[ private ]

Private inference.

Requests run inside Intel TDX attested hardware enclaves. Prompts and outputs are not visible to the machine operator.

// request

How to ask for it

Per request

Add the model suffix :private (for example gpt-oss-120b:private) or send "provider": {"private": true} in the body.

Per key

Set a key to Private tier in the dashboard. A Private-tier key whose setting cannot be read is refused rather than served on an ordinary route.

Refusal

A request that cannot be served on attested hardware is refused with no_route_for_policy and nothing is charged.

// proof

Per-request proof

Provider receipt

Every private response carries the attested provider's receipt id. The gateway fetches that receipt after the response, checks it, and archives it byte for byte with its SHA-256.

Lookup

GET /v1/privacy/receipts/{request_id} returns the archived receipt to the key that made the request. GET /v1/receipts/{request_id} shows attestation pending, verified or failed.

// attestation

Enclave attestation

Attestation archive

Checking. The enclave's attestation report is archived here by the gateway each day and on every key rotation.

// models

Private routes by model

Private routes

Private routes are listed here per model with the enclave's attestation.

Privacy documentation