Below is our recent interview with Chris Hosking, GTM Advisor for Stealthium:

Q: Could you provide our readers with a brief introduction to your company?
A: Stealthium is an AI compute security company. We built the first security control plane for the GPU and accelerator layer, the part of modern AI infrastructure that traditional security tooling is failing.
Let’s start with AI momentum. Accelerators (think GPUs and TPUs) have gone from a specialist component to the backbone of computing in a matter of years. Bloomberg Intelligence puts the AI accelerator chip market at $116 billion in 2024, growing towards $604 billion by 2033, and Gartner expects data centre systems spending to grow more than 55% in 2026 alone on the back of AI infrastructure. New neo-clouds with billions of dollars in contracts are enabling access to this infrastructure. Put simply, the money, the models and the most sensitive data an organisation owns are all moving onto GPUs and custom silicon at once. The problem is that security has not moved with it…
Every EDR, cloud workload protection platform and runtime security product on the market stops at the CPU driver boundary. The moment a workload crosses into the GPU, it goes dark. That leaves the highest-value compute in the enterprise running with almost no runtime observability, no native detection and no policy enforcement, in exactly the environments where isolation and trust matter most: multi-tenant GPU clouds, AI labs, and the new wave of custom accelerator vendors shipping novel silicon without decades of hardened security tooling behind it.

Q: What makes you the best choice? How are you unique?
A: There are a few vendors who are doing interesting work in ensuring best architectural practices for these environments. However, in this space, runtime security for accelerator runtime rather than around it, we seem to be unique at this point. We surely won’t be shortly. Where some technologies seek to infer GPU activity from the host, Stealthium instruments the GPU, the driver and the workload directly.
This is a key difference to explore. In independent validation against a battery of GPU-native attack classes, conventional endpoint tooling generated no meaningful detections across nearly the entire set. Our platform caught them. We are not asking customers to rip anything out. We sit alongside existing controls and extend control where there is currently none.
We like to lead with evidence rather than fear. Every claim we make is tied to a documented finding or a reproducible detection, which is rarer in this market than it should be. In our engagements we can show our customers more detail and insight into their runtimes than they’ve ever had previously, unlocking a range of security outcomes beyond stopping attacks!
Q: Who is your ideal client and why?
A: Anyone running multi-tenant or high-value GPU infrastructure. If you have GPU and need to prove isolation and prove security, we would love to help with that. We work alongside organisations building this kind of infrastructure for themselves directly as well as GPU cloud and neocloud providers and AI labs who want to differentiate themselves by having security built-in. Our recent partnership with Tenstorrent is a testament to our increasing range of partners who share our vision of trustworthy AI with security at the accelerator runtime.
Basically, we are best suited for environments where a cross-tenant escape or an unobserved runtime compromise is not a theoretical inconvenience but a business-ending event. For those with concentrated value in accelerators who consider this blindspot untenable.

Q: What can we expect from you in next 6 months? What are your plans?
A: More original research, deeper platform coverage, and closer work with the people building the next generation of AI hardware. Our research team has a consistent track record of publishing root-cause analysis and runtime detection for serious GPU vulnerabilities, often ahead of the wider industry, and that cadence will continue. Our recent work on Januscape provided the industry’s first meaningful runtime mitigation. This was critical for environments where customers could not prove patches as they were relying on neocloud partners who had offered them nested virtualisation access to GPUs.
On the platform side we are extending detection coverage and building out further capabilities to help turn observability into action and ensure further security outcomes. And we are partnering across the accelerator ecosystem, including beyond the incumbent GPU vendors, to make security a native property of AI compute rather than an afterthought bolted on later.
Q: What is the best thing about your company that people might not know about?
A: How much idle GPU infrastructure is quietly doing things nobody asked it to. In our own research on supposedly idle, paid-for accelerator nodes, we observed hundreds of unexpected process executions spanning dozens of distinct process families, on hardware customers believed was sitting dormant. People assume the GPU is a black box that only runs their model. It is a fully programmable computer with network access, memory and persistence, and almost nobody is watching it. That gap between what people assume and what is actually happening is the reason we exist, and most of the industry has not caught up to it yet.
That blind spot is what we close. We help make AI trustworthy by ensuring secure, observable and controlled AI accelerated compute.
