AI Potluck
Back to Gap Map Product / UX / Assurance & compliance evidence

NVIDIA Attestation SDK (nvTrust)

NVIDIA
open source / Overall score: 3.4

NVIDIA's attestation tooling for confidential computing on its GPUs and NVSwitches. It collects hardware evidence from a GPU running in confidential-computing mode and verifies it, locally or through NVIDIA's remote attestation service, so a relying party can confirm what hardware and firmware ran a workload. The C++ SDK and nvattest CLI (NVAT) succeed the Python guest tools of the original nvTrust repository.

Scored as both repositories: NVAT is the maintained successor, and the nvTrust Python SDK reached end of support on 2026-09-15, so its PyPI package is not declared. Tagged independently verifiable: the evidence is signed by the GPU and checked against NVIDIA's certificate chain, not the operator's word.

Openness

5 medium confidence
5.0
license
Apache-2.0(OSI
source
public(C++ SDK, CLI, Rust bindings and the legacy Python guest tools)
core features withheld
no

Both repositories are published under Apache-2.0 and hold the whole toolset: the C++ SDK, the CLI, the Rust bindings and the older Python guest tools. The remote attestation service is an NVIDIA-run verifier offered beside the SDK, which also verifies locally.

Adoption

1 low confidence
1.0

GitHub stars across the two repositories are the only signal. The SDK ships as native packages from NVIDIA's download page, which publishes no count, and the retired Python package no longer measures current use. A star is not a use.

Capability

5 high confidence
5.0

A relying party checks evidence the GPU itself signs, against NVIDIA's certificate chain, so the claim about what ran does not depend on trusting the operator. That is the strongest check in this category, shared only with the zero-knowledge provers, and the trust it asks for moves to the hardware vendor.

Verified 2026-09-26