For neoclouds and GPU cloud users

Securely
Run AI on Neoclouds

Lava verifies the isolation, exposure, and security of the infrastructure you rent, so you can trust your neocloud provider and secure the parts of the environment you control.

THE PROBLEM

Your Provider’s Risk Becomes Your Risk

Your models and data run on infrastructure you don’t control, but their security is still your concern. Other tenants, weak isolation, and gaps in your provider’s security can put you at risk. Because neoclouds are so new, it’s often unclear what security standards to demand from your provider and what you should be covering.

WHAT LAVA DOES

Lava protects your workloads on rented infrastructure

Lava secures your rented capacity and provides guided action items to actively reduce risk.

Provider reportEvidence your provider can act on, ready to sendPDF · 6 findingsIsolation and exposure reviewgpu-pool-b · 8 nodes · evidence attachedReady to sendCross-partition traffic not blocked at the switchCriticalTenant can read other servers’ P_KeysCriticalBMC reachable from the tenant VLANHighLocal scratch RAID not sanitized on handbackHighShare with provider

Verify isolation and provider-side risks

Verify your environment is isolated from other tenants and uncover exposure, shared resources, and infrastructure risks. Get a ready-to-share report that shows your provider exactly what, and how, to fix.

Your side of the boundaryHardening on the nodes you rent, re-checked every 4 hours8 nodes · checked 20m agoRestrict outbound egress to known endpoints5 of 8 nodes can still reach any destination on the internet5 nodesDrop privileged mode on the container runtime2 nodes hand CAP_SYS_ADMIN to the workloads they run2 nodesSecure Boot enforced on every nodeThe boot chain is verified before the OS loadsFixedRoot login over SSH disabledNo direct root session on any rented nodeFixedDisk encryption keys held by you, not the providerThe provider cannot read the volumes it hosts for youFixed

Secure what you control

Continuously check your configurations against hardening best practices, find and fix security gaps before they become a risk.

Credential guessing across the management networkOne source against five assets in three hoursHighINC-204460m agoMediumAuthentication failures recorded on this device90m agoHighAuthentication failures recorded on this device120m agoMediumRepeated failed SSH password attempts from one source150m agoHighActive SSH brute-force against this host180m agoHighActive SSH brute-force against this host

Detect threats in real time

Identify attacks and tampering the moment they happen.

Firmware versionsHow each model’s fleet splits across versions · × devices on eachLast scan · 12m agoDell iDRAC 9412 devicesDell R760xa BIOS412 devicesNVIDIA BlueField-3256 devicesNVIDIA SN560096 devicesWEKA cluster18 devicescurrent releasebehind the current releasecarries a known CVE

Know the firmware you run on

See what firmware is running across the nodes and appliances you rent, and understand which versions and CVEs introduce active risks.

Assess your neocloud in 2 minutes