMC in one deployment
Operations
- One deployment license, unlimited seats
- You own and operate it, on your own upgrade schedule
- Standard encrypted formats, no egress fees
- Deployment help and SSP templates from research compliance engineers
110 Controls. 85 Met Together with tiCrypt.
Of the 110 NIST SP 800-171r2 practices required for CMMC Level 2, tiCrypt directly addresses 74 and jointly manages another 11 with your organization. The remaining 25 cover organizational policies, physical security, and personnel processes that need institution-specific implementation.
100 controls remain yours to implement and document
Providers carry the data center and hardware controls. Access control, auditing, identification, and system protection stay with you at the application layer.
25 controls remain yours to implement and document
74 controls met directly and 11 jointly, with templated SSP language for each. Physical protection stays with your institution because the hardware is yours.
Managed-cloud figures reflect a typical IaaS shared-responsibility model; exact inheritance varies by provider, service tier, and authorization boundary. Physical protection is the one domain a cloud provider covers and tiCrypt does not, because in a tiCrypt deployment the data center is your own.
tiCrypt deployments have been independently assessed by multiple accredited C3PAO organizations across 7+ NIST 800-171 evaluations, achieving a perfect 110/110 CMMC Level 2 score on the first pass: 85 controls from tiCrypt, the remaining 25 from your institution’s own policies using our templated SSPs. Assessment details and C3PAO references are available on request during evaluation.
View the full responsibility matrix ›
Research Funding
Unlock Restricted Research Funding
Many federal grants and contracts require a compliant enclave for handling controlled data. Without one, your institution cannot compete. tiCrypt provides the certified infrastructure researchers need to win and execute these awards.
DFARS 252.204-7012 & CMMC Level 2
- Army Research Laboratory (ARL) cooperative agreements
- Office of Naval Research (ONR) grants
- DARPA-funded research programs
- Air Force Research Laboratory (AFRL) contracts
ITAR & EAR Compliance
- Defense industry subcontracts with ITAR data
- Satellite and aerospace research programs
- Controlled technology development partnerships
- International Traffic in Arms Regulations (ITAR) projects
Controlled-Access & Genomic Data
- dbGaP controlled-access genomic datasets
- All of Us Research Program controlled tier
- NCATS Clinical and Translational Science Awards
- NCI Cancer Moonshot data-intensive grants
NIST 800-171 for Federal Awards
- NSF Secure and Trustworthy Cyberspace (SaTC)
- DHS Critical Infrastructure research programs
- DOE National Nuclear Security Administration (NNSA)
- Federal grants requiring FISMA Moderate controls
Researchers at tiCrypt institutions have secured over $312M in grant funding requiring controlled data environments.
Our Origin
Developed for Researchers, by Researchers
Tera Insights was founded in 2012 by Dr. Alin Dobra, an Associate Professor in the CISE department at the University of Florida. In 2014, Tera Insights partnered with UF Research Computing to replace the university's existing system for handling sensitive data, which had limited user capacity, no proper auditing, and relied on users to self-enforce security policies.
UF needed a single platform to house all types of restricted research, including ePHI, ITAR, FERPA, CUI, and intellectual property, supporting both Windows and Linux workflows across campus. tiCrypt was jointly developed under a collaboration agreement between Tera Insights and the University of Florida, with thousands of hours of feedback from faculty, principal investigators, research computing staff, and compliance officers shaping the platform into what it is today.
What began as a replacement for one university's sensitive data system has scaled into production infrastructure for 1,300+ researchers working across 400+ unique research projects, securing more than $312M in grant funding that requires a controlled data environment. The complex workflows those projects demand, from multi-node Slurm jobs to GPU-backed model training, are what the platform has been hardened against year after year.
What Experts Are Saying
Independently Validated Security
"We have been working with Tera Insights for about a decade on building a computing environment for working with restricted data that is flexible, highly secure, and straightforward to manage. With constant feedback from researchers, the environment has matured to meet the demands of very complex workflows.
"Our independent security review and penetration test of tiCrypt revealed an exceptionally strong, defense-in-depth architecture aligned with NIST SP 800-171. The platform incorporates non-default security design choices not commonly encountered in comparable systems. We were particularly impressed by the overall security architecture and the team's responsiveness.
"After completing our penetration test of the tiCrypt LASER environment, we came away genuinely impressed. The platform reflects a layered, thoughtful security architecture built with compliance and protection at its core. For organizations working with sensitive data, tiCrypt is an exemplary model.
"Our tiCrypt environment has significantly improved collaboration between the college and hospital by providing researchers from both organizations a shared space to work with highly sensitive data. We have enjoyed watching the platform mature and continually improve. As we find new use cases, Tera Insights has been great to help us find solutions.
Ready to Secure Your HPC Workloads?
Join the growing community of R1 universities, national labs, and defense research centers running Slurm workloads inside tiCrypt's certified secure enclave, without rewriting a single job script.