Skip to content
← Website

Privacy & decentralization

taoCode runs tools on your machine and sends model requests to your selected gateway. That gateway’s service terms govern request logging and retention.

The agent session and local tool execution run on your machine. Files can be read, edited, or created there as part of a task.

Prompts, relevant code, conversation context, and tool results may be included in requests to your selected gateway. External MCP tools may also send data to their own services.

Check the service’s retention, logging, and training terms before sending sensitive code.

Secure transport↗
  1. Client
  2. Encrypted connection
  3. Gateway
TLS encrypts traffic between your client and the gateway. The gateway terminates that connection. Encryption through to an enclave requires a separate supported transport.

A Trusted Execution Environment (TEE) is designed to isolate a workload from parts of its host environment. Protection depends on the hardware, software, endpoint configuration, and how a request reaches that environment.

A label such as “TEE” or “verifiable” may describe a capability advertised by the gateway. It does not, by itself, prove that every part of your request was protected or that your client verified the response.

Attestation can provide evidence about an execution environment. What that evidence establishes depends on what is measured, how it is verified, and whether it is bound to your request. See Verifiable inference for the distinction between a capability claim and checked evidence.

You can choose a gateway and switch models. Each gateway can still enforce its own access rules, billing, and limits. Independent inference operators do not eliminate that gateway relationship.

Use the minimum context needed for a task, inspect tool permissions, and check the trust status exposed by your installed taoCode version. Match the endpoint’s documented guarantees to the sensitivity of your work.

Continue with Gateways or Inference routing.

taoCode enables privacy.teeOnly by default. For the TAO provider, this restricts model resolution to models marked as confidential-compute capable. Local models remain allowed. You can inspect the setting with /status and change it with /tee.

{
"privacy": { "teeOnly": true }
}

This selection policy uses capability metadata. It is a separate layer from cryptographic attestation.

Private repositories, customer records, personal notes, and credentials can appear in prompts or tool output. Keep secrets out of task context, limit tool access to the files you need, and choose the endpoint according to its data-handling terms.

A TEE protects an execution boundary. It does not automatically establish that a gateway never sees request plaintext, that no metadata is retained, or that an external tool handles data the same way. End-to-end encryption needs its own supported transport path.

Run /status to see whether the client has checked attestation and whether the checks passed. The verification guide explains the current Chutes wallet-auth checks and their scope.