Volumes that outlive the pod
Pods are disposable. A persistent volume keeps your weights, datasets and checkpoints across stops, restarts and re-creations — and, if you ask for it, keeps them encrypted on a disk you do not own.

Local or network
Both start at 10GB and are billed per GB·month. The difference is what they are tied to.
| Local volume | Network volume | |
|---|---|---|
| Lives on | The pod's own host machine, on direct disk | A dedicated storage node, over NFS |
| Created | With the pod, in the create flow | Standalone, from Resources › Storage |
| Reach | That one machine — the pod stays with it | Any pod in the workspace can mount it |
| Pod types | Demand pods | Demand and spot |
| Reach for it when | Scratch space and weights next to the GPU | Datasets shared across pods, or data that must outlive a machine |
Persistent, and optionally unreadable without you
- 01
Encrypted at rest, at no charge
One switch at creation and the volume's contents are encrypted on the physical disk. The key is never kept on the host machine, so a lost, resold or physically accessed disk reads as noise. The cost is roughly 3–5% of throughput.
- 02
It unlocks and locks itself
An attached volume unlocks for the pod's lifetime and locks again the moment the pod stops. Connect unlocks on demand, and an idle countdown re-locks it — a transfer in progress pauses the clock rather than being cut off.
- 03
Reachable without a pod
Connect opens a temporary SSH/SFTP channel straight to a network volume. Upload a dataset before you have rented a single GPU; preparing the channel takes about a minute.
- 04
Billed for the bytes that exist
Per GB·month for as long as the data is on disk, including while the pod is stopped — those bytes still occupy a physical drive. Deleting a pod can delete its local volumes in the same step; network volumes are deleted from the Storage tab.
Three things worth knowing first
- Can I encrypt a volume I already have?
- No. Encryption is decided when the volume is created and cannot be toggled later. To encrypt existing data, create a new encrypted volume and copy the data across.
- Why can't a spot pod use a local volume?
- A spot pod can be reclaimed and re-placed on a different machine, which would strand a volume that lives on the first machine's disk. Spot pods mount network volumes instead, and those survive the move.
- Does encryption at rest protect a running pod?
- Not by itself. While a pod is using the volume the data is necessarily unlocked for that pod. At-rest encryption covers the disk footprint — a powered-off or locked volume exposes nothing, even with the drive in hand.

Pick a card and start the pod
Sign up, choose the GPU, and the pod is yours in under two minutes. It bills by the hour and stops when you stop it.
Already a user? Invite friends and earn 15% of their first top-up.
