Skip to main content
Native SLURM IntegrationSecure VM Clusters

High-Performance Computing. Fully Secured.

NIST 800-171 Assessed·CMMC 2.0 Level 2 Assessed

Run Slurm batch jobs and GPU-accelerated AI training on your own infrastructure, with end-to-end encryption and zero admin access to your data. Scale across nodes, fine-tune models on regulated datasets, and keep your code, weights, and results inside a secure enclave assessed at CMMC Level 2.

[researcher@vm-secure ~]$ sbatch analysis.sh
Submitted batch job 48217
[researcher@vm-secure ~]$ squeue --me
             JOBID PARTITION     NAME     USER ST       TIME  NODES NODELIST(REASON)
             48217    secure analysis research  R       0:42      4 node-[01-04]
             48218       gpu train_mo research PD       0:00      8 (Resources)
[researcher@vm-secure ~]$ sacct -j 48215
JobID             State    Elapsed
------------ ---------- ----------
48215         COMPLETED   01:23:07
[researcher@vm-secure ~]$ 

How It Works

From sbatch to Results, Fully Encrypted

Same Slurm commands. Same workflow. Zero exposure to administrators. Batch jobs, MPI, and GPU training runs all follow the same path.

01

Submit

$ sbatch job.sh

Submit jobs with the standard Slurm commands you already use. No proprietary APIs, no rewritten job scripts.

02

Schedule

queued -> partition: secure

Global Slurm allocates resources across the cluster. It sees CPU, memory, and GPU requests, never your code or data.

03

Execute

RUNNING on node-01..04

Encrypted worker VMs spin up as Slurm nodes, CPU or GPU. Your job, model weights, and data stay inside LUKS-encrypted storage on an isolated network.

04

Results

COMPLETED exit:0

Output is written to encrypted project storage. Worker VMs are destroyed and their keys discarded.

Researchers use the same sbatch, srun, squeue, and sacct commands they already know. The security happens below the application layer. See how the split-instance architecture works.

The tiCrypt Platform

Your Data Is Restricted. Your Research Shouldn't Be.

Slurm-managed HPC clusters, GPU-backed AI workloads, encrypted virtual machines, and full CMMC/NIST compliance in a single platform.

Run Complex Workflows on Encrypted Clusters

tiCrypt separates scheduling from execution using multiple Slurm instances. A global instance handles resource allocation and accounting, while per-project local instances execute inside user-controlled secure VMs with access to sensitive data and code.

  • Global Slurm handles resource allocation and accounting via a service account
  • Local Slurm runs per project inside secure VMs with access to sensitive data
  • Secure VMs become nodes integrated into the local Slurm cluster
  • GPU partitions and job arrays for AI training and large parameter sweeps
  • Scheduling and execution are separated so the global instance never sees user data
How split-instance Slurm works

Coming from a shared computing cluster? Your Slurm concepts map directly onto tiCrypt, and your job scripts come with you. See the concept mapping

Explore the Docs

Who Uses tiCrypt

Built for the Most Demanding Research Environments

From computational research groups and AI labs to defense contractors and national labs, tiCrypt runs the workloads institutions cannot afford to expose.

HPC & Computational Research

Complex HPC Workflows. Fully Isolated.

Run multi-node Slurm jobs inside encrypted enclaves. Standard sbatch and srun commands, encrypted scratch storage, and ephemeral worker VMs destroyed after each job. Hardware-accelerated encryption adds single-digit percentage overhead on I/O.

  • Native Slurm: sbatch, srun, squeue, sacct with encrypted execution
  • Multi-node MPI jobs across an isolated Layer 2 network
  • Ephemeral worker VMs with LUKS-encrypted drives
  • Job arrays and GPU scheduling for large parameter sweeps
AI & Machine Learning

Train Models on Data You Could Not Use Before.

Regulated datasets are often the most valuable training data a research institution has, and the hardest to use. tiCrypt lets you train and fine-tune on CUI, ePHI, and genomic data in place, with weights and code never leaving the enclave or touching a third-party API.

