Confidential search with FHE
Works with your existing data
Persistent access controls and audit
Deploy anywhere (cloud, hybrid, on-premises)
HOW IT WORKS
From Encrypted Data to Authorized Results
Locktera Confidential RAG uses Fully Homomorphic Encryption (FHE) to compute similarity scores on encrypted vectors without exposing plaintext to the search server. Encrypted scores are returned to the authorized client for ranking and Top-K selection.
Documents are protected and converted into vector embeddings. Encrypted vectors are stored in your chosen environment.
FHE computes similarity scores directly on encrypted vectors, without exposing plaintext data to the search server.
Encrypted similarity scores are returned to the authorized client, where they are decrypted, ranked, and used to select the Top-K results.
Authorized users retrieve permitted content under access policies, with audit and revocation controls.
Confidential Search Without Exposing Your Data
Locktera Confidential RAG uses Fully Homomorphic Encryption (FHE) to compute vector similarity scores directly on encrypted data, without decrypting the vectors on the search server. Encrypted scores are returned to the authorized client for decryption, ranking, and Top-K selection.
When relevant results are identified, Locktera's access controls help govern authorized retrieval and decryption. Downstream AI inference is a separate stage that may require additional protections, such as confidential computing, depending on the deployment architecture.
The result: Confidential search that integrates into existing enterprise AI workflows without requiring organizations to replace their LLMs or AI infrastructure.
FHE Protects Similarity Search
Vector similarity scores are computed on encrypted data. Ranking and Top-K selection occur on the authorized client.
Authorized Retrieval and Decryption
Relevant documents are retrieved and decrypted only when access is authorized under applicable policies.
Inference Requires Additional Protection
Downstream LLM inference is a separate stage that may use confidential computing or other protections, depending on your environment.
REAL-WORLD EXAMPLE
Imagine Searching a Million Confidential Documents — Without Exposing Their Contents.
A researcher asks a question in natural language. Locktera Confidential RAG finds the most relevant information in encrypted documents, identifies the top results, and delivers only the content they are authorized to access.
Sensitive data stays encrypted during search
Results are ranked by relevance, not keywords
Access is controlled by your existing permissions and policies
PERFORMANCE
High Performance for Real-World Use
Locktera Confidential RAG is designed for speed and scale, delivering practical performance for enterprise AI and analytics workloads.
(1,536 dimensions)
(1,536 dimensions)
(1,536 dimensions)
Performance shown from internal benchmarks on 8 NVIDIA RTX Pro GPUs. Actual performance may vary based on hardware, configuration, and workload. Contact us for detailed benchmark information.
DIFFERENT APPROACHES
FHE Search vs. Confidential Computing
Locktera Confidential RAG is designed for speed and scale, delivering practical performance for enterprise AI and analytics workloads.
Locktera
Confidential RAG
FHE on encrypted data
- Computes similarity scores on encrypted vectors without requiring trust in a CPU/GPU trusted execution environment.
- No trusted hardware or TEE attestation required for search
- Designed for cloud and hybrid environments
- Integrates with persistent data policies and audit
- Designed for confidential retrieval and RAG
Confidential Computing (TEE)
Inference on protected plaintext
- Decrypts data inside trusted hardware for inference
- Requires TEE-capable infrastructure
- Relies on CPU/GPU manufacturer security guarantees and requires comprehensive workload attestation verification to establish trust.
- Complements FHE for full AI workflows
- Often used for LLM inference and AI agents
FITS YOUR ENVIRONMENT
Designed to Work With Your Existing Stack
Locktera Confidential RAG integrates easily with your data, AI and cloud structure.
Your Data Sources
Your AI Environment
Frequently Asked Questions
What is Confidential RAG?
Secure Retrieval-Augmented Generation (Confidential RAG) combines information retrieval with AI-generated responses while introducing protections for sensitive enterprise data. Locktera Confidential RAG uses Fully Homomorphic Encryption (FHE) to perform vector similarity search on encrypted data, with separate controls for authorized retrieval and downstream AI processing.
How does Locktera Confidential RAG protect sensitive information?
Locktera uses FHE to compute similarity scores directly on encrypted vectors without decrypting them on the search server. Encrypted scores are returned to an authorized client for decryption, ranking, and Top-K selection. Access policies then govern retrieval of protected source content.
Does Locktera Confidential RAG decrypt data during search?
The search server does not need to decrypt the encrypted vectors to compute similarity scores. The authorized client decrypts the resulting scores for ranking and selection. Authorized document retrieval and downstream AI inference are separate stages with their own security requirements.
What is Fully Homomorphic Encryption (FHE)?
Fully Homomorphic Encryption is a cryptographic technology that allows computations to be performed on encrypted data without first decrypting it. Locktera applies FHE to vector similarity calculations, helping protect sensitive information during search operations.
How is Locktera different from traditional RAG?
Traditional RAG architectures commonly perform vector search over plaintext embeddings within a protected environment. Locktera Confidential RAG computes similarity scores over encrypted vectors, reducing the need to expose searchable data to the search infrastructure.
How fast is Locktera Confidential RAG?
Locktera’s internal benchmarks include approximately 0.4 seconds for end-to-end search across 100,000 vectors and approximately 2.0 seconds across one million vectors, using 1,536-dimensional embeddings. Performance depends on hardware, configuration, and workload.
Can Locktera Confidential RAG work with our existing AI models? by AI?
Locktera is designed to integrate with existing enterprise AI and RAG workflows rather than require replacement of an organization’s language models. Integration architecture and supported interfaces should be evaluated against the customer’s existing environment.
Can Locktera Confidential RAG run in our cloud or on-premises environment?
Locktera Confidential RAG is designed for cloud, hybrid, and on-premises deployment architectures, including environments using Azure, AWS, and Google Cloud. Specific deployment requirements and availability should be confirmed during technical evaluation.
Is Confidential RAG the same as confidential computing?
No. FHE enables computation on encrypted vectors without requiring the search server to decrypt them. Confidential computing generally protects data while it is processed inside trusted hardware environments. The technologies can complement each other, particularly when downstream LLM inference requires additional protection.
How can we evaluate Locktera Confidential RAG?
Organizations can request a technical demonstration to review the encrypted search architecture, benchmark methodology, integration requirements, deployment options, and security controls for their specific workloads.
Protect Sensitive Data
Search confidential, regulated, or proprietary information without exposing it during encrypted search.
Maintain Complete Control
Enforce persistent access policies, support revocation, and keep detailed audit logs.
Enable Confidential RAG
Power AI assistants with private, high-quality retrieval from encrypted sources.
Enterprise Ready
Integrates with Azure, AWS, Google Cloud, and on-premises environments, with flexible deployment options.
