Privacy & decentralization
taoCode runs tools on your machine and sends model requests to your selected gateway. That gateway’s service terms govern request logging and retention.
What stays local
Section titled “What stays local”The agent session and local tool execution run on your machine. Files can be read, edited, or created there as part of a task.
What is sent for inference
Section titled “What is sent for inference”Prompts, relevant code, conversation context, and tool results may be included in requests to your selected gateway. External MCP tools may also send data to their own services.
Check the service’s retention, logging, and training terms before sending sensitive code.
- Client
- Encrypted connection
- Gateway
Confidential compute
Section titled “Confidential compute”A Trusted Execution Environment (TEE) is designed to isolate a workload from parts of its host environment. Protection depends on the hardware, software, endpoint configuration, and how a request reaches that environment.
A label such as “TEE” or “verifiable” may describe a capability advertised by the gateway. It does not, by itself, prove that every part of your request was protected or that your client verified the response.
Verifiable inference
Section titled “Verifiable inference”Attestation can provide evidence about an execution environment. What that evidence establishes depends on what is measured, how it is verified, and whether it is bound to your request. See Verifiable inference for the distinction between a capability claim and checked evidence.
Choose a gateway
Section titled “Choose a gateway”You can choose a gateway and switch models. Each gateway can still enforce its own access rules, billing, and limits. Independent inference operators do not eliminate that gateway relationship.
Limit access to sensitive data
Section titled “Limit access to sensitive data”Use the minimum context needed for a task, inspect tool permissions, and check the trust status exposed by your installed taoCode version. Match the endpoint’s documented guarantees to the sensitivity of your work.
Continue with Gateways or Inference routing.
TEE-only mode
Section titled “TEE-only mode”taoCode enables privacy.teeOnly by default. For the TAO provider, this restricts model resolution to models marked as confidential-compute capable. Local models remain allowed. You can inspect the setting with /status and change it with /tee.
{ "privacy": { "teeOnly": true }}This selection policy uses capability metadata. It is a separate layer from cryptographic attestation.
Personal data and project context
Section titled “Personal data and project context”Private repositories, customer records, personal notes, and credentials can appear in prompts or tool output. Keep secrets out of task context, limit tool access to the files you need, and choose the endpoint according to its data-handling terms.
A TEE protects an execution boundary. It does not automatically establish that a gateway never sees request plaintext, that no metadata is retained, or that an external tool handles data the same way. End-to-end encryption needs its own supported transport path.
Inspect the trust status
Section titled “Inspect the trust status”Run /status to see whether the client has checked attestation and whether the checks passed. The verification guide explains the current Chutes wallet-auth checks and their scope.