  • Fine-tune and serve self-hosted models with no external API calls
  • Train on ePHI, CUI, and controlled-access genomic datasets
  • Model weights and training code invisible to infrastructure operators
  • GPU partitions and distributed training scheduled through Slurm
Research Universities

CMMC-Ready CUI Environment.

Satisfies data handling requirements for DoD (DFARS 252.204-7012), NSF, NIH, and DHS without additional infrastructure. Maps to NIST SP 800-171 controls.

  • DoD-funded research (DFARS / CUI)
  • NIH and NSF sensitive data compliance
  • Multi-PI collaboration with data isolation
  • NIST SP 800-171 control mapping
Defense Contractors & FFRDCs

ITAR-Compatible. Audit-Ready.

All actions are logged to tiAudit, a separate system with independent authentication. Audit records are immutable from installation date onward. Project-level isolation enforces ITAR/EAR access boundaries.

  • Immutable audit trail for contract reporting
  • Every action is audited, no exceptions
  • Per-project access control and data isolation
  • Separate audit system with independent login

Why tiCrypt

Purpose-Built Secure HPC vs. Managed Cloud

Cloud batch services make you rewrite your workflows and trust someone else with your most sensitive research data. tiCrypt runs the Slurm commands you already know, on your infrastructure, without compromise.

What You Get Instead

The same four areas an assessor and a research computing team both care about, and what changes when the enclave is yours.

HPC & Infrastructure

  • Native dual-Slurm architecture, not a proprietary batch service
  • Standard sbatch, srun, squeue and sacct with no script rewrites
  • Model training on regulated data with no external inference APIs
  • Data never leaves your own data center
  • Runs on any x86 hardware you already own
  • Windows and Linux VMs in one deployment

Security

  • AES-256 end to end, encrypted even during compute
  • Administrators never hold decryption keys
  • Digital signatures, no passwords stored on the server
  • A dedicated encrypted VM per session, no shared tenancy

Compliance

  • 110/110 on a first-pass C3PAO assessment, with templated SSPs
  • FIPS 140-3 validated modules, keys held by the user
  • A separate tamper-evident audit system with its own login
  • HIPAA, ITAR, FERPA, CUI and CMMC in one deployment

Operations

  • One deployment license, unlimited seats
  • You own and operate it, on your own upgrade schedule
  • Standard encrypted formats, no egress fees
  • Deployment help and SSP templates from research compliance engineers

Read the full comparison against managed cloud enclaves

110 Controls. 85 Met Together with tiCrypt.

Of the 110 NIST SP 800-171r2 practices required for CMMC Level 2, tiCrypt directly addresses 74 and jointly manages another 11 with your organization. The remaining 25 cover organizational policies, physical security, and personnel processes that need institution-specific implementation.

Managed Cloud
10/ 110
controls covered for you

100 controls remain yours to implement and document

Providers carry the data center and hardware controls. Access control, auditing, identification, and system protection stay with you at the application layer.

tiCrypt
85/ 110
controls covered for you

25 controls remain yours to implement and document

74 controls met directly and 11 jointly, with templated SSP language for each. Physical protection stays with your institution because the hardware is yours.

Managed-cloud figures reflect a typical IaaS shared-responsibility model; exact inheritance varies by provider, service tier, and authorization boundary. Physical protection is the one domain a cloud provider covers and tiCrypt does not, because in a tiCrypt deployment the data center is your own.

tiCrypt deployments have been independently assessed by multiple accredited C3PAO organizations across 7+ NIST 800-171 evaluations, achieving a perfect 110/110 CMMC Level 2 score on the first pass: 85 controls from tiCrypt, the remaining 25 from your institution’s own policies using our templated SSPs. Assessment details and C3PAO references are available on request during evaluation.

