Confidential Inference

Show HN: Monitoring Confidential Inference Providers

Last verified:

Visit Confidential Inference

What is Confidential Inference?

The Attestation Monitor is an independent zero-trust verification tool that cryptographically validates hardware attestation evidence from confidential inference providers running AI models inside Trusted Execution Environments (TEE). It parses raw Intel TDX and AMD SEV-SNP quotes and verifies them against vendor roots of trust using Intel DCAP quote verification with Intel PCS and AMD KDS VCEK paths, ensuring no server-side claims are trusted.

Key features include comprehensive check tracking across 107 total verification checks, categorization of verified channels into three security models (TEE-Terminated TLS, Attested E2EE, TEE-only Gateway), and detailed per-model attestation reports showing quote type, TCB level status, signature algorithm (ECDSA-P384), confidentiality channel type, signing keys, compose hashes, RTMR values, and container image digests. The monitor tracks verification status showing 57 verified, 22 partial, 9 failed, and 19 unreachable checks across providers like Chutes, Maple, NanoGPT, NEAR AI, and PPQ.AI.

The tool is designed for security researchers, privacy-conscious AI users, confidential computing auditors, and developers who need cryptographic proof that AI inference runs on genuine secure GPU/CPU hardware in TEE mode. It enables verification that responses came from attested machines, container images haven't been tampered with, and attestations are fresh rather than replayed.

Confidential Inference pricing

Pricing model: Freemium

No pricing information available on the website - the Attestation Monitor appears to be a free public tool for independent cryptographic verification of hardware attestation evidence

Confidential Inference pros

  • Independent zero-trust verification model
  • Cryptographically validates raw TDX/SNP quotes
  • Verifies against Intel DCAP and AMD KDS vendor roots
  • Tracks 107 total verification checks
  • Categorizes 3 security models clearly
  • Shows 57 fully verified checks
  • Detailed per-model attestation reports
  • Provides quote type and TCB level status
  • Displays ECDSA-P384 signature verification
  • Shows confidentiality channel types
  • Lists signing keys for each model
  • Provides compose hash verification
  • Includes RTMR0 measurements
  • Shows container image digests
  • Tracks provider-specific results (Chutes, Maple, NanoGPT, NEAR AI, PPQ.AI)

Confidential Inference cons

  • 9 checks failed verification
  • 19 endpoints unreachable
  • 22 checks only partial verification
  • Some endpoints have no public attestation
  • Fresh evidence sometimes unavailable
  • Image provenance incomplete for some checks
  • Compose hash mismatches detected
  • Enclave TLS pin verification fails

Frequently asked questions about Confidential Inference

What is zero-trust attestation?

Zero-trust attestation means verified channels are not trusted based on server-side claims. The monitor parses raw TDX/SNP quotes and verifies them cryptographically against vendor roots of trust (Intel DCAP quote verification using Intel PCS or AMD KDS VCEK path), ensuring complete independence from provider assertions.

What are the three security models?

The three security models are: TEE-Terminated TLS (encryption terminates at TEE), Attested E2EE (payloads encrypted to attested enclave key with end-to-end encryption), and TEE-only Gateway (model runs in TEE but gateway sees plaintext prompts).

How does Intel TDX verification work?

Intel TDX verification uses DCAP QVL (Data Center Assurance Platform Quote Verification Library) with Intel PCS as the default trust channel. The monitor validates the quote signature (ECDSA-P384), checks TCB level status, and verifies report data contains the expected nonce and signing address.

What does Attested E2EE mean?

Attested E2EE means payloads are encrypted to an attested enclave key, providing end-to-end encryption where the gateway TLS termination is external. The E2EE protocol uses ML-KEM-768 or ed25519, and the signer is bound to the attestation report with nonce binding confirmed.

What is a TEE-only Gateway limitation?

TEE-only Gateway means the model runs inside a TEE but the gateway sees plaintext prompts before encryption. This provides hardware attestation for the inference itself but doesn't protect prompts from the gateway layer, representing a partial privacy guarantee.

What does partial verification mean?

Partial verification indicates hardware evidence passed but incomplete image or Sigstore provenance. The check is reported as partial rather than failed when hardware-verified checks have incomplete container image pins or unverified source provenance.

How is compose hash verified?

Compose hashes are recomputed and compared against claimed tcb_info values. Verified compose hashes confirm the container image running in the TEE matches the expected digest from the official release, proving the container hasn't been tampered with.

What is RTMR0?

RTMR0 (Runtime Measurement Register 0) is a cryptographic measurement value that uniquely identifies code running inside the TEE. The monitor displays RTMR0 values (e.g., bc122d143ab768565ba5c3774ff5f03a63c89a4df7c1f5ea38d3bd173409d14f8cbdcc36d40e703cccb996a9d9687590) to verify workload integrity.

Why do some endpoints show unavailable?

Endpoints show unavailable when fresh evidence could not be fetched in the verification run. This occurs when providers have no public attestation endpoint or when the verifier cannot reach the endpoint to fetch fresh TDX/SNP quotes for validation.

What providers are monitored?

The monitor tracks multiple confidential inference providers including Chutes (3/12 verified), Maple (1/1 fully verified), NanoGPT (16+6/28 with provenance incomplete), NEAR AI (8/8 fully verified), and PPQ.AI (4+2/6 with provenance incomplete), covering models like Gemma 4, Qwen3, GLM 5, GPT-OSS, and Kimi K2.5.

Categories

Use cases

Browse all AI tools on NeedAnAI