RESEARCHED PROVIDER · PRIMARY SOURCES

Confer

Confer-operated confidential inference with attestation-bound Noise channels and reproducible VM images.

INPUT / OUTPUT PRIVACY

Stage 1

Partial proof

ASSESSED DEPLOYMENT

Confer's attested inference path

RESEARCH REVIEW

2026-10-06 · primary-source review

Provider website

Verification labels describe capabilities established by the cited sources. This review did not perform live cryptographic attestation, reproduce production builds or complete an independent security audit.

Who actually runs the models?

Confer states that it runs inference in confidential VMs. Its published image includes a local vLLM engine, NVIDIA drivers and its own inference proxy. This is evidence of an operated model-serving stack, not a directory of third-party model APIs.

Deployment and TEE coverage

Covers the first-party client-to-confidential-inference path. Encrypted server-side chat history, attachments, confidential tool workers and external connectors have additional lifecycles and are excluded. Confer is a first-party application service; the reviewed sources do not establish a general public inference API.

The public VM build supports TDX/SEV-SNP environments and NVIDIA confidential computing. The vLLM service requires a local NVIDIA GPU/switch verification unit. This documents the selected inference image's boundary, not a universal claim for third-party tools or every connected service.

At least one content layer has independently checkable technical evidence, including partial proof within a layer. The full privacy boundary is incomplete. The stage tooltip distinguishes partial findings from fully met requirements for Stage 2.

STEPS FOR STAGE 2

2 of 3 requirements for Stage 2 met. Missing proof: Logs & storage.

  1. Request pathMet

    Private inputs and outputs across the request path, with E2EE or an equivalent attested channel that protects against intermediaries and binds keys to the accepted workload.

    Technically verifiable. Quote binds handshake key

  2. Inference executionMet

    Protected inference with a verifiable workload identity and protection covering the CPU, GPU and every place content is processed.

    Technically verifiable. Local vLLM; signed measurements

  3. Logs & storageNot established

    No content logging, persistent storage, human review or training. Any temporary content-derived cache must have verifiable isolation and enforced removal.

    Documented only. Cache configuration can vary

Identity and operational metadata are assessed separately below. They do not set the content stage; prompt or response content in telemetry remains part of the content-retention assessment.

Request path

Technically verifiable

Attested Noise channel. The client verifies the hardware quote, matches its key to the Noise handshake and checks measurements against a signed release in a public transparency log. The published proxy embeds attestation in that handshake. This provides a verifiable channel design for the first-party inference path; the deployed client and its accepted release identities remain part of the trust boundary.

Inference execution

Technically verifiable

Reproducible VM + GPU gate. The image uses Nix/mkosi and dm-verity to bind the root filesystem into CPU measurements. vLLM is ordered after, and requires, a local NVIDIA GPU/switch verification service. Published builds and transparency-log manifests support deployment comparison. This is an available verification chain; it does not establish the live GPU topology, every mutable configuration input or model weights for all serving instances.

Logs & storage

Documented only

Lifecycle not established. Confer's policy says it cannot access conversations and does not train on them; chat history is stored as client-encrypted ciphertext. The inference launcher disables prefix caching by default but permits enabling it through configuration. The reviewed material does not establish an attested production configuration and complete removal lifecycle across inference caches, logs and diagnostics. Encrypted saved history is a separate feature, not a no-storage guarantee.

Identity & metadata

Documented only

Account and session records. The policy describes email-based authentication, connection tokens and third-party sign-in/payment services. It promises minimal technical collection without a complete fixed retention schedule. Encryption of conversations does not make account activity, connections or payments anonymous.

Remaining trust assumptions

  • Intel/AMD confidential VM hardware and NVIDIA GPU/switch verification, including the complete serving topology.
  • The signed release identity, transparency-log verification and reproducibility of the accepted image.
  • The distributed first-party client, mutable inference configuration and any separately enabled tools or storage.

Limits of this assessment

  • A first-party chat service, not an established general public inference API.
  • Default-disabled prefix caching is not proof of the selected deployment's complete content-removal lifecycle.
  • Public source and release logs enable review; this research did not reproduce a build or verify a live session.

Primary-source record

8 sources · reviewed 2026-10-06

Back to providers

Sources reviewed 2026-10-06