Privacy-enhancing AI companies, products & suppliers

PETs such as differential privacy, federated learning or confidential compute for AI. Jobs: federated training; dp releases; confidential inference.

What is Privacy-enhancing AI?

PETs such as differential privacy, federated learning or confidential compute for AI. Jobs: federated training; dp releases; confidential inference.

What problems does it solve?

Useful models seem to require centralising personal data.

Typical business use cases

  • Federated training
  • DP releases
  • Confidential inference

Important capabilities

  • PET techniques
  • Threat model
  • Utility vs privacy metrics

What buyers should evaluate

  • Threat model honesty
  • Utility loss
  • Certification claims

Risks and governance considerations

A PET label without a threat model.

Procurement checklist

  • Threat model
  • Metrics
  • Independent claims

Relevant AI Trustmark assurance

AI Trustmark independent findings appear only when an assessment or certificate exists. Category membership does not imply verification.

Methodology · How verification works

Companies and providers

Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.

  • Amazon Web Services is Amazon's cloud division selling compute, storage, Bedrock model hosting and related AI infrastructure. Public pages cover regional cloud services for builder

  • Mosaic AI on Databricks unifies model building, evaluation, serving, and governance on the lakehouse. Public marketing also emphasises lakehouse-native GenAI/ML. It is presented fo

  • Healthcare, finance, and government organizations use Duality to analyze sensitive data across silos - without ever exposing it. Duality publishes Duality PETs Platform as named AI

  • Google is a US technology company that sells consumer and cloud AI products, including Gemini, Search, and related developer APIs on Google Cloud. Google publishes Imagen, Gemini f

  • Build SDG pipelines to power conversational AI, benchmarks, and agentic AI workflows with NVIDIA NeMo synthetic data tools. Gretel publishes Gretel Transform as named AI products.

  • Generate, analyze, and share privacy-safe synthetic data with MOSTLY AI’s secure, enterprise-ready platform and open-source SDK. MOSTLY AI publishes MOSTLY AI Synthetic Data Platfo

  • NumFOCUS promotes open practices in research, data, and scientific computing. We run educational programs and fiscal sponsorship of open source projects. NumFOCUS publishes OpenFHE

  • OpenMined publishes PySyft as named AI products. OpenMined is used for Privacy-enhancing AI work. OpenMined is recorded in United Kingdom. OpenMined publishes product information a

  • Privitar is a London data-privacy company selling software to de-identify and control the use of sensitive data. Public marketing covers privacy engineering for analytics and AI pi

  • Tonic.ai publishes Tonic Textual, Tonic Fabricate, and Tonic Structural as named AI products. Tonic.ai is used for Privacy-enhancing AI and PII detection / redaction work. Tonic.ai

  • The Zama Protocol enables confidential assets to be issued, traded, and managed natively on public blockchains, with full verifiability and programmable compliance. Zama publishes

Products

Claimed products appear first. Ranking packs and payment do not change this list.

Also used in this category

These products have a different primary category so they do not compete for the same ranking queries. They are listed here because buyers still encounter them in this job.

Related categories

Relevant procurement and assurance guides

Frequently asked questions

What is Privacy-enhancing AI?

PETs such as differential privacy, federated learning or confidential compute for AI. Jobs: federated training; dp releases; confidential inference.

What should not be listed as Privacy-enhancing AI?

Products whose buyer job is DLP, PII redaction tools, or identity products. Those belong on their own category page so search queries are not split.

Has AI Trustmark independently assessed every Privacy-enhancing AI supplier?

No. A category listing is descriptive. Independent assessment is shown only on company or product pages that carry Trustmark evidence.

What model or provider changes should a buyer insist on being told about?

Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.

How should buyers verify where AI customer data is processed?

Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.

Does a TrustMark on one product cover the rest of the company?

No. Independent assessment is scoped to the named organisation and, where relevant, the named product. Category pages list suppliers as a topic label. They do not imply that every listed company has been assessed.

What incident-handling evidence is useful for AI suppliers?

Buyers should see how AI-specific failures are detected, contained and notified — including unsafe outputs, data leakage and unauthorised agent actions. An incident policy that never mentions models, prompts or tools is incomplete for this class of product.

What security testing evidence should buyers request for an AI product?

Ask what was tested, against which version, whether prompt-injection, data-exfiltration and tenant isolation were in scope, and where failed prompts were stored. A generic ISO certificate or a vendor scanner screenshot is not by itself an AI TrustMark assessment.