Secure Research Computing

Secure HPC for CUI, ITAR, and Defense Research

Run sensitive research workloads on shared HPC infrastructure while keeping every project cryptographically isolated.

Hundreds of isolated project environments, each with its own compute, storage, and applications, connect into one shared HPC and SLURM cluster for maximum utilization.

The Tradeoff

Traditional Secure HPC Forces a Tradeoff

Organizations must choose between convenience or isolation.

Share Infrastructure

Trust administrators and shared systems.

Six researchers connect into a shared HPC cluster of compute nodes and storage.

Limited isolation

Risk of data exposure and lateral access.

Tradeoff

Choose between convenience or isolation.

Isolate Projects

Duplicate clusters, storage, and administration.

Three separately colored projects, each with its own researcher, compute nodes, and storage.

High cost and complexity

Resource duplication and operational overhead.

tiCrypt Removes the Tradeoff

One shared HPC infrastructure. Cryptographic isolation for every project.

Project A, B, and C are each isolated by their own keys, while sharing a single HPC cluster for compute, storage, and network.

One Cluster

Maximize utilization and reduce cost.

Strong Isolation

Cryptographic boundaries protect every project.

Simplified Operations

Centralized infrastructure without sharing trust.

Trust Model

tiCrypt Replaces Trust With Cryptography

Cryptographic isolation replaces operational trust.

Traditional HPC

Trust People + Infrastructure

  • Administrators
  • Compute nodes
  • Shared storage
  • Project separation
  • Network isolation

tiCrypt

Trust Cryptography

  • Researchers control encryption keys
  • Data never leaves the secure enclave
  • Administrators cannot access research data
  • Every project is cryptographically isolated
  • Centralized, immutable auditing across all projects

How It Works

From Researcher to Secure Enclave

Researchers securely access HPC, storage, and applications without exposing research data to administrators.

Researchers connect through an encrypted session into the on-prem tiCrypt Enclave, which provides HPC compute via SLURM, data and storage, and apps and tools. No admin access to data, data never leaves the enclave, and every action is logged with a full audit trail.

Native SLURM • Shared CPU/GPU

High Performance Computing with SLURM

Secure Shared HPC

Give isolated research environments access to shared CPU/GPU resources (GPU - Q4 2026).

Data Stays Protected

Run jobs without moving sensitive data outside the secure environment.

Native SLURM Integration

Use familiar SLURM scheduling and HPC workflows.

Scale Across Programs

Share compute across secure projects.

SLURM workload manager

Maximize Mission Impact

Deliver secure, on-demand HPC performance at enterprise scale, without exposing research data.

Architecture

One HPC Cluster. Hundreds of Isolated Research Programs.

Every project gets its own

Encryption keysVirtual infrastructureAccess controlsCompute environment

While sharing

SLURM schedulerCompute hardwareStorage infrastructureNetworking

Projects share compute - not trust.

Compromise or misconfiguration in one project cannot expose another.

Security

Security by Architecture

Scheduler Cannot See Research Data

SLURM handles scheduling - not decryption.

Administrators Cannot Decrypt Files

Researchers retain control of encryption keys.

Endpoints Stay Plaintext-Free

Devices connect without receiving unencrypted research data.

Cryptographic Project Isolation

Each project is isolated by keys, not just policy.

Immutable Audit Trail

Access is logged in tamper-resistant records.

Customer-Controlled Encryption Keys

Your organization controls the keys; tiCrypt cannot access your data.

Compliance

Built Around NIST SP 800-171

84 of 110 controls implemented and managed by tiCrypt.

76%24%NIST SP 800-171110 Controls

tiCrypt Controls Covered

84/110

Implemented and managed by tiCrypt.

Organizational Controls

26/110

Owned by customer policy, not tiCrypt.

The remaining 26 organizational controls are implemented through customer policies and procedures.

See the full SSP Blueprint for more information on how compliance is simplified with tiCrypt.

Compatibility

Built for Real HPC Workloads

Fully compatible with existing HPC workflows. Researchers, not administrators, control access to research data.

Scheduling

Native SLURM

Compute

CPU workloadsGPU workloads (Q4 2026)Machine learningSimulation

Research Environments

MPI applicationsHigh-throughput computing

Secure Your Existing HPC Infrastructure

See how tiCrypt can isolate CUI and ITAR research workloads without replacing your cluster.