View the full responsibility matrix ›

74DirectlyAddressed

Research Funding

Unlock Restricted Research Funding

Many federal grants and contracts require a compliant enclave for handling controlled data. Without one, your institution cannot compete. tiCrypt provides the certified infrastructure researchers need to win and execute these awards.

Department of Defense

DFARS 252.204-7012 & CMMC Level 2

  • Army Research Laboratory (ARL) cooperative agreements
  • Office of Naval Research (ONR) grants
  • DARPA-funded research programs
  • Air Force Research Laboratory (AFRL) contracts
Export-Controlled Research

ITAR & EAR Compliance

  • Defense industry subcontracts with ITAR data
  • Satellite and aerospace research programs
  • Controlled technology development partnerships
  • International Traffic in Arms Regulations (ITAR) projects
NIH & Biomedical

Controlled-Access & Genomic Data

  • dbGaP controlled-access genomic datasets
  • All of Us Research Program controlled tier
  • NCATS Clinical and Translational Science Awards
  • NCI Cancer Moonshot data-intensive grants
NSF & Federal Agencies

NIST 800-171 for Federal Awards

  • NSF Secure and Trustworthy Cyberspace (SaTC)
  • DHS Critical Infrastructure research programs
  • DOE National Nuclear Security Administration (NNSA)
  • Federal grants requiring FISMA Moderate controls

Researchers at tiCrypt institutions have secured over $312M in grant funding requiring controlled data environments.

Our Origin

Developed for Researchers, by Researchers

Tera Insights was founded in 2012 by Dr. Alin Dobra, an Associate Professor in the CISE department at the University of Florida. In 2014, Tera Insights partnered with UF Research Computing to replace the university's existing system for handling sensitive data, which had limited user capacity, no proper auditing, and relied on users to self-enforce security policies.

UF needed a single platform to house all types of restricted research, including ePHI, ITAR, FERPA, CUI, and intellectual property, supporting both Windows and Linux workflows across campus. tiCrypt was jointly developed under a collaboration agreement between Tera Insights and the University of Florida, with thousands of hours of feedback from faculty, principal investigators, research computing staff, and compliance officers shaping the platform into what it is today.

What began as a replacement for one university's sensitive data system has scaled into production infrastructure for 1,300+ researchers working across 400+ unique research projects, securing more than $312M in grant funding that requires a controlled data environment. The complex workflows those projects demand, from multi-node Slurm jobs to GPU-backed model training, are what the platform has been hardened against year after year.

What Experts Are Saying

Independently Validated Security

"

We have been working with Tera Insights for about a decade on building a computing environment for working with restricted data that is flexible, highly secure, and straightforward to manage. With constant feedback from researchers, the environment has matured to meet the demands of very complex workflows.

Dr. Erik Deumens, PhDSenior Director, UFIT Research ComputingUniversity of Florida
"

Our independent security review and penetration test of tiCrypt revealed an exceptionally strong, defense-in-depth architecture aligned with NIST SP 800-171. The platform incorporates non-default security design choices not commonly encountered in comparable systems. We were particularly impressed by the overall security architecture and the team's responsiveness.

Guillermo Munoz, M.A., CISSP, CEHSenior Information Security ArchitectHarvard Medical School
"

After completing our penetration test of the tiCrypt LASER environment, we came away genuinely impressed. The platform reflects a layered, thoughtful security architecture built with compliance and protection at its core. For organizations working with sensitive data, tiCrypt is an exemplary model.

Amanpreet Parmar, CASP+Senior Security EngineerHarvard Medical School
"

Our tiCrypt environment has significantly improved collaboration between the college and hospital by providing researchers from both organizations a shared space to work with highly sensitive data. We have enjoyed watching the platform mature and continually improve. As we find new use cases, Tera Insights has been great to help us find solutions.

Elijah Gagne, M.S.Director Research CyberinfrastructureDartmouth

Ready to Secure Your HPC Workloads?

Join the growing community of R1 universities, national labs, and defense research centers running Slurm workloads inside tiCrypt's certified secure enclave, without rewriting a single job script.