RESEARCHED PROVIDER · PRIMARY SOURCES

Chutes

A distributed inference network with model-dependent confidential computing and an optional encrypted request path.

INPUT / OUTPUT PRIVACY

Stage 0

Privacy claimed

ASSESSED DEPLOYMENT

Public LLM API; E2EE is optional

RESEARCH REVIEW

2026-10-06 · primary-source review

Provider website

Verification labels describe capabilities established by the cited sources. This review did not perform live cryptographic attestation, reproduce production builds or complete an independent security audit.

Who actually runs the models?

Miners execute deployed model containers using Chutes software. Chutes supplies the validator, serving API and deployment system; this is a compute network rather than a directory of unrelated upstream APIs.

Deployment and TEE coverage

The assessment covers public system-user LLM inference, including the standard API path. Private/user-created chutes and chat-history storage have different guarantees.

The broader platform supports TEE and non-TEE deployments. On 2026-10-06, the public /v1/models snapshot advertised 14/14 models with confidential_compute: true. These are provider-reported flags, not verified hardware reports, and do not cover custom chutes. Check the live flag for the exact model; a -TEE name alone is insufficient.

Privacy is claimed or promised by policy, but independently checkable technical proof of content protection has not been established for the assessed path.

STEPS FOR STAGE 1

Stage 1 requires technical proof for at least one content layer. None is established in the reviewed record.

Any one proven step earns Stage 1. All three must be proven for Stage 2.

  1. Request pathNot met

    Private inputs and outputs across the request path, with E2EE or an equivalent attested channel that protects against intermediaries and binds keys to the accepted workload.

    Operator access. Standard gateway sees content

  2. Inference executionNot established

    Protected inference with a verifiable workload identity and protection covering the CPU, GPU and every place content is processed.

    Documented only. 14/14 public catalog flags

  3. Logs & storageNot established

    No content logging, persistent storage, human review or training. Any temporary content-derived cache must have verifiable isolation and enforced removal.

    Documented only. Public API only

Identity and operational metadata are assessed separately below. They do not set the content stage; prompt or response content in telemetry remains part of the content-retention assessment.

Request path

Operator access

E2EE optional. In standard API mode, the gateway can read request bodies transiently. The local E2EE proxy encrypts payloads to the target instance and rejects models lacking confidential_compute by default. Encryption alone does not establish that the instance key is independently bound to an approved attestation; this review did not establish that binding for the proxy. The optional path does not raise the standard-path rating.

Inference execution

Documented only

Model-dependent TEE. TEE deployments use Intel TDX and NVIDIA protection; non-TEE chutes retain operator access. The published security flow puts hardware and workload verification at the Chutes validator. The catalog snapshot establishes advertised coverage only, not customer verification of every serving instance, workload and GPU.

Logs & storage

Documented only

Zero-content policy. Chutes states that public system-user API content is not persisted. It describes short-lived prefix hashes for routing. User-created code and saved chat history have separate behavior. This is a policy statement; complete deployed logging, cache and storage enforcement was not independently established.

Identity & metadata

Documented only

Usage retained. Usage and billing metadata are retained. Chutes says core databases do not store IP addresses, but security infrastructure may process them. Metadata retention is purpose-based without a complete fixed schedule or verifiable deletion controls.

Remaining trust assumptions

  • Intel and NVIDIA isolation and attestation roots for TEE models.
  • Chutes validator, approved serving code and model configuration.
  • The locally operated E2EE proxy and authenticity of the destination instance key when E2EE is used.

Limits of this assessment

  • TEE coverage is model-specific and may change; the public LLM catalog is narrower than the platform.
  • TEE execution does not protect plaintext at the standard API gateway.
  • No live cryptographic attestation or independent deployment audit was performed.

Primary-source record

5 sources · reviewed 2026-10-06

Back to providers

Sources reviewed 2026-10-06