Verified current behavior
Attestation status
Attestation evidence can still provide meaningful hardware authenticity and freshness checks. The missing policy checks limit the conclusion: a pass must not be described as complete proof that an approved release image processed the request.
Known gaps
Priority sequence and roadmap
- Open-source CVM base image: Open-source the hardened, read-only confidential-VM base image with a minimal package set and a verifiable root of trust. Closes: open-source CVM base image.
- Pin approved measurements by default: Ship golden policies with reference measurements pinned, so an attestation pass proves an approved release image processed the request without operator-specific configuration. Closes: approved-image pinning.
- ZDR inside CVMs: Deploy Zero Data Retention workloads inside hardware-isolated Confidential Virtual Machines. Closes: ZDR hardware isolation.
- Multi-GPU binding contract: Publish a verifiable exact-set contract so developers can confirm from the public result that every participating GPU was bound to serving. Closes: multi-GPU evidence contract.
- Route assurance: Bind the attested measurement to the served model and backend so the routing path is independently verifiable. Closes: route assurance.
- Model and engine verification: Add an open-source procedure to verify model weights, serving engine code, and runtime configuration.
- Transparency logs: Publish public transparency logs for CVM images so customers can audit changes.
- Third-party security audit: Complete an independent security audit of the platform and publish the audit report.