Rent a machine In testing
A whole virtual machine on somebody's hardware, with a share of its GPU — for work that does not fit a chat request: training runs, long jobs, your own stack. You reach it from the panel; the machine itself is never exposed to the internet.
Choose a host
The panel's Available hosts list shows machines their owners offer to the network: CPU cores, memory, the GPU and its memory, disk, measured network speed, whether the host is online right now, and the price per minute for the machine you are about to order.
- A host is shown online while its agent keeps reporting in; one that has gone quiet is marked offline and will not accept an order.
- Hosts are ordinary people's computers. Before you order on somebody else's host, you confirm that you understand what that means — see what the host owner sees.
- NVIDIA GPUs are what the network offers today. Other vendors are detected but not offered In development.
Place the order
You choose a name, the number of cores, the memory, the disk size, the base image, and whether the machine gets a share of the host's GPU. Your SSH public key goes in here too — from the order form or from your profile.
On somebody else's host, the order is a contract offer, not an immediate build. Nothing exists until the owner signs it:
-
You sign
The panel shows the contract with the host's specification, the price and the trust level written into it. Signing sends it to the owner.
-
The owner answers
Accept, or decline with a reason. Owners who have opted in accept standard terms automatically. An offer nobody answers expires within a day.
-
The build starts
Only after a signature. Until then there is no machine, no build task and no charge; you can withdraw the offer at any point.
On your own host there is no contract step — there is nobody to agree with.
While it builds
The panel shows the build as it happens, step by step, over its own connection to the server. Closing the tab does not interrupt anything; reopening it picks the progress back up.
- The machine is deployed from a prepared image that the host keeps, so the second machine of the same image on that host starts much sooner than the first.
- A build that stops making progress is failed rather than left hanging, and so is a machine that never finishes starting.
- A failure is explained in plain words — the host went offline, it ran out of disk, the agent could not start the machine — with the raw error kept under Details. Try again reopens the order form with your choices, so nothing is resubmitted behind your back.
States you will see on the machine: creating, starting, online, offline (built, not running), failed.
Connect
The machine has no public address and no open ports of its own. Everything goes through the platform:
- Console. A real terminal in the panel — colours, editors, tab completion. It runs as an unprivileged session user, not as root; if that cannot be arranged, the shell does not start at all.
- Files. Upload and download in the same console, up to 512 MB per file. There is no public SFTP or SCP endpoint Planned.
- Your own services. A service you run inside the machine can be published on a platform address and reached through it. Only you (and platform administrators) can reach it; the host owner cannot.
- SSH. The key you gave is installed for your session user inside the machine. It is used through the platform, not by connecting to the host from outside.
Disks and what survives
The machine has two disks, and the difference between them is the whole story of what you keep.
| Disk | What it holds | What happens to it |
|---|---|---|
| System | The base image: the operating system and what ships with it. | Redeployed from that image every time the machine starts. Nothing you leave there is yours to keep, and it is not encrypted — it is the same public image on every machine. |
Data (/data) |
Your work. | Encrypted with a key issued for the session. A reboot inside the session keeps it. When the session ends the key is destroyed and the volume is made anew — which is what makes the previous session's data unrecoverable. |
The running machine's memory is never written to the host's disk: it cannot be paused to disk or checkpointed, precisely so the data key cannot be fished out of a saved state.
A GPU share carries the host's own driver into the machine when the host offers one. Beyond the operating system and that driver, assume nothing is preinstalled — bring your own toolchain.
Taking results with you
Anything you want to outlive the machine goes into /data/artifacts.
In testing
- Files there are encrypted inside the machine, with a key of yours that the host never receives, and go straight to the platform's object storage. Neither the host owner nor the application server sees their contents.
- They belong to your account, not to the machine, so deleting the machine does not delete them.
- A file is left alone until it stops changing, so a half-written checkpoint is not shipped.
- They are kept for about a year, and you are warned before that runs out. Deleting them earlier is done by asking us In development.
- If storage is full or unreachable, the run is not killed: the copy is skipped and reported.
Only that one directory is shipped. Model weights and packages you can fetch again are not — that would spend the host owner's bandwidth for nothing.
What the host owner sees
This is the part we would rather state plainly than let you assume.
| Can | Cannot |
|---|---|
| Observe the machine while it runs — its memory, processor and network traffic are on hardware they control, and nothing prevents that today. | Read your data disk, its key, or your artifacts: the key is issued to the machine itself, never to the host's agent. |
| Stop the machine, or stop offering the host altogether. | Open your console, transfer your files, or reach the services you published — those answer to you, not to the hardware. |
| Deliver the GPU driver into the machine through a single-purpose channel. | Get a shell in your session: your user has no administrator rights and no password to use. |
So: encryption protects your data at rest and after the session, not the computation while it runs. Hardware attestation and hosts with protected memory are Planned. During the test, do not put confidential data or other people's personal data on a rented machine — see the Acceptable Use Policy.
What it costs
- By the minute by default: the price shown on the host, charged once a minute, and only for minutes the machine was actually reachable.
- For a fixed term if you prefer: a term from a short fixed list, priced at the same per-minute rate. The whole term is held in reserve when you sign, and settled at the end. Stopping early means paying for what you used; if the host is what broke, the term costs nothing.
- The price comes from the platform's formula — cores, memory, disk, GPU and its memory, adjusted for the quality of the host. The owner does not set it, and there are no discounts or negotiated rates Planned.
- A GPU that turns out smaller than the host claimed reduces the price; it never raises it.
- When your balance reaches zero, the machine is stopped on the host — not merely marked unpaid.
Ending the rental
Delete the machine in the panel. The platform stops it on the host, destroys the data key, closes the order and settles what is owed. A fixed term left early is settled the same way.
What is left afterwards: your artifacts in storage, the credit entries, and the contract — the record of what was agreed, which neither side can quietly rewrite.
Next: put your own machine to work, or serve a model in a pool.