Verifiable inference
Hardware attestation provides evidence about the environment serving a model. taoCode can check this evidence locally through supported Chutes wallet authentication.
Capability is not verification
Section titled “Capability is not verification”A gateway may mark a model as TEE-capable or confidential. That is a statement about the endpoint. Verification requires checking evidence, rather than relying only on the label.
How verification works
Section titled “How verification works”In an attestation flow, hardware produces signed evidence about an execution environment. A verifier checks that evidence against trusted roots and expected measurements. The application must also establish how that environment relates to the request or response being inspected.
The supported Chutes checks are described under Current client checks.
What verification can establish
Section titled “What verification can establish”Valid evidence may establish that an expected environment was running, subject to the verifier’s policy and trust assumptions. Claims about the precise model, request confidentiality, or response provenance need evidence that covers those properties.
Verification does not prove that generated code is correct. Review changes and run tests as you would with any coding agent.
In taoCode
Section titled “In taoCode”Run /status to inspect the client’s trust state. The table below explains each state and the checks behind it.
See Privacy & decentralization for data-handling boundaries and Selecting a model for gateway selection.
- Fresh nonce
- Signed quote
- Local checks
Current client checks
Section titled “Current client checks”The current Chutes integration can verify evidence when a supported wallet-auth configuration is available. The client obtains evidence for known enclave instances, validates DCAP quotes against Intel-rooted collateral, and checks that quote report data binds a fresh nonce and the instance public key.
Successful results are cached for up to one hour; unavailable results are retried sooner. This is not a fresh verification of every individual response.
| State | Meaning in the client |
|---|---|
| Claimed | The gateway reports TEE capability, but no successful current check is available |
| Verified | The implemented quote-chain and nonce-binding checks passed |
| Failed | The client recorded a trust-status or binding mismatch |
The current implementation does not compare runtime measurements against a known-good image. Its evidence checks cover the model’s reported enclave instances; they do not independently prove the exact model execution behind every token. API-key-only access does not enable the wallet-auth verification flow in this implementation.
For the gateway’s distinction between model metadata and attestation evidence, see Chutes’ private inference guide.