OPAQUE develops Confidential AI infrastructure designed to let enterprises use sensitive data in AI workloads while enforcing policies during execution and producing verifiable evidence of what occurred. Pulse 2.0 interviewed OPAQUE CEO Aaron Fulkerson to learn more.
Aaron Fulkerson’s Background

When asked about his background and the experiences that ultimately led him to OPAQUE, Fulkerson shared:
I grew up on a little farm south of San Jose, dialing into bulletin board systems on a 2400-baud modem. I was building MUDs and teaching myself to code before I understood what a career in technology even meant. That early experience, connecting to strangers through primitive networks and watching something collaborative emerge, stuck with me.
I started in distributed systems research at Microsoft, then founded MindTouch, where we built an enterprise knowledge platform that still powers over a billion page views a month. After that, I went to ServiceNow and created what became one of their fastest-growing products. We reduced an insurance demand letter process from eight days to four seconds using AI.
Across every chapter, one pattern kept repeating: the technology was never the bottleneck. Trust was.
The internet didn’t scale until HTTPS. Cloud didn’t go mainstream until compliance frameworks gave CISOs something to point at. AI is at that same inflection point.
The models are extraordinary, but enterprises still hesitate to use their most sensitive data because they can’t verify what happens during processing. That’s what pulled me to OPAQUE.
Scaling Confidential AI
When asked how his previous experience shaped his approach to scaling Confidential AI infrastructure at OPAQUE, Fulkerson explained:
At ServiceNow, I saw what happens when teams try to bolt governance onto a product after it ships. Adoption slows, legal pushes back, and internal resistance builds. The teams that embedded security and compliance into the architecture from Day 1 actually moved faster.
The same dynamic is playing out in AI. The bottleneck isn’t model quality. It’s verification. Security teams can’t confirm what happens to sensitive data during execution, so the most valuable use cases stay stuck in pilot.
We built OPAQUE to make trust part of the runtime itself. Instead of relying on reviews or assumptions, the system produces verifiable evidence of what happened during execution.
That shifts the conversation from speculation to proof, and that’s what unlocks deployment.
Founding OPAQUE
When asked what problem in AI security and data privacy the founding team identified and how that insight led to OPAQUE, Fulkerson described:
The founding team, Ion Stoica, Raluca Ada Popa, and Rishabh Poddar, saw a gap that the industry had accepted as a trade-off: encryption protects data at rest and in transit, but once systems start actively processing that data, those protections fall away.
In practice, that means the moment value is being created, during computation, is also the moment data is most exposed.
As AI systems become more autonomous, chaining actions across tools and environments, that gap becomes harder to reason about and control.
OPAQUE was built to close that gap by enforcing policies during execution and producing verifiable evidence of what actually happened. Instead of relying on what should have occurred, enterprises can prove what did.
Customer Validation
When asked which technical or customer-driven milestone has felt most validating, Fulkerson recalled:
The moment that stands out most was seeing a customer take a dataset they had kept completely offline, too sensitive for any AI workflow, and run it through a production system for the first time.
They had wanted to do it for over a year, but security wouldn’t allow it. Once they saw evidence that the data remained protected during processing, the conversation immediately shifted from “we can’t” to “what else can we do?”
That’s the pattern we see repeatedly. Enterprises aren’t short on ideas and AI ambition. They’re short on verification. When that barrier drops, adoption accelerates quickly.
Our Series B round validated the category as well. NVIDIA, AMD, Intel, Anthropic, and several major hyperscalers have endorsed or adopted confidential AI in under a year.
Jensen Huang put confidential computing at the center of NVIDIA’s entire product catalog at GTC this week. As he said in one of his roundtable sessions, to use AI safely, you’ve got to be using confidential computing with verifiable policies.
That’s not a niche security vendor saying it. That’s the most influential compute platform on the planet.
But the customer moments are what I carry. When someone unlocks a use case they’d written off as impossible, that’s when you know the architecture is right.
How Confidential AI Works
When asked how OPAQUE’s Confidential AI platform works in practice and which industries are seeing the most immediate need, Fulkerson detailed:
If you’re an AI builder, the goal is simple: move fast, connect to real data, and get into production. OPAQUE makes that possible without long security delays.
We operate across three phases.
Before runtime, we attest. Hardware-backed remote attestation verifies that the environment is genuine and the code is approved before any sensitive data enters.
During execution, we enforce that data stays encrypted within Trusted Execution Environments, or TEEs, and cryptographic policy ensures agents can access only what they’re authorized to access. If a measurement fails, the workload gets blocked.
After execution, we audit. Tamper-proof, hardware-signed logs prove which code ran, which data was touched, and which policies governed every step.
The hardware does the security review. Your team ships.
We see the strongest demand in industries with the highest data sensitivity, including financial services, insurance, healthcare, and enterprise software.
For example, a bank running AI agents across bond trading data or risk models needs cryptographic proof that data never left a specific jurisdiction during processing.
Insurance is right behind, including claims automation, underwriting models, and actuarial data. It’s regulated and often stuck in pilot because legal can’t sign off.
