OC3 registrations are now open! Join the premier event for confidential computing online or in Berlin on March 27.

Press Release

Launch of Privatemode AI

Launch of “Privatemode AI”: First AI chat app & API with end-to-end encryption


  • With Privatemode AI, companies can finally process sensitive data using generative AI.
  • Easy deployment: Privatemode AI offers an intuitive chat interface and an API that is compatible with the OpenAI syntax.


Bochum, February 19, 2025 - Edgeless Systems, specialist for highly secure confidential computing, releases Privatemode AI (www.privatemode.ai), a solution for organizations that want to use generative AI without taking data protection risks.


Privatemode AI offers both an AI chat app and an AI API that work with end-to-end encryption. This means that all data - from input to processing to output - remains fully protected. Companies can thus use generative AI models without incurring security or compliance risks.

Challenge: AI use and data protection

The processing of sensitive data by generative AI services presents companies with a challenge: on the one hand, AI offers efficiency benefits, but on the other, there are risks in terms of data protection and data security.

Existing solutions offer two inadequate alternatives:

  • Use cloud-based AI services and relinquish control over data
  • Operating your own AI infrastructure, which is associated with high costs and considerable administrative effort


Privatemode AI offers an alternative that combines the advantages of the cloud with end-to-end technical security.


“Previous AI services relied on contractual regulations and security best practices to ensure data protection. As a counter-design to this, Privatemode AI is the first AI service based on the protection mechanisms of confidential computing technology. We are particularly proud to have achieved this as a European company,” comments Dr. Felix Schuster, CEO and co-founder of Edgeless Systems.


Technical implementation

Confidential computing is a hardware-based security technology that enables sensitive data to be processed securely. Privatemode AI uses AMD EPYC CPUs and Nvidia H100 GPUs that support this technology. In combination with a specially developed software architecture, Privatemode AI offers the following security features.

  • End-to-end encryption: Data is encrypted on the users device and is never accessible in plain text.
  • Confidential processing: During processing in the cloud, the data also remains encrypted throughout in the working memory and is therefore protected from external access.
  • End-to-end verifiability: Cryptographic certificates confirm the integrity of the secure processing environment. The certificates are automatically checked using remote attestation on the end devices.


To put it simply: Privatemode AI processes the data in a “black box architecture”. The data is never available in plain text and cannot be viewed by Edgeless Systems, the cloud operator or system administrators. Even if hackers were to gain access to the cloud infrastructure, they would not have access to the data due to technical reasons.

The AI model itself cannot disclose any data, use it for training or “remember” it.

Use and model selection

Privatemode AI supports various open source AI models. Meta Llama 3.3 is available at launch. DeepSeek R1 will follow shortly. This will make it possible to use the much-discussed Chinese model in a secure manner.

The relevant program code behind Privatemode AI will soon be published on the GitHub platform (“Source available”) to ensure the traceability and transparency of the security mechanisms.


Use as an app or API

Privatemode AI is available as a chat application and API:

  • App: user interface for direct use
  • API: interface compatible with OpenAI for integration into existing systems

The service is immediately ready for use after registration with an email address.


Prices & availability

Privatemode AI is now available for use:

  • App: 14-day trial period, then €20/month per user (Download)
  • API: 14-day test phase with 1 million tokens, then €5/1 million tokens (Sign-up)


About Edgeless Systems

Edgeless Systems was founded in Bochum in 2020 and develops open source cybersecurity solutions with confidential computing. The company offers security solutions for cloud and AI applications and works with customers such as Schwarz Gruppe (Stackit), IT.NRW and Uniklinik Freiburg. Edgeless Systems' technology is also used in the ePatient Record (ePA).

Edgeless Systems is a member of the Confidential Computing Consortium and organizes the Open Confidential Computing Conference (OC3) with the participation of companies such as Nvidia, Google, Microsoft, Intel and AMD.