Enterprise ISVs building AI into their platforms are hitting the same wall. Their customers demand verifiable guarantees before they’ll connect sensitive data.
And, of course, healthcare, including clinical workloads, patient records, and cross-institutional research.
In each case, the challenge isn’t a lack of use cases. It’s the inability to move forward without stronger guarantees.
AI Security Challenges
When asked about challenges facing the Confidential AI sector and how OPAQUE is addressing them, Fulkerson noted:
Thankfully, market awareness is moving fast. Jensen Huang put confidential computing at the center of GTC, not a side session, not a security track, but central to the entire event.
When NVIDIA builds its roadmap around verifiable AI workloads, the market listens. A year ago, I was explaining what confidential AI even meant. Now CISOs and CIOs are coming to us asking how to deploy it. That acceleration is real.
One main challenge is that different AI risks often get grouped together, including hallucination, prompt injection, and data exposure, when they’re fundamentally different problems.
Hallucination is a model reasoning problem. Data leakage is an architecture problem.
When teams conflate the two, they deploy guardrails that address behavior but ignore boundaries. They’re essentially processing sensitive intellectual property on hope.
As AI agents gain autonomy, the question that matters shifts. Instead of asking, “Did the model respond correctly?” the right question is, “What could the system technically access?”
A well-behaved agent with unrestricted access to sensitive data still poses a structural risk. Behavior can be tuned. Access must be enforced.
We’ve been working to address and reframe that challenge. Enterprises need to focus on containment, not correction.
When something fails at scale, and at scale, something will, they need cryptographic proof of what the system did and did not access.
Hard runtime boundaries and verifiable evidence move the risk conversation from speculation to architecture. When those boundaries are enforced, the risk becomes much more manageable.
Technology Evolution
When asked how OPAQUE’s approach to Confidential AI has evolved as large language models and enterprise AI adoption have accelerated, Fulkerson explained:
Early on, confidential AI focused on relatively contained use cases, single models operating on defined datasets. As adoption has accelerated, that simplicity has disappeared.
Today, organizations are building multi-step workflows where agents interact across systems, APIs, and datasets. That expands both the opportunity and the risk surface.
That acceleration forced us to expand.
We’ve moved into confidential AI training, protecting the data that shapes the model, not just the data the model processes.
We’ve built sovereign cloud deployments for enterprises and governments that require verifiable jurisdictional control.
And we’re building post-quantum security into the stack now because the cryptographic guarantees you deploy today need to withstand the threats of the next decade.
$24 Million Series B
When asked what OPAQUE’s Series B funding enables the company to do next, Fulkerson said:
Our $24 million Series B brings total funding to $55.5 million and accelerates three areas we were already focused on.
First, extending cryptographic guarantees across both training and inference. Most of the industry is focused on inference security. Training is where the model learns your proprietary data. That’s equally critical to protect.
Second, post-quantum security. The encryption standards that protect AI workloads today won’t hold forever. We’re building for what comes next.
Third, sovereign cloud deployments. Enterprises and governments increasingly need verifiable proof that AI workloads run inside a specific jurisdiction, on approved hardware, under approved policies.
That’s becoming a regulatory requirement in multiple markets, and OPAQUE Studio, our development environment for building AI agents with runtime-verifiable privacy, is how we deliver it.
Competitive Differentiation
When asked what differentiates OPAQUE from its competition, Fulkerson emphasized:
Most approaches to AI security depend on trust at some point in the stack. Configuration trust, monitoring trust, and contractual trust. Somebody has to believe that the system did what it was supposed to do.
We don’t ask anyone to trust. We prove.
Our platform combines hardware-backed confidential computing, runtime policy enforcement, remote attestation, and tamper-proof audit logs.
When an enterprise runs a workload through OPAQUE, they get cryptographic evidence of exactly what happened: what code ran, what data was accessed, and what policies governed execution.
That evidence is hardware-signed and tamper-proof.
Think about it from the buyer’s side. A CISO evaluating two AI platforms asks the same question: “How do I know my data is safe?”
One vendor says, “We have strong access controls and monitoring.” The other hands over a hardware-attested audit log.
That’s the difference between monitoring AI and governing it.
As systems become more autonomous, that distinction matters more. Oversight alone doesn’t scale. Verification does.
What Comes Next
When asked what to expect next from OPAQUE, Fulkerson concluded:
Confidential computing will follow a similar path to HTTPS. It’ll become invisible and mandatory.
Every serious AI deployment will require runtime verification, just as every serious website requires encrypted connections. Nobody debates HTTPS anymore. It’s just infrastructure.
As that happens, the conversation will shift from whether AI can be deployed safely to how quickly it can be deployed at scale.
You’ll see OPAQUE push deeper into sovereign AI deployments, strengthen ecosystem integrations with major cloud and AI platforms, and expand broader post-quantum readiness.
The agentic web is being built right now, autonomous systems operating at machine speed across organizational boundaries.
That web needs a trust layer. Vint Cerf said for 30 years that the Internet needed one. We’re not going to make the same mistake twice.
Enterprises won’t debate whether to deploy AI at scale. They’ll demand proof that it operates safely.
We intend to make that proof automatic.

